TL;DR: The riskiest moment for a business payment is not when your finance manager is at their desk. It is when they are on a beach and somebody else is covering. Criminals know this, they can see who is away from your own out of office replies, and August is one of their better months. The fix is not more vigilance. It is one verification rule that does not bend for anybody.
The gap nobody plans for
Most businesses have an unwritten payment process that works fine because the same person always does it. They know which suppliers exist, what a normal invoice looks like from each one, and roughly what things cost. When something is off, they notice without being able to explain why.
Then they go on holiday for a fortnight, and somebody who does not have any of that background is asked to keep things ticking over.
That stand-in has no baseline. They have never seen a genuine invoice from that supplier. They do not know that the amount is unusual, or that the bank details changed, or that the boss never asks for anything by email on a Friday afternoon. They are trying to be helpful in a job that is not theirs, and their main worry is holding things up.
That is the gap. It is not a technology gap and it is not a training gap. It is a knowledge gap, and it opens on a predictable schedule every summer.
How they know you are away
Here is the part that surprises people: the attacker does not need to guess.
Your automatic out of office reply tells them. Send one email to a general address and you get back, unprompted, a message explaining that the finance manager is away until the 30th, and in the meantime please contact a named colleague on this address.
That is the whole plan handed over: who is away, how long for, and exactly who is standing in. All the attacker adds is a plausible invoice or a change of bank details, sent to the stand-in, with a reason to hurry.
The email itself does not need to be sophisticated. It usually is not. It works because it lands on the one person in the building who has no way of knowing it is wrong.
The two shapes it takes
The supplier that changed its bank details. An email arrives from a supplier you genuinely use, saying their account has moved and here are the new details for the invoice due this week. Sometimes the criminal has been reading a real mailbox for weeks and sends this at exactly the right moment, referencing a real invoice number. The payment goes out, correctly authorised, to the wrong account. This is business email compromise, and it is the most expensive thing that happens to small businesses that never make the news.
The urgent request from someone senior. An email that appears to come from a director, apologetic and brief, asking for a payment to be made quickly while they are travelling and hard to reach. It leans on authority and urgency at once, and it is aimed at someone who has never had to say no to that person before.
Both rely on the same thing: that nobody will check, because checking feels like an insult or a delay.
The fix is a rule, not more care
The instinct is to tell everyone to be careful. That does not work, because the whole point of these attacks is that they look ordinary. Asking a temporary stand-in to spot a well-made fake is asking them to do something the regular person often could not do either.
What works is removing the judgement call. One rule, applied to everyone, every time:
No bank details are ever created or changed on the strength of an email. The change is confirmed by phoning the supplier on a number you already held before the request arrived.
That last clause is the whole thing. Not the number in the email. Not the number in the signature. Not the number on the invoice. The number from your own records, or from the contract, or from their website that you navigated to yourself.
Three things make it stick:
- Write it down and give it to the stand-in. A rule that only lives in one person's head goes on holiday with them. Put it on one page with the process and the phone numbers, and hand it over as part of the handover.
- Say out loud that delay is fine. The stand-in needs explicit permission to hold a payment for a day while they check. If nobody tells them that, urgency wins, because looking obstructive feels worse than being slow. Tell them plainly: nothing bad happens if a genuine payment goes out a day late.
- Require two people on anything above a threshold. Pick a number that suits your business. The point is not the amount, it is that a single compromised mailbox is no longer enough on its own.
Tidy up the out of office too
You do not need to abandon automatic replies. You do need to stop them briefing strangers.
An out of office that says "I am out of the office and will reply on my return, for anything urgent please contact the office on 01584 517234" gives colleagues and customers what they need. It does not hand over a named target, a date range and a direct address to a criminal.
Keep the detail for internal senders if your mail system supports separate internal and external replies. Most do.
The technical half
Process catches what reaches the inbox. The other half is stopping as much as possible from arriving.
- Make sure your own domain cannot be impersonated. SPF, DKIM and DMARC are the settings that stop anyone sending email that appears to come from your business. Most local firms we check have at least one of them missing or set to do nothing, which is why we wrote up what we found. Our email authentication guide explains all three without the jargon.
- Turn on impersonation protection. The controls in Microsoft 365 Business Premium can spot an email pretending to be a director or a known supplier and deal with it before a person has to make a decision. Detail on our Business Premium page.
- Get MFA on every mailbox. Most invoice fraud that references real invoice numbers starts with someone reading a real mailbox. MFA is what stops a leaked password turning into weeks of quiet surveillance.
Before the next handover
It takes about half an hour. Write down the payment rule. Add the supplier phone numbers you would actually call. Agree the two-person threshold. Hand it to whoever is covering, and tell them explicitly that checking is welcome and delay is acceptable.
Do that and the summer gap mostly closes, without anyone needing to become a fraud expert.
If you would like us to check whether your domain can currently be impersonated, we will run it and send you a plain-English report on what is exposed. It is free and there is no obligation: get your email security check, or call us on 01584 517234.

