Back to Blog
Guides

A Fraudulent Invoice Just Left Your Mailbox and What to Tell Clients Today

A fraudulent invoice has gone out from your own email address and a client may have already paid it. Here is what to tell your customers today, and who else you must notify.

By Mark Sullivan • Sep 26, 2026 •1 views
business email compromiseBEC responseinvoice fraudNorth Texas cybersecurity
Share:

A client calls on a Tuesday afternoon and asks why your bookkeeper changed the wire instructions. You did not change anything. Somebody in your mailbox did.

That is the moment this article is about. Not the moment you buy better email filtering, and not the moment your insurance carrier finally pays out. The moment a fraudulent invoice has already gone out from your own email address, one of your customers has already paid it, and you have to decide what to tell them before the end of the day.

Business Email Compromise, usually shortened to BEC, is a fraud where a criminal gets into a real business mailbox and uses it to redirect money. There is no ransom note and often no malware at all. The attacker simply reads your mail until they understand how you bill people, then sends a message that looks exactly like every other message you have ever sent. It is the most common way we see North Texas businesses lose real money, and the damage almost never stops at the company that got breached. It lands on its customers.

Prevention is a separate conversation, and we have covered it in our guide to stopping wire fraud before it starts. This article assumes prevention already failed. Your mailbox has been used as a weapon against people who trusted you, and the next twenty-four hours will determine whether you keep those relationships.

What These Attacks Have Actually Cost in North Texas

It helps to see what is on the public record close to home, because local incidents run larger than owners expect.

In May 2023 the City of Dallas was attacked by the Royal ransomware group. Police dispatch fell back to manual processes, municipal courts closed, and library systems went dark. The city later reported that personal information belonging to more than twenty-six thousand people had been exposed, and the city council approved roughly eight and a half million dollars in emergency spending to recover. That was a city with a dedicated technology department, a real budget, and full-time security staff.

In March 2024 the Tarrant Appraisal District, the office that sets property values for Tarrant County, was hit by a group calling itself Medusa. The attackers demanded a payment reported at around seven hundred thousand dollars. The district declined to pay and took its public systems offline while it rebuilt. Closer to the healthcare world, the attack on JPS Health Network rippled outward to every vendor that had ever invoiced the hospital, which we covered in what the JPS attack means for Fort Worth businesses.

Notice what all three have in common. The headline was about the institution, and the bill was paid by everyone connected to it. When an attacker gets into a mailbox, they inherit the contract numbers, the payment schedules, the names of the people who approve invoices, and the tone those people write in. That inventory is what turns one compromised account into fraudulent invoices going out to a dozen customers, and it is why our business email compromise response service treats client notification as part of the incident itself rather than as public relations cleanup afterward.

The uncomfortable truth for a smaller company in Plano, Frisco, or Allen is that you do not get the benefit of a public narrative. Dallas was covered by every outlet in the region, so its vendors understood what happened without being told. When a twenty-person firm gets hit, nobody reports it. The only version of events your clients will ever hear is the one you give them.

The Fraud Does Not Look Like Fraud to Your Client

An attacker who gets a password, usually through a convincing fake login page, does not start deleting things. They sit quietly. They read six weeks of your email. They learn that you invoice on the first and the fifteenth, that a particular office manager at a particular customer approves anything under twenty thousand dollars without a second signature, and that you sign your emails a specific way. Many of them create a hidden rule that quietly moves any reply containing the words invoice or payment or bank into a folder nobody opens, so you never see your client's questions.

Then they send a real-looking invoice from your real address, referencing a real project, with new banking details and a plausible reason for the change. Your client pays it. Nothing looks wrong to anyone until the money is gone.

There are two details worth understanding, because clients will ask about both. First, your client was not careless. The message came from your address, so every check they had in place passed. Second, these messages are far better written than they used to be. Attackers now use generative tools to match a writing style from a handful of sample emails, which is one reason we treat artificial intelligence security as a practical business concern rather than a future one.

The technical side of locking an attacker out of a Microsoft 365 mailbox is its own sequence of steps, and we walk through it in the first forty-eight hours after you find a compromised mailbox. Closing the door is necessary. It is not the part that saves the relationship.

The First Day Belongs to Your Clients, Not Your Network

Most businesses get the order of operations wrong here, and the instinct behind it is understandable. You want to be certain before you say anything. So you spend two days investigating, and you tell your customers on day three.

Those two days are the expensive ones. During that window, more fraudulent invoices go out under your name, clients who noticed something odd start telling other people, and any customer who already paid loses the narrow window in which a bank can still claw the money back. That window is measured in hours, not weeks.

The rule we give every client is simple. Your customers get told on the same business day you confirm that a fraudulent message left your mailbox, even though you will not have complete answers yet. Partial information delivered fast reads as competence. Complete information delivered late reads as concealment, and it is the second impression that costs you the account.

Notifying early does not mean guessing. There is a real difference between saying that you do not yet know which mailboxes were involved and implying that nothing serious happened. Say the first, never the second. Correcting a detail later in writing is survivable. A client discovering the breach from their own bank is not.

What to Actually Say, and to Whom

Your notification should go out in three versions, because three different groups need three different things.

Every client who received an invoice or payment request from you in the affected window gets a direct message, by phone first and email second. Tell them fraudulent messages were sent from your email system, give the date range, tell them not to act on any payment instruction from you during that period, and give them one verified phone number to confirm any request going forward. Use your main published line, which for us is 512-518-4408, and give a person's name. Do not ask them to reply to email to confirm anything, because email is the channel that is compromised.

Any client who already sent money gets a phone call within the hour, and it is an operational call, not a sympathetic one. They need to contact their bank immediately and specifically request a recall or reversal on a fraudulent transfer, they need to file a report with the FBI Internet Crime Complaint Center, and they need the transaction details in writing from you to support the claim. Recovery rates on wire fraud drop sharply after the first day and become very small after the first week. A client who recovers their money because you called fast will usually stay a client. A client who finds out on day four almost never does.

Everyone else in your address book gets a shorter notice. They do not need incident details. They need to know that any unexpected payment change from your company should be verified by phone, and they need one number to use.

There is also a set of people you have to tell who are not customers. Your bank needs to know so it can watch your own accounts. Your cyber insurance carrier needs to be notified inside the window your policy specifies, and that window is often seventy-two hours or less. Many policies also require you to use an approved response vendor, and calling someone else first can reduce or void the claim, which is one of several reasons we wrote up what cyber insurance carriers actually require from North Texas businesses. If your mailbox contained medical records, financial account numbers, or personal information about Texas residents, you may also have breach notification obligations with their own deadlines. Read the policy and the statute before you decide that an incident was minor.

Proving What the Attacker Actually Saw

Once notification is out, the question every serious client and every carrier will ask is what else was exposed. Guessing at this is where companies get into legal trouble.

Saying that only one mailbox was affected is a factual claim about your systems, and it requires evidence from sign-in and audit logs, not an assumption based on which fraud you happened to discover first. Attackers who get one set of credentials commonly use that mailbox to phish colleagues internally, where the message carries far more trust than anything from outside. We have seen investigations that started with one compromised account and ended with four, and the additional three were only found because somebody pulled the logs properly. That evidence work is what digital forensics is for, and a carrier reviewing a six-figure claim will read it closely.

The other half of the picture is what happens to the stolen credentials afterward. Passwords harvested in one campaign get bundled and resold, which is why dark web monitoring belongs in the follow-up and not only in the prevention bucket. If your accounting manager's password shows up in a fresh dump ninety days from now, you want to hear about it from a monitoring service rather than from a second round of fake invoices.

Then comes the part that actually closes the hole. Every mailbox gets its password rotated and its active sessions revoked, because a stolen session token can keep working after a password change. Every inbox rule the attacker created gets found and removed. Multi-factor authentication, which means requiring a second proof of identity such as a code on a phone in addition to the password, gets turned on for everyone, and the phishing-resistant kind gets turned on for anyone who can approve a payment. That ongoing filtering and authentication work is the domain of email security, and it is what keeps this from becoming an annual event.

Who Answers the Phone When This Happens on a Saturday

Timelines like the ones above assume somebody is available to run them. That assumption breaks in a lot of North Texas businesses.

If your technology support is one internal person, or a managed provider whose contract covers uptime and help desk tickets rather than security incidents, then the day a fraudulent invoice leaves your mailbox you have one person trying to do four jobs at once. They need to lock down accounts, pull logs, brief the owner, and help draft client notifications, all while the normal work of the business keeps arriving. Something gets dropped, and it is almost always client notification.

This is the specific gap that co-managed IT exists to fill. Your person keeps owning the systems and the relationships they already know. An outside team takes the incident work and the forensics, so the notification calls actually get made on day one instead of day three. We wrote more about how that division of labor works in practice in who acts at 2 AM for Plano and Frisco businesses.

We are based in McKinney and most of our work sits in Collin County and the surrounding DFW market, which means a named person can be on site the same day for a business in Frisco, Plano, or Allen. On the specific problem of a mailbox that has defrauded your own customers, somebody sitting across the table helping an owner make hard phone calls is worth more than any dashboard.

The practical step to take this week, before any of this is urgent, is to decide two things in advance and write them down. Decide who makes the client notification calls, by name. Decide what your verification rule is for payment changes, which should always be a callback to a number already on file and never a number supplied in the message requesting the change. If you want an outside read on where your email and payment approval process would actually break, our security assessment covers exactly that, or you can reach us at 512-518-4408 or through our contact page.

Frequently Asked Questions

Do I have to tell my clients that my email was hacked?

In almost every case yes, and the practical reasons outweigh the legal ones. If fraudulent payment instructions went out under your name, your clients need that information to protect their own money, and any of them who already paid need it within hours to have a realistic chance of a bank reversal. Separately, if the mailbox held personal information about Texas residents, medical records, or financial account details, you may have a formal notification obligation with a statutory deadline. Read your policy and the applicable statute rather than deciding on instinct that the incident was too small to mention.

Can my client get their money back after they pay a fraudulent invoice?

Sometimes, and the odds depend almost entirely on speed. A bank can often recall a domestic wire on the first day if the receiving account has not already been emptied, and the FBI has a recovery process that works best inside the first seventy-two hours. After a week the money has usually been moved through several accounts, and the chances fall dramatically. This is exactly why the phone call to any client who already paid cannot wait for your investigation to finish.

Is my business liable if a fraudulent invoice came from my email?

Liability depends on your contracts, your jurisdiction, and the facts of the case, so that is a question for your attorney and not your technology provider. What we can tell you is what tends to drive the outcome in practice. Two things matter most to carriers and to courts, which are whether you had reasonable controls in place such as multi-factor authentication and a payment verification rule, and how quickly you notified the affected parties once you knew. Delay is the factor most consistently held against the breached company.

How do I know the attacker is really out of my mailbox?

You do not know it from the absence of new fraudulent emails, which is the mistake most businesses make. You know it from sign-in logs showing no unexpected sessions, from confirming that every active session was revoked rather than only the password changed, and from finding and deleting every inbox rule the attacker created. A stolen session token can keep working after a password reset, and a hidden forwarding rule can keep feeding an attacker information for months. Document all three checks, because your insurance carrier will ask for them.

Need Help With This?

Innovation Network Design helps businesses across McKinney, Dallas, and nationwide with expert cybersecurity services.

M

Mark Sullivan

Innovation Network Design

With nearly a decade in cybersecurity and IT infrastructure, our team delivers expert insights to help businesses in McKinney, Dallas, and across DFW make informed security decisions. Have a question? Get in touch.

Ready to Secure Your Business?

Get a free security assessment and find out where your organization stands.