Back to Blog
Guides

You Paid a Fake Invoice and How North Texas Businesses Recover the Money

A fake vendor invoice is paid and the money is already moving. Here is what a North Texas business should do in the first hours to recover it.

By Mark Sullivan • Sep 28, 2026 •2 views
business email compromisewire fraudincident responsenorth texas
Share:

The call almost always comes from the accounting side, not the IT side. Someone in your office paid an invoice from a vendor you have worked with for years. The amount was ordinary. The message came from the right person at the right company, inside the same email thread you had been using all month. Ten days later that vendor calls to ask why the bill is still open, and the room goes quiet.

That is business email compromise, and it is the most common way North Texas companies lose real money to a cyber attack. Business email compromise, usually shortened to BEC, means an attacker gets inside a real email mailbox and uses it to redirect a payment to an account they control. There is no ransom screen, no locked files, no dramatic outage. There is a wire that went to the wrong place and a very short window in which you can do anything about it.

We recently covered the other side of this problem, which is what to tell your own clients when the fraudulent invoice went out from your mailbox. This post is the receiving end. You paid, the money is gone, and the next several hours decide whether you get any of it back.

The Money Clock Runs Faster Than the Forensics Clock

The instinct after any cyber incident is to find out what happened. That instinct is correct for almost every kind of attack and it is wrong for this one, at least for the first few hours.

Once funds leave your account, they move through a chain of accounts controlled by the people who sent the fake invoice. The money does not sit still. It is typically pulled out or pushed onward quickly, and each hop makes it harder to reach. A wire transfer is designed to be fast and effectively final, which is exactly why fraudsters ask for one. An ACH payment, which is the slower bank to bank transfer used for payroll and routine bills, has more built in room for reversal, but that room is measured in days rather than weeks.

So the order of operations matters more here than in almost any other security event. The investigation into which mailbox was compromised, which is real work that has to happen, does not need to happen before someone picks up the phone to the bank. If one person would end up doing both jobs, that person calls the bank first.

This is why we tell every client in McKinney and across Collin County to decide in advance who owns which call. Not who sits on the incident response team in the abstract, but which named human dials the bank at four in the afternoon on a Friday when the controller is out.

The First Four Hours and Who Makes Which Call

Three things need to happen at the same time, which means three different people need to be doing them.

The first person calls your bank, asks for the fraud or wire recall desk by name, and states plainly that the payment was fraudulently induced and you are requesting a recall. Do not open with an explanation of the phishing email. Open with the request. Have the date, the exact amount, the trace number, and the receiving bank and account details ready before you dial, because hunting for them during the call costs minutes you do not have.

The second person files a report with the FBI Internet Crime Complaint Center at ic3.gov. This is not the same as calling your local police. The Bureau operates a process specifically for contacting receiving banks and attempting to freeze fraudulent domestic transfers, and it only works when it is triggered quickly. File it even if your bank says they are already working on a recall. The two efforts do not conflict.

The third person stops the bleeding on the email side without destroying anything. That means forcing a password reset and signing out active sessions on the affected mailbox, and checking for mail forwarding or inbox rules the attacker added. It does not mean deleting the suspicious messages, and it does not mean wiping a laptop. Those messages and logs are the evidence your bank, your insurer, and any eventual digital forensics review will need. Digital forensics simply means collecting and examining the records a system keeps, in a way that holds up when someone later asks you to prove what happened.

If your technology is split between an internal person and an outside provider, this is the moment the split hurts. Two parties each assuming the other called the bank is a very expensive assumption. A co-managed IT arrangement is worth having precisely because the handoffs are written down before the day you need them, rather than negotiated in a group chat while the clock runs.

What Your Bank Needs to Hear and Why the Wording Matters

Banks treat two situations very differently. One is an unauthorized transfer, where someone took money out of your account without your involvement. The other is an authorized but fraudulently induced transfer, where your own employee approved a payment because they were deceived. Paying a fake vendor invoice is the second kind, and that distinction shapes what the bank can do and what your insurance will cover.

Say it accurately. Tell them the payment was authorized by your staff but fraudulently induced by an attacker impersonating a known vendor, and that you are requesting a recall on that basis. Overstating it as an unauthorized withdrawal can send the claim down a path that later has to be unwound, which wastes the only resource that matters here.

Then call your insurance broker the same day, before you have all the answers. Most cyber policies handle this under a funds transfer fraud or social engineering clause that is separate from breach response coverage, and that clause frequently carries its own lower limit. If you have never read that section of your policy, read it this week rather than during an incident, and if the language is unclear, that is a reasonable thing to work through with an outside security advisor who has read a few of them.

Notification deadlines in these policies are often written in hours, not days. A late call can reduce or void a payout on a loss that was otherwise covered.

The Question Nobody Asks First, Which Mailbox Was Actually Hacked

Here is the assumption that costs companies a second loss. Everyone assumes the vendor was hacked. Sometimes the vendor was hacked. Sometimes you were.

There are three ways the fake invoice reaches you, and they lead to very different next steps. The attacker may be inside the vendor mailbox, reading the real thread and replying from the real address. The attacker may be inside your mailbox, watching your payables and injecting a message. Or the attacker may be in neither, using a domain that looks almost right, with a letter swapped or a word added, gambling that nobody reads the address closely.

You cannot tell these apart by looking at the email in your inbox. You tell them apart by reading the full message headers and by reading your own mailbox sign in logs for the period before the invoice arrived. If your mailbox was the one compromised, then the fake invoice you paid is the smaller problem, because the same attacker has been reading your client correspondence and is very likely preparing the same trick against the people who pay you. That is the scenario where this post and the compromised mailbox response guide have to be run together.

It is also worth checking whether your staff credentials are already circulating. Dark web monitoring, which means watching the criminal marketplaces and leak sites where stolen usernames and passwords are traded, frequently shows that the password used to open the mailbox was taken from an unrelated breach months earlier and simply reused.

Why the Fake Invoice Was So Convincing This Year

Business owners in Plano and Frisco tell us the same thing afterward. The email did not look like the clumsy phishing they were trained on. It was written in the voice of the vendor, it referenced the right project, and it arrived at the time of month the real invoice normally arrives.

Two things changed. The first is that generative tools removed the tells. Broken grammar and odd phrasing used to be the reliable signal, and they are gone. The same tools can now clone a voice convincingly enough that a confirmation call to a number supplied in the email is worth nothing. This is the practical, unglamorous reason AI security belongs on a small business agenda rather than only an enterprise one. The exposure is not a distant policy question, it is the quality of the forgery sitting in your payables inbox.

The second is that the mail systems themselves keep providing the way in. Our advisory feed this month covered a flaw in Roundcube, a web based email program that many smaller companies and their hosting providers run, tracked as CVE-2026-48842 and confirmed under active attack in late September 2026. A CVE identifier is just the industry catalogue number for a specific software flaw, and what matters to you is that this one let attackers reach into mail data on unpatched systems. Ten days earlier the same feed covered a zero day in a Cisco email security gateway, which is the appliance whose entire job is filtering malicious mail before it reaches staff. When the filter itself is the entry point, employee training is not the control that saves you.

None of that means prevention is pointless. It means prevention and response are separate budgets. The controls that reduce how often this happens, which are the authentication and filtering and verification work, live with email security, and we have written the prevention side up separately in the wire fraud prevention guide. This post is about the day prevention did not hold.

What It Costs Beyond the Wire Itself

Owners reasonably fixate on the transferred amount, because it is the number they can see. It is rarely the whole loss.

The vendor invoice is still outstanding. In most cases you still owe that money, because you did not actually pay your vendor, you paid a criminal. That fact alone doubles the exposure for many small companies before anyone has looked at a log file.

Then there is the time. A forty person contractor in Allen that loses its controller and its operations manager for the better part of a week is absorbing a real payroll cost and delaying everything those two people were supposed to deliver. There is the relationship with the vendor, which becomes awkward in both directions while each side works out whose mailbox failed. There is the insurance renewal, where a funds transfer fraud claim is a question you will be answering for several years. And if the compromise turns out to be on your side, there is the client notification work, which is slow and unavoidable.

The businesses that come through this well are not the ones with the largest security budget. They are the ones where somebody knew which number to call in the first hour.

What to Change Before the Next Invoice Arrives

Three changes prevent nearly all of this, and none of them require new software.

Establish that any change to vendor payment details gets verified by voice, on a number you already had on file before the request arrived, never a number supplied in the email requesting the change. Apply it to every vendor without exception, and make it explicit that nobody is allowed to be annoyed about being called. One unnecessary verification call does not compare to the alternative.

Set a dollar threshold above which a payment requires two people. It does not need to be sophisticated approval software. It needs to be a rule that one deceived employee cannot move a large amount alone.

Finally, decide now who calls the bank, who files with ic3.gov, and who preserves the mailbox evidence, and put those three names somewhere that does not require access to your email to read. A plan stored only in the system that is currently compromised is not a plan.

If a payment has already gone out, the useful thing is a phone call and not a form. Innovation Network Design works with businesses across McKinney, Plano, and Frisco on exactly this situation, and our business email compromise response work starts with the recovery clock rather than a long assessment. Call 512-518-4408 if money has moved and you need help in the next hour. If nothing has happened yet and you want to know where the gaps are before someone else finds them, request a security assessment or reach us through our contact page and we will walk your payment approval process with you.

Frequently Asked Questions

Can a wire transfer actually be recovered after a fake invoice is paid?

Sometimes, and speed is the dominant factor. Banks can attempt a recall, and the FBI operates a process for contacting the receiving bank and freezing fraudulent domestic transfers when it is notified quickly. Recovery becomes far less likely once the funds have been withdrawn or moved onward, which is often a matter of hours rather than days. There is no guarantee, which is why the call happens immediately rather than after an internal investigation.

Should we call the police or the FBI first?

File with the FBI Internet Crime Complaint Center at ic3.gov, because that is the mechanism connected to freezing the funds, and a local police report on its own does not trigger it. File a local report as well if your insurer requires one, but do not let it delay the federal filing or the call to your bank.

Does cyber insurance cover money lost to a fraudulent invoice?

Often, but under a different section than most owners expect, and frequently with a lower limit than the main policy. This type of loss usually falls under funds transfer fraud or social engineering coverage rather than breach response, and some policies require that a vendor payment change was verified by a specific method for the claim to be valid. Read that clause before you need it, and notify your broker the same day an incident occurs, because these policies commonly impose short notification deadlines.

How do we know whether our mailbox or the one belonging to the vendor was compromised?

Read the full message headers on the fraudulent email and compare the sending domain character by character against the real one, then review your own mailbox sign in history and any inbox or forwarding rules for the weeks before the invoice arrived. If unfamiliar sign ins or attacker created rules appear on your side, treat it as your compromise and assume your client correspondence was read. If your side is clean and the headers trace back to the genuine vendor domain, the problem is theirs, and they need to be told today because their other customers are targets too.

Is this worth reporting if the amount was small?

Yes. Small first payments are frequently a test of whether your approval process catches anything, and the same attacker often returns within weeks for a much larger amount using access they still have. Treating a small loss as not worth the paperwork leaves that access in place. The response is the same regardless of the amount, and it is considerably cheaper the first time.

Need Help With This?

Innovation Network Design helps businesses across McKinney, Dallas, and nationwide with expert cybersecurity services.

M

Mark Sullivan

Innovation Network Design

With nearly a decade in cybersecurity and IT infrastructure, our team delivers expert insights to help businesses in McKinney, Dallas, and across DFW make informed security decisions. Have a question? Get in touch.

Ready to Secure Your Business?

Get a free security assessment and find out where your organization stands.