"Our Bank Info Changed": The Invoice Scam Hitting Southwest Ohio Businesses

The email looks completely normal. It's from a vendor you've paid every month for years — same name, same logo, same friendly sign-off. There's just one small update: their bank changed, so this month's payment needs to go to a new account. Your bookkeeper updates the file and sends it, exactly like always.

Three weeks later, the real vendor calls. They never got paid. They never changed their bank. And the money your business sent is already gone — pulled out of an account that was opened just to catch it.

That's business email compromise, and it's one of the most expensive scams aimed at small businesses today. The good news: it's also one of the most preventable, because it relies on a broken process far more than any fancy hacking. Here's how it works and how to shut it down — in plain English.

The scam in plain English

Business email compromise — BEC for short — is when a criminal impersonates someone you trust to trick your team into sending money or changing payment details. There's usually no virus and no dramatic break-in. The attacker simply pretends to be a vendor, your boss, a contractor, or an employee, and asks for something that sounds routine.

It works because it targets people and process, not firewalls. And the numbers are sobering: in its 2024 Internet Crime Report, the FBI's Internet Crime Complaint Center (IC3) tied business email compromise to $2.77 billion in reported losses across 21,442 complaints in a single year — making it one of the costliest cybercrimes in the country (source: FBI IC3 2024 Internet Crime Report). Small businesses are squarely in the crosshairs, because they're the least likely to have a formal check on who's allowed to move money.

Why small businesses get hit hardest

It's rarely about being careless. It's about being small and trusting:

  • One person often handles the bills, so there's no second set of eyes.

  • Everybody knows everybody, so an email "from the owner" doesn't get questioned.

  • The owner is out on a job or on the road, so "I can't talk right now, just handle it" feels believable.

  • There's no written rule for verifying a payment change, so whoever's at the keyboard makes the call.

None of that is a technology problem. It's a process gap — which is exactly why the fix is mostly about process, not expensive software.

The versions you're most likely to see

BEC wears a few familiar disguises:

  • The vendor "bank change." A supplier you know emails new banking details for your next payment. This is the classic, and the costliest.

  • The urgent boss request. A message "from the owner" asks for an immediate wire or a batch of gift cards, usually with a reason you can't easily check.

  • The fake invoice. A bill arrives for software, advertising, or supplies you might actually use — hoping it gets paid on autopilot.

  • The payroll swap. An "employee" emails to update their direct-deposit account, quietly rerouting their next paycheck.

Red flags worth training your whole team to catch

Most of these scams share the same tells. Teach everyone who touches money or email to stop when they see:

  1. change in payment details — a new bank, a new account number, or a "temporary" account.

  2. Urgency plus secrecy — "do this now," "don't loop anyone in," "I'm in a meeting, just email me."

  3. look-alike email address — createchinnovations.com becoming createch-innovations.com, or an "o" swapped for a zero.

  4. reply-to address that doesn't match the sender you think you're talking to.

  5. A request that skips the normal process you'd usually follow.

Your anti-fraud playbook

You don't need enterprise software to beat this. You need a handful of habits everyone follows, every time:

  1. Call to confirm any payment change — using a number you already have. Never the number printed in the suspicious email. A 30-second call to your vendor's known line stops the number-one version of this scam cold.

  2. Require a second approval for wire transfers, new payees, and any change to banking details. Two people, always.

  3. Treat urgency as a stop sign, not a green light. Real requests survive a verification call; scams fall apart under one.

  4. Lock down your email. Turn on multi-factor authentication for every mailbox, use strong and unique passwords, and set up email authentication so impostors can't easily spoof your domain. (We walked through the technical side in our post on stopping email spoofing with DMARC.)

  5. Write the rules down and train to them. The person at the keyboard is your last line of defense — make sure they know they're allowed to slow down and check.

  6. Have a "money already left" plan. Decide in advance who calls the bank and how fast, because minutes matter.

If it already happened, move fast

If a payment has already gone out, speed is everything. Call your bank immediately and ask them to recall or freeze the transfer — recovery odds drop by the hour. Report it to the FBI's IC3 at ic3.gov, which can help flag the receiving account. Then reset the passwords on any email account involved and switch on multi-factor authentication if it wasn't already. Businesses that act within the first day or two have a far better shot at getting funds back than those who wait.

Where CreaTech comes in

Most small businesses don't need a security department — they need the right handful of protections set up correctly and someone to call when something looks off. That's what we do. CreaTech is an independent, business-only technology advisor for Southwest Ohio, and we help owners put the practical layers in place: multi-factor authentication on your email, domain protection so you're harder to impersonate, and straightforward guidance your team will actually follow. Because we're carrier-neutral and coordinate your internet, phones, and IT under one roof, you get a single point of contact instead of a stack of vendors pointing at each other.

We work with businesses across Wilmington, Dayton, Cincinnati, Beavercreek, Centerville, Xenia, Lebanon, Blanchester, Sabina, and Washington Court House.

Don't let a routine-looking email cost you

The unsettling part of business email compromise is how ordinary it looks. The reassuring part is how ordinary the defense is: a phone call, a second signature, and a team that knows it's okay to pause. Put those in place before you need them.

Want a quick check of your email security and payment safeguards? Reach out through our contact page or call us at (937) 556-4123. A short conversation now is a lot cheaper than a wire you can't get back.

CreaTech Innovations LLC is an independent technology advisor serving small businesses across Southwest Ohio with business internet, phone, IT, printing, and toner. We're vendor-neutral, business-only, and your single point of contact.

Next
Next

The Copper Landline Is Going Away: What Southwest Ohio Businesses Need to Do Before Theirs Does