

It always starts with someone getting into a mailbox. Sometimes it's yours. Sometimes it's your supplier's, and the two need different answers.
If it's yours, that is ours to prevent and to catch. We make the mailbox hard to get into and quick to notice when somebody does, so your customers never receive anything at all.
If it's your supplier's, no technology of ours stops the email arriving, because it genuinely came from them. What protects you then is a payment process that doesn't take email at its word, and a team who recognise the pattern. We help with both.
Most often through a password that was used somewhere else and turned up in a breach of that other site. No hacking is involved. They simply try the password on your email, and if multi-factor authentication isn't switched on, they're in. The second most common route is a convincing sign-in page that captures the password as it's typed.
You're in a much better position, but it depends on where it's applied and how. We regularly find it enabled for most staff and quietly missing for a handful, often long-serving accounts set up years ago that belong to exactly the people with payment authority. It's also worth checking whether older sign-in methods are still permitted, because those can bypass it entirely.
There is also a newer approach where an attacker sits between you and the real sign-in page, lets you approve the prompt as normal, then reuses the session that follows. Multi-factor authentication on its own does not stop that, which is why watching for sessions being used from unexpected places matters as much as having it switched on.
Ring your bank immediately, before anything else, and ask them to attempt a recall. Then change the password and sign out all sessions on the affected mailbox, check for forwarding rules the attacker may have left, and report it to the National Cyber Security Centre. Tell the supplier as well, because their mailbox may be the compromised one. Hours matter more than anything else at that point.
Sometimes, if you move quickly enough that the funds are still sitting in the receiving account. Once they've been moved on, which often happens within hours, recovery becomes unlikely. It's worth reporting regardless, because banks do freeze accounts already under investigation, but nobody should plan on the money coming back.
Check rather than assume. This is a type of loss where no system is technically broken into and the payment is authorised by your own staff, which is exactly the gap where cyber and crime policies often diverge. Cover for funds transfer fraud is frequently excluded, capped at a much lower sublimit, or only available as a specific extension. Worth a conversation with your broker either way.
Make it a rule that bank account changes are verified by phone, on a number you already had on file, never one from the email requesting the change. It costs nothing, requires no technology, and defeats the scam on its own. Everything else we do is there to catch the times someone is in a hurry.