# The Invoice Scam Irish SMEs Miss

> Email scams cost Irish SMEs €18.9m in two years, FraudSMART says. Invoice redirection gets past spam filters and antivirus. One phone call stops it.

*Source: https://panoptic.ie/blog/business-email-compromise-invoice-scam-irish-smes-miss*

# Business email compromise: the invoice scam Irish SMEs miss

Invoice redirection fraud doesn't need a bad click or a piece of malware. It needs a convincing email and a routine payment run, and it has cost Irish SMEs close to €19 million in two years.

[David Griffith](https://panoptic.ie/about#david-griffith), Managing Director · 19 August 2026

![Infographic showing three icons (euro symbol, document, warning triangle) with statistics about invoice scams, and text describing prevention measures.](https://panoptic.ie/_astro/blog_business_email_compromise_invoice_scam_irish_smes_miss_92185f6616_avMQW.png)

In short

Business email compromise, most often invoice redirection fraud, needs no malware and no clicked link. A convincing email says a supplier's bank details have changed, and the next real invoice gets paid into a fraudster's account instead. FraudSMART data shows Irish SMEs lost close to €19 million this way over two years, with average losses of over €22,000 per incident. A phone call to a known number, made before you pay, stops it.

Your finance team can spot a dodgy link and would never open a strange attachment, yet none of that stops invoice redirection fraud. It needs no malware and no click. It needs one convincing email landing at the moment your accounts team expects it, and it has cost Irish SMEs close to €19 million in two years.

## Why this isn't a phishing-click problem

Standard phishing defences protect against malware and credential theft: email filtering, staff training on suspicious links, endpoint protection. Invoice redirection fraud, also called business email compromise, often carries no malicious payload at all. The email itself is the attack.

A fraudster compromises a real supplier's mailbox, or builds a domain that reads almost the same at a glance, then writes to your accounts team to say the bank details have changed. Nothing about that message trips a virus scanner. Nothing in it needs a click to succeed, only a bank transfer processed weeks later against a genuine invoice.

A business can pass every technical security check and still lose money this way. The control that matters here sits in your payment process, not your firewall.

## How the scam runs

The pattern reported by [An Garda Síochána](https://www.garda.ie/en/crime/fraud/my-company-has-been-targeted-by-an-invoice-redirect-ceo-fraud-what-should-i-do-.html) and by [FraudSMART](https://www.fraudsmart.ie/2025/04/10/sme-fraud-campaign/) is consistent:

1. A fraudster compromises or closely copies a real supplier's email account.
2. An email arrives stating the supplier's bank account has changed. No payment is requested yet.
3. Weeks pass. Nothing looks urgent and there's nothing to click.
4. A genuine invoice from that supplier arrives on schedule.
5. Your team pays it into the new account on file, the one the fraudster supplied, and the money is gone.

CEO impersonation runs a faster version of the same idea: an email that appears to come from a director, asking for an urgent transfer or for sensitive information, timed for when the real person is travelling or hard to reach.

## What it's costing Irish businesses

FraudSMART, the fraud awareness initiative run by the Banking & Payments Federation Ireland, publishes a rolling two-year total for email-related scam losses among Irish SMEs. Its [April 2025 figures](https://www.fraudsmart.ie/2025/04/10/sme-fraud-campaign/) put that total at €17.4 million, with invoice redirection alone accounting for €15.7 million between January 2023 and December 2024.

The [most recent figures, published in March 2026](https://bpfi.ie/almost-e19-million-lost-by-smes-to-email-related-scams-over-the-past-two-years-fraudsmart/), put the two-year total at €18.9 million, with average losses of over €22,000 per incident. These are overlapping two-year windows rather than a running tally, so the two totals can't be added together, but read side by side they describe a problem that is not going away.

In a survey of Irish business owners published alongside those figures, 67% said they had been targeted by a financial scam in the previous 12 months, while more than half (53%) said they had no fraud-awareness guidelines or training in place for staff.

That gap, not a missing antivirus licence, is where most of these losses start.

## The checks that stop it

None of the controls that work here are expensive or technical:

- **Verify bank detail changes by phone**, using a number you already have on file, never one supplied in the email requesting the change.
- **Require dual authorisation** on payments above an agreed threshold, so no single person can action a bank detail change or a transfer alone.
- **Train staff on this scam specifically**, separate from general phishing awareness, because the email itself often carries no obvious warning sign.
- **Check invoices against your existing supplier record** before paying, not only against the email that arrived.

The common thread is a phone call. Ten minutes spent confirming a change with a known contact, before it's actioned, closes almost the entire attack. It costs nothing and it's the one step a fraudster can't get around.

## Where this fits your wider security picture

This risk sits outside what most technical security testing measures. Our [penetration testing and vulnerability scanning](https://panoptic.ie/services/penetration-testing-vulnerability-scanning) work looks at whether your systems and your team can be tricked into clicking a link or handing over a password. Invoice redirection fraud tests your payment process instead, and a scenario built around it needs to sit alongside that testing rather than be assumed covered by it.

The fix lives in procedure as much as in technology. Getting dual authorisation and a callback policy written down, and followed, is exactly the kind of change that fits into a [Technology Success Program](https://panoptic.ie/services/technology-success-program) review alongside the rest of your security baseline.

## What to do this week

Write down one rule: no bank detail change is actioned without a phone call to a number you already hold on file, and no payment above an agreed amount goes out on one person's say-so alone. Share it with everyone who touches accounts payable, not only the finance team.

If your business has been targeted already, or you want help putting these checks in place, [get in touch](https://panoptic.ie/contact) and we'll talk through what a practical payment-verification policy looks like for your team.

What is business email compromise?

Business email compromise is a scam where a fraudster impersonates a trusted contact, usually a supplier or a company director, by email. It doesn't rely on malware or a malicious link. The email itself, asking for a bank detail change or an urgent payment, is the whole attack, which is why standard phishing defences often don't catch it.

How does invoice redirection fraud work?

A fraudster contacts your accounts team, usually posing as an existing supplier, to say their bank account has changed. No payment is requested at that point. When a genuine invoice arrives later, your team pays it into the fraudster's account instead of the supplier's real one, often without anyone noticing until the supplier chases payment.

How much has invoice fraud cost Irish businesses?

FraudSMART, run by the Banking & Payments Federation Ireland, reported €18.9 million in losses to email-related scams among Irish SMEs over a two-year period, in figures published in March 2026, with average losses of over €22,000 per incident. Its earlier release covering January 2023 to December 2024 put the equivalent two-year total at €17.4 million, of which invoice redirection accounted for €15.7 million. The two figures cover overlapping periods, so they aren't cumulative.

Can antivirus or spam filters stop invoice fraud?

Rarely. These emails often come from a genuinely compromised mailbox or a domain built to look almost identical, and they carry no malicious attachment or link for a filter to catch. The defence that works is procedural: verifying any bank detail change by phone, using a number you already hold, before acting on it.

What should I do if my business already paid a fraudulent invoice?

Contact your bank immediately. Fraudulent transfers can sometimes be halted or reversed if you catch them quickly. Report it to your local Garda station and to the Garda National Economic Crime Bureau, and keep a full record of the emails involved. Speed matters more than anything else at this stage.

[All blog posts](https://panoptic.ie/blog)

## Start with a free IT review.

You'll get a clear picture of where you're exposed today, and what it looks like to have your whole IT covered as one managed system. No obligation.

[Talk to us ](https://panoptic.ie/contact)[See how we onboard](https://panoptic.ie/how-we-onboard)
