AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / Threats

Threats

Auto Repair and the Trades: When Your Own Invoice Reaches the Customer With Someone Else's Bank Details

Invoice fraud in auto repair and the trades: how a shop's email gets read for weeks, why the customer pays a stranger, and the ten-minute fix that ends it.

Sam KhanSam Khan The Cyber ExpertFounder and CEOFebruary 15, 2027 · 6 min read

The fleet invoice that got paid to the wrong bank

A five-bay shop outside Columbus does fleet work: sixteen vans for a plumbing company, a dozen for a landscaper, a small municipal contract. The office manager sends invoices from a laptop at the counter, between phone calls, usually on Thursdays.

In November the plumbing company's controller receives an invoice from her for forty-one thousand dollars, covering brakes and tires across eleven vans. Same PDF layout as always. Same wording, same slightly cheerful sign-off, same reply address, one character different. It notes that the shop has moved to a new bank after "an issue with the old processor" and asks that this payment go to the new account. The controller pays it on the Friday.

Three weeks later the shop's owner calls the plumbing company about the outstanding balance. The controller forwards the thread. He reads it twice, then reads his own sent items, and finds nothing. Because it never came from his sent items. It came from a lookalike domain registered in September, written by somebody who had been reading his real mailbox since August, who knew the van count, the brake job, the Thursday habit and the way his office manager signs off.

The plumbing company still owes the money. They pay it, eventually, over four months, and they get their next brake job done somewhere else.

What the heck does this mean

This is business email compromise pointed outward. Most articles describe the version where a fake vendor tricks your bookkeeper into paying the wrong account. The trades get the mirror image: the attacker reads your mailbox, learns your customers and your rhythm, then bills your customers using your name.

Two pieces make it work. The first is access to your email, almost always through a password typed into a fake login page months earlier. The second is a lookalike domain, a web address one character off yours, registered for a few dollars, which is why the reply never reaches you.

Jargon translated. A mailbox rule is an instruction your email follows automatically, and it is the attacker's favorite hiding place, because it can quietly file the customer's reply where you will not see it. Funds transfer fraud is the insurance term for any payment that moves because of a lie. A lookalike domain is a spelling trick, usually a lowercase l posing as a capital I, or a hyphen added, or ".net" instead of ".com".

Shops in auto repair and the skilled trades get chosen for a specific reason. Invoices are large, irregular and expected. Nobody at the customer's end blinks at forty-one thousand for eleven vans.

The numbers that matter

Business email compromise accounted for USD 3.05 billion in reported losses across 24,768 complaints in the FBI IC3 2025 Internet Crime Report, and 86% of that money moved by wire or ACH. The transfer is done before anyone is suspicious.

The human element featured in 62% of breaches in the Verizon 2026 Data Breach Investigations Report. Not a genius attack. A busy person, a plausible email, a Friday.

Business email compromise and funds transfer fraud together made up 58% of claims in the Coalition 2026 Cyber Claims Report. In the insurer's data, this is the most common way a small business loses money to a computer, well ahead of anything involving locked files.

What to do this week

  1. Turn on multi-factor authentication for every mailbox in the shop, owner included, and have your IT provider switch off the legacy sign-in protocols that bypass it. Ask specifically about IMAP and POP. This one item removes the first half of the fraud. (CIS 6 Access Control Management)
  2. Add a permanent line to your invoice template and your email signature: our bank details have not changed and will not change by email, call this number before paying anything that says otherwise. Print the number. Your customers now have a rule they can follow without calling you first. (CIS 14 Security Awareness and Skills Training)
  3. Have someone pull the list of mailbox rules and forwarding addresses across all accounts today, then set an alert for any new one. Also check whether anyone still has access who left the shop, including the part-timer from last summer. (CIS 9 Email and Web Browser Protections)
  4. Register the two or three closest misspellings of your own domain. It costs less than a set of rotors per year and it takes the cheapest version of this attack off the table. (CIS 9 Email and Web Browser Protections)
  5. Make the callback rule apply in both directions. Nobody at your shop changes a supplier's bank details without phoning a number already on file, and nobody accepts a change to a customer's payment instructions by email either. Write it on a card and put it where the invoices get sent. (CIS 14 Security Awareness and Skills Training)
  6. Write down what happens in the first hour if money moves wrong: your bank's fraud desk number, your insurer's hotline, who calls the customer, and who preserves the email evidence instead of deleting it. Recovery odds fall by the hour. (CIS 17 Incident Response Management)

Where AccuSights fits

Our assessment checks the exact conditions this fraud needs: mailboxes without multi-factor authentication, forwarding rules that already exist, accounts belonging to people who no longer work for you, and lookalike domains sitting registered against your name. The Cyber Hygiene Test takes three minutes and tells a shop owner where he stands without a sales conversation. Our team implements the controls at a reasonable rate, from email protections to data loss prevention to scanning, and 15 minutes with an engineer is usually enough to close the two gaps that matter most.

Questions people ask

A customer paid a scammer using our invoice. Do we still get paid? Usually yes, and it will cost you the relationship anyway. The customer owes the debt to you, not to the account they wired it to, so legally the obligation stands. Commercially you are now asking a fleet manager to pay a large bill twice while his own boss asks why your email was the one being read. Expect a long conversation, a discount, and a permanent dent in the account.

How does an attacker read our email for weeks without anyone noticing? He signs in with a password harvested from a fake login page, then creates a mailbox rule that moves certain messages to a folder you never open, or straight to deleted items. Your mail keeps working normally, which is the point. The two things that catch it are an alert on new forwarding and inbox rules, and a review of sign-in locations. Both take your IT provider under an hour to set up.

What is the single fastest thing a five-person shop can do this week? Turn on multi-factor authentication for every mailbox, starting with the owner's and the office manager's, and switch off the old sign-in protocols that skip it. Then add one line to your invoice template stating that your bank details never change and giving a phone number to call before paying anything that says otherwise. That is roughly ten minutes of work and it removes both halves of this fraud.

You spent fifteen years earning the right to send that invoice; ten minutes of setup is a fair price for keeping your name on it.

Controls this post maps to

CIS 6 Access Control ManagementCIS 9 Email and Web Browser ProtectionsCIS 14 Security Awareness and Skills Training

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.