In short
A business receives a message changing a supplier's invoice or bank-payment details The objective is typically to redirect a legitimate business payment to the fraudster.
What it is
The email appears to come from the real vendor or a compromised business mailbox. The victim is then pushed to pay an invoice to a new bank account controlled by the attacker.
How it starts
A business receives a message changing a supplier's invoice or bank-payment details.
What they tell you
The email appears to come from the real vendor or a compromised business mailbox
What they want you to do
Pay an invoice to a new bank account controlled by the attacker
How you lose money
redirect a legitimate business payment to the fraudster
What happens next
After the first successful step, the fraudster may demand more money/information, deepen account or device access, or disappear.
Warning signs
trust | urgency | routine | business email compromise | email takeover | domain spoofing
Where this is documented
India — officially documented by an Indian authority/regulator
How to avoid it
Verify payment-detail changes and executive requests through a second trusted channel; use MFA and domain/email controls; pause unusual urgent transfers.
If it already happened
Contact the bank/payment provider immediately if money moved; report financial cyber fraud promptly via 1930 and cybercrime.gov.in; preserve messages, transaction IDs, phone numbers and URLs. Alert finance/security teams and the receiving bank immediately, and preserve email headers and approval records.