Most security budgets go into technology that detects malware. That is sensible. It simply does not help against the attack that most reliably costs Swiss SMEs money.
An attack with no malicious code
Invoice fraud works without malicious code. A message arrives from a known supplier, in the usual tone. It carries a single piece of information: the bank details have changed.
There is nothing to block. No attachment, no malicious link, no anomaly. To any technical system this email looks like ordinary business correspondence. And to the person working through thirty invoices on a Friday afternoon, it looks that way too.
The attack is not aimed at your infrastructure. It is aimed at a moment of routine under time pressure.
The only defence that holds
Which is why only a habit helps here. Every change to bank details gets confirmed through a channel that is not the email itself:
- A call to the number you already have on file.
- Not the number in the message.
- Even when the sender looks familiar.
It costs two minutes and prevents a loss that quickly runs into tens of thousands.
The hard part is not knowing the rule. The hard part is that it still holds when things are urgent. And that only comes from having practised it before it mattered.