3-minute read DataRoad
In summary
- Most fraud doesn't exploit software — explores pressure, hierarchy and trust.
- Invoice modification is the most profitable fraud in Portugal and leaves no technical trace whatsoever.
- No technology can prevent a payment authorised by mistake. What is preventing it is a procedure.
- The rule that resolves almost everything: bank detail changes are confirmed by telephone, at a number already known.
In this article
When talking about computer security, people think of firewalls and antivirus software. But most of the money that Portuguese companies lose to fraud does not go through a technical flaw — it goes through a transfer authorised by someone who believed what they were reading.
They are attacks that do not exploit software. They exploit haste, hierarchy and trust. And that is why no technology alone solves them.
The amended invoice
It is the most profitable scheme and the hardest to detect. This is how it works.
Someone compromises a supplier's mailbox — or the company's own — and watches in silence for weeks. They learn who invoices whom, the usual amounts, the tone of the messages, the deadlines.
When a real invoice arrives, intercept it and resend it with the IBAN changed. Everything else is authentic: the value, the reference, the conversation history, the signature. It frequently comes accompanied by a casual note — “we've changed bank, please update our details”.
Payment is made by someone who did their job correctly. The fraud is only discovered weeks later, when the real supplier asks about the overdue payment.
The rule that completely stops this fraud: Any change to a supplier's bank details is confirmed by phone, to a number they already had before — never to the number given in the email requesting the change. No exceptions, including for long-standing suppliers.

The urgent request from management
A message from someone in management to the accounts or treasury department. It is urgent, confidential, the person is travelling and cannot answer the phone. They are requesting an immediate transfer.
The details vary, but the structure is always the same and it attacks three things at the same time: urgency, so there's no time to think; authority, to discourage questions; and confidentiality, to prevent verification with colleagues.
These attacks are quite convincing nowadays: they use the right name, the right signature, and sometimes refer to real internal matters gathered from previous emails.
Organisation is the defence, not technology: no transfer above a set amount is made without confirmation via a second channel — and management must explicitly tell the team that they will never be annoyed at being asked for confirmation.
Credential theft
The gateway for both of the previous schemes is almost always the same: someone typed their password into a page that looked legitimate.
Fake authentication pages are now faithful copies. What gives them away is the address — and that is precisely what nobody checks when they are in a rush.
Three measures drastically reduce this risk:
- Two-factor authentication for everyone. It is the single measure with the best balance between effort and protection. A stolen password is no longer enough.
- Password manager. As well as preventing reuse, it has an underestimated advantage: it doesn't autofill credentials on websites whose address doesn't match the real one. It spots the fraud before the person does.
- Automatic forwarding alerts. Creating a rule to forward mail externally is the first step for anyone who compromises an account — and it goes unnoticed for months.
The procedures that work
Four simple rules, written down and known by everyone, that resolve the vast majority of cases:
- IBAN changes are confirmed by telephone, to a previously known number.
- Payments above a limit require two people. He who requests is not the one who approves.
- No urgent request dispenses with verification. Urgency is the attacker's tool, not a reason to skip steps.
- Anyone can stop a payment without having to justify mistrust. If the company culture punishes those who ask questions, no one asks.
And short, regular training with real examples. Not a two-hour session once a year that nobody remembers — fifteen minutes a quarter with concrete cases works better.
If it has already happened
Speed is everything. In the first few hours there is still a chance.
Contact the bank immediately to request the cancellation or recovery of the transfer — the sooner you do it, the higher the likelihood. Change the passwords of the accounts involved and end all active sessions. Check if any forwarding rules have been created in your mailbox. File a complaint with the authorities. And notify the supplier or client on the other end, because they are likely the ones who have been compromised — and other companies will be receiving the same invoices.
Then, and only then, figure out how they got in. Without that, it will happen again.
DataRoad helps companies implement IT security and strong authentication, within the managed IT services.
A chat before making a decision
Whether you’re tackling a specific problem, planning a move or simply looking for a second opinion, we always start in the same way: by understanding your situation before making any suggestions. No obligation, no jargon and no catalogues.




































































































