According to the FBI's annual Internet Crime Report, the IC3, corporate email fraud — a scam where the criminal breaks into nothing, and just writes the right email at the right time — caused over USD 3 billion in verified losses in the United States in 2025. The exact figure, USD 3,046,598,558, puts this category in second place among all cybercrime types the FBI tracks, behind only investment fraud.

The pattern holds on the other side of the problem too. Verizon's Data Breach Investigations Report, the 2025 DBIR, measured a median loss of USD 50,000 per case, with 88% of the money leaving by wire transfer — the same route any legitimate corporate payment would use if nothing had been altered along the way.

For someone deciding at a Brazilian company, the number that matters is not the dollar figure: it is the mechanism. There is no virus to detect, no leaked password to change. The criminal reads the conversation between the company and the supplier, waits until the invoice is close to due, and swaps the account at the right moment — with the same signature, the same tone, and the same PDF attachment as always.

The scam that needs no break-in at all

The scam works two ways. In the first, the criminal actually breaks into the supplier's or the company's inbox — usually through a reused password or a click on a fake link — and spends days or weeks just reading. In the second, more common way, there is no break-in at all: the criminal registers a domain almost identical to the supplier's, swapping one letter or a dot, and joins the conversation as if it were them.

Either way, the moment chosen is always the same: right before the invoice is due. According to reporting from Correio Braziliense on this kind of fraud, criminals manage to intercept PDF invoices directly in the victim's inbox and alter the barcode and bank details inside the document, without changing a single word of the email text.

The sophistication keeps growing. The same reporting cites the security firm Redbelt Security, which maps more than two dozen variations of this scam, concentrated in five main vectors — and already logs cases where AI-cloned audio, imitating an executive's voice, pressures the finance team into approving payment without checking anything else.

In Brazil, the backdrop is one of growth. According to Febraban, financial fraud in the banking system totaled R$10.1 billion in 2024, up 17% from R$8.6 billion in 2023 — most of it concentrated in credit card and Pix fraud, but through the same entry point: social engineering, manipulating someone into acting against their own interest without realizing it. Brazil's federal police created the Tentáculos platform specifically to trace this kind of fraud between banks and victims.

A real case shows the effect. In October 2025, a corporate email fraud incident led Rede Amazônica, the largest affiliate of Brazilian broadcaster TV Globo, to rebuild its digital security from scratch — unifying email providers, requiring a second confirmation step beyond the password on every account, and centralizing who has access to what.

Why an email filter alone does not solve it

Why an email filter alone does not solve it

The common approach is to trust what already exists: the email provider's spam filter, antivirus on the machines, and the good judgment of whoever is in finance. The problem is that none of the three catches this scam. The email has no malicious attachment, no strange link, no technical alarm goes off — it is plain text, from a known contact, in a conversation that was already happening.

A standard email filter checks whether a message looks malicious, not whether the sender's domain is really the supplier's. An address with one swapped letter slides right through — and it slides past the eyes of whoever is rushing to close the payment before it is due, too.

The second gap is process, not technology. At most small and mid-sized companies, whoever receives the invoice also approves the payment, alone, without checking any other channel — and a supplier's bank account change, something that should raise a flag, arrives folded into the routine, in the same email as always, and no one picks up the phone to confirm it.

What has to be in place

A real control against this scam combines technology and process — neither one alone solves it.

Verification of the sending domain. A rule set up on the email provider flags when the sender's domain looks similar, but is not identical, to a known contact's — the kind of one-letter swap the human eye lets slide.

A second confirmation step beyond the password on finance and leadership inboxes. Those are the accounts worth breaking into, and the first ones a criminal tries.

Confirming any bank account change by phone, on a number already on file — never the one that came in the email. It is the one barrier a fake domain or a compromised account cannot simulate: the voice of someone already known, on a number that did not come from that message.

A second approval above a defined amount, with a second person reviewing before any transfer goes out — without relying on whoever received the email also being the one who releases the payment.

A minimum waiting period between request and payment for any out-of-pattern change, even with the invoice close to due. Urgency is this scam's favorite tool, and a minimum waiting period takes urgency out of the equation.

This is how Skills IT works: adjusting email filter rules to flag suspicious domains, reviewing who has access to the most sensitive inboxes, and helping the company design the double-check process before any payment goes out.

What changes for the company when this works

What changes for the company when this works

When these controls exist, the gain shows up in two places. The first is the money that does not leave through the wrong door — without relying on luck or on someone being suspicious at exactly the right moment. The second is what happens afterward: without a verification process, every supplier payment carries a quiet doubt, and that doubt steals time from whoever is in finance, double-checking what should already be checked by routine.

Inside a managed services contract like Skills IT's, this check is built into the same security support that already covers the rest of the infrastructure — it is not one more separate vendor to manage.

There is also a less obvious gain: with a record of past attempts, the company learns over time — it knows whether the volume of scams is rising, where they tend to come from, and adjusts the process before the next case, instead of finding the gap only after the money is already gone.

Four questions to bring to the next meeting

Before writing yet another internal policy, it is worth answering these four questions with finance and with whoever handles IT:

  1. Who confirms a supplier's bank account change, and through which channel? If the answer is "whoever received the email, by replying to that same email," the defense does not exist — confirmation needs to happen on a channel the criminal does not control.
  2. Is there an amount above which a payment requires a second approval? If not, every transfer depends on one person's judgment, on a day when they might be in a hurry.
  3. Does the email provider flag look-alike domains, or does it only block malicious attachments? These are two different problems, and this scam does not use any attachment at all.
  4. When was the last time someone tested the process, posing as a supplier asking for urgency? A process that has never been tested under pressure is an assumption, not a control.