A supplier-payment email has diverted £38,740. What happens next?¶
A convincing email has caused a business to pay a genuine supplier's invoice into the wrong account. This walkthrough follows the investigation from the original message and lookalike domain to the receiving account, the onward movement of the money and two developing suspects.
You do not need to become an email engineer before starting. At each stage, examine what has been established, decide which line of enquiry follows and use the linked cards when the technical detail becomes useful.
The lines of enquiry can run together. The bank need not wait politely while the email header is being admired.
The case begins¶
Hartwell Fabrication regularly buys components from Ridgeway Components. Hartwell's finance officer receives an email in an existing invoice conversation saying that Ridgeway has changed bank accounts. The officer pays invoice RC-10482 using the replacement details.
The following morning Ridgeway asks why the invoice remains unpaid. Hartwell checks the payment and reports the matter. The money and the email now create separate but connected lines of enquiry.
Hi Jamie,
We have moved our invoice account. Please use the replacement details on the attached notice for invoice RC-10482 and future payments.
Martin
Accounts Manager
Ridgeway Components
Follow the investigation¶
01 · Protect the money and preserve the evidence
The payment has left Hartwell, but the receiving bank may still be able to restrict, trace or recover some of it.
The immediate financial action is to notify the relevant financial institutions through the available fraud process, identify the payment precisely and seek appropriate restriction, recall or tracing action. Record who was contacted, when, the reference given and what happened next.
At the same time, preserve the original email, its complete header, attachment, underlying links and mailbox context. Do not reduce the evidence to the screenshot somebody helpfully pasted into a report.
09:24 UTC
RC-10482PAY-77421- Email: preserve the native message and full header.
- Mailbox: retain the surrounding thread, rules and relevant audit material.
- Attachment: keep the replacement-bank notice in its original relationship to the message.
- Payment: retain the instruction, authorisation, transaction record and receiving details.
- Witness account: establish what the finance officer saw, checked and did.
- Business records: preserve the genuine invoice and earlier supplier correspondence for comparison.
Go deeper: How do I preserve an email properly? · Is a screenshot or forwarded copy enough? · Should I preserve the mailbox as well?
02 · Establish what the email actually represents
The message imitates Ridgeway, but its underlying addresses do not use Ridgeway's genuine domain.
The visible name, Martin Cole - Ridgeway Components, is what the recipient was invited to believe. The underlying From address is accounts@ridgeway-componants.example; Ridgeway's genuine domain is ridgeway-components.example.
The Reply-To address points somewhere else again: ridgeway.payments@postbox.example. That matters because a reply would leave the apparent supplier conversation and go to an account controlled elsewhere.
ridgeway-components.exampleUsed in established invoices and independently confirmed by Ridgeway.ridgeway-componants.exampleThe spelling is different even though the display name looks right.The suspicious email appears beneath genuine messages about invoice RC-10482. That could mean the fraudster copied the subject and quoted text, obtained an earlier email, or gained access to one of the mailboxes. A familiar-looking thread does not prove that every message in it travelled through the same accounts.
Go deeper: Does the From address identify the sender? · How do I establish whether messages belong to the same thread? · What is the difference between From, Reply-To and Return-Path?
03 · Read the delivery and authentication records correctly
The message authenticated successfully - but for the fraudster's lookalike domain, not for Ridgeway.
Hartwell's preserved message includes the following excerpt:
SPF, DKIM and DMARC have not failed. They show that the message used an authorised or aligned route for ridgeway-componants.example. They do not turn that lookalike into Ridgeway's genuine domain, and they do not identify the person at the keyboard.
Put simply: the authentication controls are doing their job. They are authenticating the wrong domain perfectly well.
A message trace from Hartwell's provider confirms receipt from 203.0.113.84 at 16:42:19 UTC. This gives the investigation a sending service, time and message identifier that can be used in the next provider enquiry.
Go deeper: What do SPF, DKIM and DMARC actually prove? · Which Received line can I trust? · What can timestamps in an email header tell me?
04 · Follow the domain and sending account
Registration and provider returns connect the lookalike domain and mailbox to details associated with Ellis Ward.
A domain-registration lookup shows that ridgeway-componants.example was registered nine days before the email. Public details are privacy-protected, but the registrar and email-service provider are identifiable. Defined enquiries are made using the domain, mailbox, message identifier, sending IP address and exact time.
SA-882041ellis.ward@postbox.example61429031Subscriber and financial records associate the recovery mobile and payment card with Ellis Ward. That makes Ellis a person of interest in the infrastructure line of enquiry. It does not yet prove Ellis personally registered the domain or sent the message; account details can be shared, misused or supplied by somebody else.
The account was accessed from more than one network, but the same browser identifier appears during domain setup, mailbox configuration and message submission. That continuity is more useful than treating a current IP lookup as a person's name.
Go deeper: Who may hold relevant email records? · What account-access records may exist? · What records may link an email account to a device?
05 · Follow the receiving account and onward money
Hartwell's payment entered an account in Sam Dyer's name and most of it moved to an exchange account associated with Ellis Ward.
The receiving institution preserves and supplies the account-opening, access and transaction records available through the appropriate process:
The receiving account was opened eighteen days earlier using identity material and a live image associated with Sam Dyer. The same registered handset identifier appears during account opening, beneficiary creation and approval of the £34,000 onward transfer.
The exchange return identifies customer AC-88214 as an account verified in Ellis Ward's name. It records receipt of the £34,000 and a later withdrawal using that account.
Sam is now a suspect in the receiving-account line of enquiry. Ellis is a suspect in both the infrastructure and onward-money lines. Those are evidence-based investigative positions, not final conclusions about knowledge, agreement or responsibility.
06 · Test whether the email and money lines converge
Independent records now place Ellis in both lines of enquiry and associate Sam with the account that received and moved the payment.
The recurring appearance of Ellis-associated details is not one magical identifier that solves the case. Its value comes from independent providers recording Ellis in the creation of the sending arrangement and the receipt of the onward money.
Sam's position also requires testing. A bank account in Sam's name is not automatically a confession, but the account-opening image, continuing handset identifier and rapid onward transfer require an explanation.
Go deeper: What corroboration should I look for? · Can an email identify the person who wrote it?
07 · Plan the next operational action around the suspects
The investigation has reached two suspects and a defined set of questions that further enquiries, interview and device evidence can answer.
The next operational steps should test the case built so far rather than merely collect more digital material because it exists.
- Which device created or administered the lookalike domain and mailbox?
- Which device submitted the payment-change email?
- How were the genuine invoice number, amount and conversation obtained?
- Who controlled Sam's receiving account and registered handset?
- Who controlled Ellis's exchange account and the withdrawn assets?
- What communications passed between Sam and Ellis before and after the payment?
- Were other lookalike domains, messages, receiving accounts or victims involved?
- Is there an innocent or different explanation for any of the account activity?
Depending on the evidence and applicable process, further action may include interviews, searches, device seizure or examination, additional provider returns and financial tracing. The operational plan should identify the accounts, devices, dates, records and questions already known so that the next team is not handed a vague request to “check the phones for emails”.
Finding the email on a device associated with Ellis, or banking access on a device associated with Sam, would be important. It would still need to be interpreted alongside possession, timing, account activity and the wider evidence.
What the investigation has established¶
The email moved the investigation because it exposed the infrastructure and accounts actually used. The financial records then provided an independent route to Sam and back to Ellis. Neither line carries the whole case on its own; together they justify treating both as suspects and asking much better questions.
If the evidence points somewhere else¶
This case follows a lookalike domain and two identifiable financial accounts. A different result changes the next line of enquiry: