Accounts-Receivable / Aging-Report Redirect
Attackers who access your systems study your accounts-receivable and then message your customers as 'you,' redirecting their payments to a fraudster's account.
Think a message like this reached you? You can check it right now.
What this scam is
After compromising a business email account, criminals review the accounts-receivable aging report to see who owes you money and how much. They then email those customers, posing as your business, with 'updated' remittance instructions — sending your incoming payments to the scammer's account. The customer thinks they paid you; you're left chasing 'unpaid' invoices. Securing email with strong MFA and verifying any remittance-detail change protect both you and your customers.
What it usually looks like
- Your customers receiving 'updated payment instructions' from 'you.'
- Payments that customers made but you never received.
- Signs your email/systems were accessed.
- New remittance accounts on your invoices.
Common warning signs
- Customers saying they paid an invoice you show as open.
- Changed remittance details on outgoing invoices.
- Unfamiliar email rules or logins on your accounts.
- Aging-report data appearing in scam messages.
Example wording scammers use
“(To your customers) 'Please note our remittance bank has changed; pay your outstanding balance to the account below.'”
These are illustrative examples written by ScamSplain, not real messages.
What the scammers want
- To redirect your incoming customer payments.
- To exploit access to your receivables.
- Hard-to-recover transfers.
What to do
- Secure business email with phishing-resistant MFA; monitor for rogue rules/logins.
- Tell customers to verify any remittance-change by phone before paying.
- Use consistent, documented remittance details and flag changes.
- Review AR access and logging.
What to do if you already responded
- Notify affected customers and your bank; attempt recalls.
- Reset credentials, remove rogue rules, and engage security.
- Report to ic3.gov and reportfraud.ftc.gov.