The first thirty minutes
- Call your bank now and ask for a recall of the transfer. Minutes matter.
- Call the real supplier or executive by phone, on a number you already had, to confirm the request was fake.
- Preserve the email with full headers; the sending domain is usually one letter off the real one.
- Check the mailbox of whoever received the request for forwarding rules and unknown logins; the attacker may be inside your own email.
The next day
- Report to the police cybercrime portal and the fraud centre; large transfers can sometimes be frozen at the receiving bank within 24 to 72 hours.
- Tell every customer and supplier your domain may be impersonated.
- Make a rule: bank-detail changes are confirmed by phone on a known number, always, no exceptions for urgency.
Keep this evidence
- The fraudulent email with headers, the invoice, and the beneficiary account details.
- Bank reference numbers and the time of the transfer.
Do not
- Do not reply to the fraudulent thread.
- Do not send a second payment "to fix" the first.
Who to report to
Bank, fraud centre and police, in that order. Your cyber-insurer if you have one. Find the numbers and portals for your country in the reporting directory.
General guidance, not legal advice. If someone is in immediate danger, call your police emergency number.