Subject: Urgent: Payment Approval Needed

It arrived on a Friday at end of month, directly from the CEO himself. The signature was fine, the tone on point (no hello, formalities skipped, and referring to everything as “urgent”). As part of the finance team, you needed to approve this payment “by COB today”. Bank details attached, the supplier has been waiting for weeks, just get it done ASAP.

For a phishing email, it really seemed to understand how things work out here.

A bit too well, in fact…

It’s 2026. Hackers and Phishing Scams are Smart Now:

Most people imagine Phishing emails as poorly typed essays full of spelling mistakes and payment links. Some still are (there’s a Nigerian prince desperately waiting to share his fortune for 20+ years now). Others, however, look like ordinary requests from people you genuinely work with.

Attackers have evolved, and they’re capable of copying real signatures, using legit addresses with minor differences, or even accessing a genuine company mailbox. They might take it one step further and refer to a project, supplier, or deadline by name.

The result? An Email that seems familiar enough that you act on it before inspecting properly. And that’s the point. Attackers want you thinking “I’d better sort this out” rather than “why are we skipping process?”

The Red Flags Were There All Along

The email had the CEO’s name, which is what got your attention.  Everything else deserved a closer look.

The payment was urgent, banking details changed, and the sender likely discouraged a phone call or message. Each detail was curated towards making a quick decision rather than asking why. Make no mistake, bosses do send urgent messages and suppliers do change banking details. The combination of all the above + pressure to act immediately? That’s a warning sign if we ever saw one.

What did the Finance Manager do Next?

They didn’t reply to the Email. Instead, they called the boss using the number already saved in their phone. Guess what? Boss knew nothing about the payment, and a closer inspection revealed that the sender address had been ever so slightly altered. At a glance, it looked like the company domain. At more than a glance, it really wasn’t.

The money stayed into the account, the original email went to IT, and someone very far away had a potential victim slip through their fingers.

The verification took less than a minute, whereas recovering the payment would have taken considerably longer (with much less certainty and significantly more paperwork. Plus a scolding).

Boss in your Inbox? Here’s how to Verify:

Any email regarding money, banking details, credentials, or containing a link deserves slowing down long enough to check it. Here’s our safety guide:

  1. Read the full sender address. Carefully. Look at the actual name, spelling, and domain.
  2. Treat a change of banking info as a process with due diligence.
  3. If they ask you to skip a step, don’t. Trust us on this one.
  4. Report anything that feels off immediately.
  5. Never escalate, circumvent, expedite, or reroute anything regarding payment. Double check if you need to, but don’t listen to the Outlook because you’re afraid of HR.

Training helps, but Processes help more:

Your payment process should protect staff to account for being busy, distracted, or dealing with someone impersonating their line manager.

Apply independent verification for changes to supplier banking details. Use second approvals for payments above a stipulated amount. Provide a clear pathway to report suspicious requests without making staff feel foolish for asking. Implement the correct email security, MFA, and account monitoring.

No single safeguard can catch everything. However, multiple small ones working together can make an expensive Friday seem like a great saving.

Honestly? The Boss can wait a Minute

A Phishing email doesn’t need to fool everyone. Instead, it just needs to fool someone.

If a request involves anything sensitive, including personal details and passwords, then verify this using contact details you already trust. A good boss can handle a quick phone call. A bad one will blame you if you don’t.

Vox helps businesses build stronger connectivity and security around the people and systems they rely on every day. Because “it looked like it came from the boss” is a terrible line to find in an incident report.