## Purpose

Use this checklist when the company suspects that money may have been redirected, a fraudulent payment may have been made, or an attacker may be attempting to manipulate a financial process.

**Examples include:**

- Invoice fraud
- Supplier impersonation
- Business email compromise
- Executive impersonation
- Payroll diversion
- Fraudulent refunds
- Unauthorized bank-detail changes
- Payment account compromise

Speed matters. Financial institutions may have a greater chance of stopping or recovering money when contacted quickly.

## Incident Information

Incident ID: ____________________

Date/time discovered: ____________________

Reported by: ____________________

Finance incident owner: ____________________

Cybersecurity / IT owner: ____________________

## 1. Stop Further Payments

**Immediately consider:**

- Hold related payments.
    
- Stop pending transactions where possible.
    
- Prevent additional payments to the suspicious account.
    
- Temporarily restrict affected payment processes if necessary.
    
- Alert appropriate finance personnel.
    
Do not continue normal payments while the destination or requester remains in doubt.

## 2. Contact the Bank or Payment Provider

**If money has already been sent:**

- Contact the bank or payment provider immediately.
    
- Use the official fraud or emergency contact channel.
    
- Request recall, freeze, cancellation, or recovery action where available.
    
- Provide transaction details.
    
- Obtain a case/reference number.
    
- Record instructions received.
    
Bank/provider: ____________________

Contacted at: ____________________

Contact person: ____________________

Reference number: ____________________

Action requested: ____________________

## 3. Verify the Genuine Party

Contact the legitimate supplier, employee, customer, or executive through previously trusted contact details.

**Determine:**

- Whether they actually requested the payment or change.
    
- Whether their email account may be compromised.
    
- Correct payment details.
    
- When legitimate communications last occurred.
    
- Whether other fraudulent requests may have been sent.
    
Do not rely on contact details contained only in the suspicious communication.

## 4. Preserve Evidence

Preserve relevant:

- Emails
- Email headers where available
- Attachments
- Chat messages
- Payment instructions
- Invoices
- Bank transaction records
- Authentication logs
- Mailbox audit logs
- MFA records
- Forwarding rules
- Payment system logs
- Approval records
- Screenshots

Do not delete suspicious messages or accounts before evidence requirements are considered.

## 5. Secure Potentially Compromised Accounts

If account compromise is suspected:

- Revoke active sessions
- Reset compromised credentials
- Verify MFA settings
- Review MFA devices and recovery methods
- Review mailbox forwarding rules
- Review inbox rules
- Review mailbox delegates
- Review suspicious OAuth or third-party applications
- Review recent logins
- Review administrator changes
- Search for similar activity on other accounts

Do not assume changing the password alone resolves the compromise.

## 6. Determine the Scope

**Establish:**

- How many fraudulent messages were sent? ____________________

- How many payments were affected? ____________________

- Total potential exposure: ____________________

- Confirmed loss: ____________________

- Other recipients contacted by attacker: ____________________

- Other accounts potentially compromised: ____________________

- Other bank-detail changes: ____________________

- Other suspicious transactions: ____________________

## 7. Notify Appropriate Parties

Depending on the situation, consider notifying:

- Leadership
- IT / MSP
- Cybersecurity provider
- Cyber insurer
- Legal counsel
- Affected vendor or customer
- Payroll provider
- Payment processo
- Law enforcement or relevant fraud authority where appropriate

Record notifications in the Incident Communication Log.

## 8. Protect Other Transactions

**Review:**

- Recent bank-detail changes
- Pending payments
- High-value payments
- New suppliers
- Payroll changes
- Customer refunds
- Other transactions involving the affected parties
- Similar requests received by other employees

Warn relevant finance employees about the active fraud pattern without unnecessarily distributing sensitive incident details.

## 9. Record the Financial Impact

Transaction date: ____________________

Amount: ____________________

Currency: ____________________

Destination: ____________________

Bank reference: ____________________

Amount recovered: ____________________

Amount outstanding: ____________________

Insurance claim reference: ____________________

Other costs: ____________________

## 10. Correct the Control Failure

After immediate response, determine how the fraud succeeded or nearly succeeded.

**Consider improvements such as:**

- Independent bank-detail verification
- Stronger transaction approvals
- Separation of duties
- MFA improvements
- Better email security
- Mailbox monitoring
- Finance staff training
- Supplier verification procedures
- Stronger payroll change verification
- Executive impersonation procedures
- Reduced account privileges

Action: ____________________

Owner: ____________________

Due date: ____________________

## 11. Complete Post-Incident Review

**Once immediate financial and cybersecurity risks are controlled:**

- Complete the incident timeline
- Confirm financial outcome
- Document root cause
- Identify failed controls
- Assign improvement actions
- Preserve required evidence
- Review lessons with finance and leadership
- Update relevant procedures

## Practical Rule

If payment fraud is suspected, act immediately:

Stop the money, contact the bank, verify the genuine party, preserve the evidence, secure the accounts, and look for other affected transactions.
