A supplier emails to say their bank details have changed. Your accounts team updates the record, the next invoice gets paid to the new account, and everything looks normal until the real supplier calls asking where their money went. That is invoice fraud, and it is why the National Crime Agency and the National Federation of Builders just launched a joint campaign aimed straight at the people who approve payments in construction firms.

The campaign targets accounts payable and finance staff rather than IT teams, because they are the ones fraudsters are actually trying to fool.

The scam is not a suspicious email

Picture invoice fraud and you probably imagine a badly worded message demanding an urgent wire transfer. That is not the version hitting construction right now. Criminals impersonate a supplier or contractor a business already works with, often through a compromised or spoofed email account, and ask for one small change: an updated bank account on an invoice the business already expected to pay. Nothing else about the request looks wrong. The project is real, the amount is real, and the contact has emailed before. The only thing that changed is where the money lands.

In one case reported in April 2026, a UK energy company lost £700,000 this exact way: a genuine invoice, a genuine supplier relationship, and a bank detail change nobody picked up the phone to confirm.

Why construction keeps showing up in the fraud numbers

The NCA and NFB point to three features of construction that make it an easy target: long chains of contractors, subcontractors and suppliers, frequent large payments, and heavy reliance on email to send and confirm payment instructions. Every extra link in that chain is another place a criminal can insert themselves, and every large payment is worth the weeks a fraudster will spend watching a mailbox before striking.

NCA press release announcing the joint campaign with the National Federation of Builders to protect against invoice fraud in construction

Report Fraud data cited in the campaign shows construction and manufacturing together made up roughly a quarter of all reported invoice fraud cases over the prior year, and the September 2025 numbers alone explain why the NCA acted now.

Invoice fraud losses reported in a single month £3.9M lost to invoice fraud in83 cases, September 2025 alone

That works out to more than £47,000 lost per case, on average, from a single month of reports.

The attempts are accelerating

Security firm Trustmi tracked a roughly fivefold year over year jump in payment fraud attempts, from 119 incidents in the first half of 2025 to 597 in the first half of 2026. In the US, the FBI’s 2025 Internet Crime Report, released in April 2026, put total business email compromise losses at $3.05 billion across about 24,800 cases, averaging roughly $123,000 per incident.

Payment fraud attempts reported, H1 2025 vs H1 2026 0200400600800119H1 2025597H1 2026

None of this is a phishing awareness problem. It is a verification problem.

Verify the change, not the email

The NCA’s guidance comes down to one habit: when a supplier or contractor updates their bank details, especially by email, call them on a phone number you already have on file, not one printed in the email, before any payment goes out. An email thread can be intercepted or spoofed end to end. A phone call to a number your business used last month cannot be faked the same way.

The invoice format is part of the defense

An editable PDF or Word invoice is exactly what a criminal needs: a document anyone with an email client can alter, attach, and forward with a changed account number, and nobody notices until the payment fails to arrive. A payable link tied to a specific invoice record works differently. The payment destination lives inside the platform that issued the invoice, not inside an email thread a scammer can quietly edit.

Editable invoice documentPayable-link invoice
Bank details can be silently changedYes, by anyone with the fileNo, tied to the invoice record
Payment trail if something goes wrongScattered across email threadsOne traceable transaction
What a scammer needs to redirect paymentAn email clientAccess to the platform itself

A BillyPaid invoice sends with a payable link locked to that specific invoice record, so a bank detail change cannot be slipped into an email thread and paid without anyone noticing.