Cybersecurity

The GHS 19M Threat: How Ghanaian Businesses Can Shield Themselves from Invoice & Email Fraud

An urgent invoice arrives in your finance department. It comes from a familiar supplier, references a legitimate transaction, and requests payment into a new bank account. Everything appears normal, so your accounts officer processes the transfer.

Days later, the supplier calls to ask why payment has not arrived.

That is when the truth emerges: the email was fraudulent, the payment went to a criminal, and your business has lost money.

This scenario illustrates the danger of Business Email Compromise (BEC), a form of cybercrime that exploits trust, business relationships, and weaknesses in email security.

For Ghanaian businesses, where email communication, electronic invoicing, internet banking, and Mobile Money increasingly support daily operations, invoice and email fraud present serious financial and operational risks.

The threat is not limited to large corporations. Small and medium-sized enterprises (SMEs), churches, educational institutions, suppliers, contractors, and public-sector organizations can all become targets.

The headline figure of GHS 19 million represents the scale of the threat being highlighted in this article, not a verified single incident or independently confirmed national loss figure. Regardless of the exact amount lost across Ghana, one successful payment diversion can cause substantial damage to an organisation.

The good news? Businesses can significantly reduce their exposure by combining strong email authentication, secure payment procedures, employee awareness, and appropriate technology.

In this guide, Sikaba Systems explains how invoice and email fraud works, how criminals exploit business communication, and what Ghanaian organisations can do to protect their money.

What Is Business Email Compromise (BEC)?

Business Email Compromise is a type of cyberattack in which criminals manipulate email communications to deceive individuals or organisations into transferring money, disclosing confidential information, or taking other unauthorised actions.

Unlike traditional spam, BEC attacks often rely on research and impersonation rather than obvious malicious links or attachments.

Criminals may impersonate:

  • A company’s managing director or chief executive.
  • A finance manager requesting an urgent transfer.
  • A legitimate supplier submitting an invoice.
  • A procurement officer coordinating a payment.
  • A business partner requesting updated banking details.
  • A lawyer or consultant handling a confidential transaction.

The attacker may use a fake email address, a compromised legitimate account, or a lookalike domain designed to resemble a trusted business.

For example, a company that normally communicates with accounts@abccompany.com might receive a fraudulent message from a domain that looks almost identical.

An employee who does not inspect the sender’s full address may never notice the difference.

The central weakness in many BEC attacks is not a lack of intelligence. It is misplaced trust in digital communication.

How Invoice and Email Fraud Works in Ghana

Understanding how these attacks happen is the first step towards preventing them.

1. Supplier Impersonation and Fake Invoices

A criminal impersonates a legitimate supplier and sends an invoice containing fraudulent payment details.

The invoice may include:

  • The supplier’s real company name and logo.
  • A genuine purchase order number.
  • References to previous transactions.
  • The correct name of the purchasing organisation.
  • A convincing invoice number and payment deadline.
  • A bank account belonging to the attacker.

The message may instruct the recipient to disregard previous payment details because the supplier has supposedly changed banks.

If the finance department processes the payment without independently verifying the change, the money may be transferred to the criminal’s account.

In Ghana, where businesses regularly deal with suppliers, contractors, distributors, and service providers, this attack can disrupt legitimate commercial relationships and cause significant financial losses.

2. Business Email Account Takeover

Instead of creating a fake address, criminals may gain access to a genuine business email account.

They might obtain credentials through phishing, password reuse, malware, or stolen authentication sessions.

Once inside, an attacker can study previous conversations to understand:

  • Who approves payments.
  • Which suppliers are regularly paid.
  • When invoices are normally processed.
  • How staff members communicate.
  • Which transactions are awaiting approval.

The criminal may then intervene in an ongoing email conversation, making the fraudulent message appear entirely legitimate.

Because the email comes from a real account, ordinary checks of the sender’s domain may not identify the compromise.

This is why email authentication must be combined with account security and payment verification.

3. Executive Impersonation

An employee receives an email that appears to come from the managing director, executive director, or another senior official.

The message requests an urgent transfer and insists that the transaction remain confidential.

The attacker may use language such as:

  • “Process this payment immediately.”
  • “This is a confidential transaction.”
  • “Do not delay this payment.”
  • “I will explain the details later.”

These instructions are designed to discourage employees from following established approval procedures.

A senior person’s email should never override an organisation’s financial controls.

Every payment must follow the same authorisation process, regardless of who appears to have requested it.

4. Fraudulent Bank Account Changes

One of the most dangerous invoice scams involves changing a supplier’s payment details.

A criminal sends a message claiming that the supplier has opened a new bank account or changed its payment arrangements.

The new details may involve a bank account or other payment destination controlled by the attacker.

The message may look routine, especially when the organisation is expecting an invoice.

The solution is straightforward: independently verify every change to payment instructions using a previously established and trusted contact method.

Do not use the phone number or contact details supplied in the suspicious email to verify the request. An attacker may control those details too.

5. Hijacked Email Conversations

Criminals may monitor a compromised account and wait for a genuine transaction to reach the payment stage.

They then send a message that fits naturally into the conversation.

For example, a supplier and a business may exchange several emails about a delivery. When the invoice is eventually sent, the attacker introduces a different payment account.

Because the surrounding conversation is genuine, the fraudulent instruction may be difficult to detect.

Businesses should therefore verify sensitive payment instructions even when they appear within an established email thread.


Why Ghanaian Businesses Need to Take Email Security Seriously

Email fraud is not simply an IT problem. It is a business risk that can affect cash flow, operations, customer confidence, and organisational reputation.

Financial Losses

Money transferred to a fraudulent account may be difficult to recover. Reporting the incident quickly can improve the chances of intervention, but recovery is never guaranteed.

For businesses operating with tight margins, even a single fraudulent payment can affect salaries, supplier obligations, and daily operations.

Operational Disruption

When money intended for a legitimate supplier is diverted, the business may still owe the original invoice.

This can result in delayed deliveries, interrupted services, contractual disputes, and additional administrative costs.

Reputational Damage

Customers and suppliers expect organisations to handle payments and sensitive information securely.

A successful fraud incident may weaken confidence in the affected organisation’s internal controls and digital systems.

Legal and Compliance Risks

An incident involving personal data, confidential business information, or regulated activities may also trigger legal and regulatory obligations.

Organisations should assess applicable requirements under Ghanaian law and seek professional advice when necessary.

Increased Pressure on Finance Teams

When businesses lack clear payment procedures, employees may be forced to make high-value decisions under pressure.

Well-designed financial controls reduce this risk by giving staff a consistent process to follow, even when a request appears urgent.


How to Protect Your Business with SPF, DKIM, and DMARC

One of the most important technical measures for preventing email impersonation is implementing three email authentication standards: SPF, DKIM, and DMARC.

These standards help receiving email systems determine whether messages claiming to come from your domain are authorised and properly authenticated.

They are especially important for organisations that send invoices, payment notifications, quotations, payroll information, and other sensitive business communications.

However, it is essential to understand their limitations: SPF, DKIM, and DMARC help protect your domain against certain forms of email spoofing, but they do not prevent every type of fraud or stop criminals from using compromised legitimate accounts.

Each standard serves a different purpose.

1. SPF: Sender Policy Framework

SPF allows a domain owner to specify which mail servers are authorised to send email on behalf of that domain.

This information is published in a DNS TXT record.

When a receiving email server checks an incoming message, it can compare the sending server with the domain’s published SPF policy.

If the sending server is not authorised, the message may fail SPF authentication.

Example

Suppose your business uses yourcompany.com for official email.

Your IT administrator configures an SPF record identifying the authorised email service providers.

When a criminal attempts to send email directly from an unauthorised server while impersonating your domain, the receiving server can detect that the sending server is not authorised under the relevant SPF policy.

How to implement SPF

  1. Identify every legitimate service that sends email using your domain.
  2. Check your email hosting provider’s recommended SPF configuration.
  3. Create or update the SPF TXT record in your domain’s DNS settings.
  4. Ensure you publish only one SPF record for the domain.
  5. Test the configuration and monitor authentication results.

Important: Do not copy an SPF record from another company without adapting it to your environment. An incorrect record can cause legitimate emails to fail authentication.

Also, SPF alone does not prevent every form of spoofing. It primarily checks whether a sending server is authorised for the relevant envelope-sender domain.

2. DKIM: DomainKeys Identified Mail

DKIM allows an email to carry a digital signature associated with the sending domain.

The sending system uses a private key to sign selected parts of the message. The receiving system retrieves the corresponding public key from DNS and checks the signature.

A successful DKIM check helps establish that the signed portions of the email have not been improperly modified and that the signature corresponds to the domain’s published key.

Why DKIM matters

Imagine your organisation sends invoices to clients.

DKIM helps receiving mail systems verify the message’s signature, providing an additional layer of protection against certain types of message manipulation and impersonation.

How to implement DKIM

  1. Confirm that your email hosting provider supports DKIM.
  2. Generate or obtain the required DKIM keys through the provider.
  3. Publish the specified public-key record in your DNS settings.
  4. Enable DKIM signing for outgoing messages.
  5. Send test emails and confirm that receiving systems report DKIM as passing.
  6. Establish a process for rotating keys when appropriate.

Many hosted email providers offer guided DKIM configuration.

For businesses using multiple services to send email, ensure that every legitimate sending service is configured appropriately.

3. DMARC: Domain-based Message Authentication, Reporting, and Conformance

DMARC builds on SPF and DKIM by allowing domain owners to publish instructions about how receiving systems should handle messages that fail authentication and do not meet the required domain-alignment rules.

It also supports reporting that can help domain owners understand how their domains are being used in email.

DMARC is particularly valuable because it helps organisations establish a policy for unauthenticated messages that claim to originate from their domains.

Understanding DMARC policies

DMARC supports three main policy options:

PolicyWhat it doesRecommended use
p=noneRequests no specific enforcement action under DMARC; supports monitoring through reports.Initial monitoring and assessment.
p=quarantineRequests that messages failing DMARC be treated as suspicious, often placed in spam or quarantine.A staged enforcement phase after reviewing legitimate email sources.
p=rejectRequests rejection of messages that fail DMARC.Stronger protection after legitimate sending services are correctly configured.

Receiving providers determine how they apply the published policy, so enforcement outcomes are not absolutely guaranteed.

A sample DMARC record

A basic monitoring record may look like this:

v=DMARC1; p=none; rua=mailto:dmarc-reports@yourcompany.com

This is an illustrative example, not a ready-to-deploy configuration.

Before publishing it, confirm that the reporting mailbox exists, that your DNS provider supports the record, and that the domain’s email configuration is correct.

The reporting address should be one your organisation controls. DMARC reports may contain technical information about email sources and authentication results.

How to implement DMARC safely

  1. Inventory all legitimate services that send email using your domain.
  2. Configure SPF and DKIM for those services.
  3. Publish a DMARC policy initially set to monitoring mode, where appropriate.
  4. Analyse reports to identify legitimate sending services and unauthorised sources.
  5. Correct authentication and alignment problems.
  6. Progress towards quarantine and, eventually, rejection when your organisation is ready.
  7. Review reports and authentication results regularly.

Moving directly to a strict rejection policy without checking all legitimate sending services can cause genuine business emails to be rejected.

SPF vs DKIM vs DMARC: What’s the difference?

FeatureSPFDKIMDMARC
Primary purposeChecks authorised sending serversVerifies a cryptographic email signatureEstablishes domain-alignment requirements and a policy for authentication failures
Uses DNS recordsYesYesYes
Helps detect spoofingYesYesYes, by combining authentication with alignment and policy
Provides reportingNot as a core featureNot as a core featureSupports aggregate reporting
Can stop all email fraud?NoNoNo

The best approach is to implement all three correctly rather than relying on one standard alone.


Seven Practical Ways to Prevent Invoice and Email Fraud

Technical email controls are essential, but they must be supported by strong internal procedures.

Here are seven measures every Ghanaian business should consider.

1. Verify Every Change to Supplier Payment Details

Treat every request to change a supplier’s bank account or other payment instructions as a high-risk transaction.

Require employees to contact the supplier using a telephone number or communication channel already on file.

For significant payments, consider requiring two authorised employees to approve the change.

Document the verification and approval.

2. Introduce a Two-Person Payment Approval Process

No single employee should have unrestricted authority to initiate and approve high-value payments.

Establish clear approval limits based on transaction value and risk.

For example, a small routine expense may require one authorised approver, while a major supplier payment may require approval from both the finance manager and another designated officer.

Set thresholds that match your organisation’s size and financial exposure.

3. Enable Multi-Factor Authentication

Multi-factor authentication (MFA) requires users to provide an additional verification factor beyond their password.

Enable MFA for:

  • Business email accounts.
  • Domain registrar accounts.
  • DNS hosting platforms.
  • Cloud administration accounts.
  • Financial systems.
  • Business collaboration tools.

Where supported, phishing-resistant methods such as passkeys or hardware security keys offer stronger protection against credential theft than passwords alone.

4. Use Strong, Unique Passwords

Never reuse a business email password across multiple websites.

If a low-security website suffers a data breach, reused credentials may give attackers an opportunity to access your business accounts.

Use a reputable password manager to generate and securely store unique passwords.

Establish a process for removing access when an employee leaves the organisation or changes roles.

5. Train Employees to Recognise Suspicious Emails

Cybersecurity awareness should extend beyond the IT department.

Train finance staff, procurement officers, managers, administrative personnel, and other employees to recognise warning signs such as:

  • Unexpected requests for urgent payments.
  • Changes to supplier banking information.
  • Slight variations in familiar email addresses.
  • Unexpected requests for confidential information.
  • Unusual instructions from senior executives.
  • Requests to bypass established approval procedures.

Encourage employees to report suspicious messages without fear of embarrassment or punishment.

6. Establish a Written Incident Response Procedure

Every organisation should know what to do if it suspects email or invoice fraud.

A basic response procedure should identify:

  • Who receives the initial report.
  • Who contacts the bank or payment provider.
  • Who secures potentially compromised accounts.
  • Who preserves emails, transaction records, and other evidence.
  • Who communicates with affected suppliers or customers.
  • Who determines whether legal or regulatory notification is required.

When fraud is suspected, speed matters.

7. Secure Your Business Website and Domain

Your domain name is part of your organisation’s digital identity.

Attackers may exploit weak account security or poor domain management to impersonate your organisation or interfere with email services.

Protect your domain by:

  • Enabling multi-factor authentication at your registrar.
  • Using strong, unique account credentials.
  • Limiting access to DNS management.
  • Keeping recovery information current.
  • Enabling domain locking where supported.
  • Monitoring DNS changes.
  • Configuring SPF, DKIM, and DMARC correctly.
  • Maintaining an inventory of authorised email services.

Businesses should also review website security, software updates, administrator permissions, and backups as part of their broader cybersecurity programme.


What Should You Do If Your Business Has Already Been Scammed?

If you discover that your organisation has transferred money to a fraudulent account, act immediately.

Do not wait for a lengthy internal investigation before contacting the relevant financial institution.

Step 1: Contact Your Bank or Payment Provider

Report the fraudulent transaction immediately.

Request urgent assistance with tracing the transfer, contacting the receiving institution where possible, and attempting to freeze or recover the funds.

If the payment involved Mobile Money, contact the relevant service provider through its official fraud-reporting channel.

Recovery is not guaranteed, but early reporting may improve the chances of intervention.

Step 2: Secure Compromised Accounts

If an email account may have been compromised:

  • Change the affected password from a trusted device.
  • Revoke active sessions where possible.
  • Enable or reset multi-factor authentication.
  • Review email forwarding rules.
  • Check mailbox delegates and connected applications.
  • Inspect account recovery settings.
  • Review administrator access and recent sign-in activity.

If an attacker has established persistence through forwarding rules or connected applications, simply changing the password may not be sufficient.

Step 3: Preserve Evidence

Keep copies of fraudulent emails, message headers, invoices, payment confirmations, and relevant correspondence.

Record the transaction amount, date, recipient details, and time the incident was discovered.

Avoid deleting suspicious messages before the necessary evidence has been preserved.

Step 4: Notify Relevant Authorities

Report the incident through appropriate Ghanaian law-enforcement and cybercrime-reporting channels.

Where personal data or other regulated information is involved, assess whether notification obligations apply under the relevant legal and regulatory framework.

Step 5: Contact the Genuine Supplier

Use previously verified contact information to establish what happened.

Determine whether the supplier’s account was compromised, whether its email was spoofed, or whether the attacker interfered with the communication between the two organisations.

Agree on a secure method for confirming outstanding payment obligations.

Step 6: Review Your Security Controls

After containing the incident, investigate how the fraud occurred.

Review email authentication, account access, payment approval procedures, staff awareness, and domain security.

The goal is not merely to resolve the immediate incident. It is to prevent the same weakness from being exploited again.


A Business Email Security Checklist for Ghanaian Organisations

Use the following checklist to assess your organisation’s readiness.

Security measureRecommended action
SPFConfirm that only authorised sending services are included.
DKIMEnable email signing and verify that signatures pass.
DMARCMonitor authentication results and progress towards enforcement.
Multi-factor authenticationEnable it for email, DNS, domain, and financial accounts.
Supplier verificationIndependently verify every change to payment instructions.
Payment approvalsIntroduce appropriate separation of duties and approval limits.
Password securityUse unique passwords and a reputable password manager.
Email monitoringReview suspicious sign-ins, forwarding rules, and account changes.
Employee trainingTrain staff to recognise and report BEC attempts.
Incident responseDocument escalation, evidence preservation, and recovery procedures.
Domain securityProtect registrar and DNS accounts against unauthorised access.
Periodic testingReview configurations and payment controls regularly.

Practical recommendation: Start with your email and domain configuration, then review payment procedures. Both areas must be addressed to reduce the risk of successful fraud.


Why Ghanaian Businesses Need a Systems-Based Approach to Cybersecurity

Many organisations invest in individual digital tools without establishing clear processes for how those tools should work together.

A company might use professional email, accounting software, cloud storage, and online payment services, yet still have no reliable procedure for verifying supplier account changes.

This creates a gap between having technology and operating securely.

Effective protection requires a coordinated approach involving:

People → Processes → Technology → Monitoring → Response

  • People: Employees understand the risks and know how to report suspicious activity.
  • Processes: Payments, supplier changes, and sensitive requests follow documented approval procedures.
  • Technology: Email authentication, access controls, MFA, and monitoring help reduce exposure.
  • Monitoring: Suspicious activity is reviewed before it becomes a larger incident.
  • Response: The organisation can act quickly when fraud is detected.

This systems-based approach is particularly important for growing businesses whose transaction volumes, employee numbers, and digital operations are becoming more complex.

Cybersecurity should not be treated as a one-time installation. It should be an ongoing business function.


How Sikaba Systems Can Help Your Business Build More Secure Digital Operations

At Sikaba Systems, we believe technology should do more than digitise existing activities. It should help organisations operate more efficiently, make better decisions, and manage risk more effectively.

Through business technology solutions and digital systems development, organisations can improve the way their processes, information, and operational tools work together.

Depending on your requirements, a business technology review may include:

  • Website and web application security considerations.
  • Review of digital workflows and access permissions.
  • Improvements to business process controls.
  • Secure design of custom web applications.
  • Better management of business information.
  • Recommendations for appropriate email and domain security controls.
  • Identification of operational weaknesses that increase fraud risk.

Email authentication and financial fraud prevention require appropriate technical configuration and clear internal responsibilities. Where specialist email security services or independent security testing are required, businesses should engage qualified professionals with the relevant expertise.

The objective is simple: build digital operations that support business growth without overlooking security, accountability, and trust.

Protect Your Business Before Fraudsters Strike

Do not wait until your organisation loses money to review its cybersecurity controls.

Start by checking whether your domain has correctly configured SPF, DKIM, and DMARC records. Review who can authorise payments. Verify supplier account changes independently. Enable multi-factor authentication and ensure your employees know how to report suspicious emails.

These measures are practical steps towards building a more resilient organisation.

If your business is expanding its digital operations, now is the right time to assess whether your systems, processes, and security controls are keeping pace.

Visit Sikaba Systems to explore digital solutions that help businesses work smarter, operate efficiently, and build stronger systems.

We don’t spam! Read more in our privacy policy

Leave a Reply