News |  

29.09.2026

Invoice Fraud via Hacked Email Accounts: How to Protect Yourself

Have a question about this article?
Contact us here!

Cybersecurity

Cybercriminals are becoming increasingly sophisticated. In recent cases, we saw how a single stolen password led to a compromised email account and manipulated invoices issued in Titeca’s name. How does such an attack unfold, and how can you protect yourself against it?

Why We're Letting You Know About This

Recently, we have assisted several customers whose email accounts were compromised after their passwords were stolen through phishing. The attackers then searched for ongoing conversations and invoices and attempted to change payment information.

In both cases, the cause and the breach occurred outside of Titeca’s systems. However, as your trusted partner, we are happy to proactively keep you informed so that you can recognize suspicious activity more quickly and process payments securely.

How does an attack like that unfold?

1

The password is stolen. Through a phishing message, the attacker gains access to an email account. This usually happens without the user noticing.

2

The attacker is watching. Without multi-factor authentication (MFA), he can freely search through trusted contacts, ongoing conversations, and invoices.

3

A message or invoice is being tampered with. The attacker intercepts or forges an existing invoice, for example, by using a different account number.

4

The payment is going to the wrong account. Because the message comes from a trusted source, it appears to be legitimate. This could involve payments to the government, to Titeca, or to other partners.

What does Titeca do?

•We secure our own email systems using the technical measures available today.
•We analyze reported incidents and help affected customers, where possible, to assess the situation.
•We follow identifies recurring patterns of fraud and inform you, whenever necessary.
•We are committed to more secure channels for invoicing and payment, such as Peppol and direct debit.

How to Protect Yourself: 7 Tips

1

Enable MFA on all your email accounts.

A password alone isn't enough if it's intercepted or reused. Your email provider (Telenet, Proximus, Gmail, Microsoft 365, etc.) or your IT partner can help you with the configuration.

2

Verify any change to an account number through a second, independent channel.

Call your regular contact at a number you already know and ask for explicit confirmation.

3

Compare the payee with the payment details.

Take any warning from your bank regarding the verification of your name and account number seriously.

4

Choose more secure channels.

Use Peppol whenever possible, or set up direct debit for your payments to Titeca.

5

Be on the lookout for typical signs.

Consider time pressure, an unusual writing style, unexpected attachments or links, and requests for confidentiality.

6

Are you unsure? Don't click, don't pay, and don't reply.

Contact us through another, trusted channel. Never use the contact information provided in the suspicious message itself.

7

Report it immediately.

Notify your organization or IT partner and the supplier in question. Have you already made a suspicious payment? If so, contact your bank as soon as possible.

Do you have questions about an invoice from Titeca?

If you notice a change in your account number for no apparent reason, please contact your usual point of contact or account manager using the contact information you already have. We'll be happy to look into it with you.