Protecting a Couture Client's Finances: How Our Atelier Screens Payment Emails Before a Single Stitch Is Cut
A couture atelier moves five-figure payments by email - prime phishing territory. Our four screening rules, borrowed from bank-email comparison.
A couture atelier handles sums that make thieves attentive. A single bespoke bridal gown represents hundreds of hours of hand-work and a five-figure commitment made across months of fittings, and every one of those payments travels by email. Over the years we have developed a discipline around financial correspondence, and it draws heavily on the side-by-side method used by Bank Mails, the editorial project that documents the emails banks actually send — fraud alerts, statements, fee notices — next to their phishing lookalikes. This is a guide for anyone whose business moves serious money by inbox: ateliers, galleries, studios, any craft practice where a client's trust is part of the product.
Why craft businesses are targets
We are, from a fraudster's perspective, ideal victims: high-value invoices, irregular payment schedules, clients who expect white-glove email, and no corporate IT department. A fake "payment reminder" or a forged wire-instruction update fits our workflow perfectly. The defense is not paranoia; it is reading discipline.
The side-by-side habit
The single most useful idea we borrowed from Bank Mails is comparison rather than intuition. Scam emails are engineered to feel right; the tell is never a feeling, it is a mismatch. We keep a small internal reference of what our actual banks' legitimate notices look like — headers, salutations, the exact phrasing of their fraud alerts — and every financial email gets checked against the genuine pattern, never against memory. What Bank Mails does publicly for major banks, any business can do privately for its own counterparties in an afternoon.
Our atelier's four rules
- Bank details never change by email. Wire-instruction updates arrive by email and are confirmed by telephone, using a number we already hold — never one printed in the email itself.
- Urgency is disqualifying. Genuine banks do not threaten account closure within hours. A fabricated deadline is the oldest lever in the kit, and it appears in nearly every lookalike we have compared against the real thing.
- Links are decoration; domains are fact. We read the sender domain character by character. The difference between the real bank and the fake is often a single letter, and it is always the whole story.
- One person verifies, another pays. No payment leaves the atelier on the say-so of whoever opened the inbox. A second pair of eyes reads the same thread. This costs us minutes and has already caught one convincing impersonation.
Teaching clients, not just staff
What the impersonation attempt actually looked like
Because rules are abstract until they meet a real email, here is the near-miss that built rule four. A client's production week: fittings scheduled, balance payment due within days. An email arrived in our shared inbox from what appeared to be the client's personal address — display name identical, thread history plausible — requesting a change of payment account "for administrative reasons," with correct invoice number and a warm tone our client genuinely uses. Only the domain's final two characters differed from her real one. The staff member who opened it followed the rules by habit: flagged it, called the number we hold on file, and the client, bemused, confirmed she had sent nothing. Total delay to the payment: one morning. Total damage: none.
We share this not because we were clever but because we were lucky once and disciplined thereafter. The email passed every intuitive test — tone, context, timing — and failed one mechanical test. That is the entire shape of modern fraud, and it is why intuition-based training fails and comparison-based training works.
Scaling the discipline as the atelier grows
Practices that work for a two-person atelier must survive growth, so we've written ours down the way a larger firm would. New team members spend their first afternoon on the comparison archive and our four rules, then complete a supervised mock payment — a fake wire-instruction change sent by a colleague — before touching the live inbox. Quarterly, we refresh the reference file of genuine bank notices, because banks redesign their templates and the reference file ages. And annually, we rehearse the worst case: a real-seeming instruction that arrives while the one person who verifies is unreachable, and what the second person does instead.
Craft businesses rarely think of themselves as financial institutions, but the moment you hold client deposits against months of production, you are one. The protections that scale are the boring ones: written rules, two-person verification, and a healthy disrespect for urgency. Our gowns take hundreds of hours; our clients' payments deserve the same protection of process.
The final layer is the client herself. When a bride receives an invoice from us, we have told her in advance exactly what our emails will and will not ask for. We will never request card details by email; we will never change account details without a phone call she initiates. It is the same principle a good bank uses, and it works because it removes the attacker's favorite tool: surprise. If your business correspondence involves payment instructions of any kind, studying the real-versus-fake comparisons in Bank Mails' archive of phishing examples is the fastest hour of training you can give your team — and unlike a fitting, it can be done from anywhere.