Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

A supplier changed the bank account on an invoice? Verify it before paying

A new bank account on a convincing invoice may be fraud. This practical verification process protects both the business and its supplier relationship.

PUBLIC RESEARCH
AUTHOR
/ CEO Breachroad · OSCP · PNPT
PUBLISHED
22 September 2026
READING TIME
15 min read
TOPIC
Human Security
A supplier changed the bank account on an invoice? Verify it before paying

The invoice looks familiar. The logo is right, the account manager’s name is right, and the message even contains part of an earlier conversation. Only the bank details have changed, accompanied by a short note: “Please send payments to our new account from this month.” The invoice is due today, so the natural reaction in accounts payable is to process it.

That is exactly the moment fraudsters exploit. They do not need to break into a bank or build a technically sophisticated attack. They only need to convince one person that the change is routine. Sometimes they imitate the supplier, sometimes they compromise a real mailbox, and sometimes they join an existing email thread. Correct language, genuine branding and conversation history are therefore not proof that the request is authentic.

What to do before releasing the payment

Pause the payment for a few minutes. Do not immediately reply to the message or use the phone number printed in it or on the new invoice. Open the supplier record in your accounting system, the original contract or a previously verified invoice. Call a known contact using a number the business already held.

Ask a specific question: did you change your bank account, when does the change take effect, and did you issue this invoice? If the account manager is unavailable, contact the supplier’s switchboard or finance team using details from its official website. An inability to confirm does not prove that the invoice is fake. It means the payment should wait.

Confirmation by email in the same thread is not enough. If the supplier’s mailbox has been compromised, the person who altered the payment details may also write the reply. Safe verification uses a second, independent channel.

Ask the control question without giving away the answer

Do not ask, “Does the new account end in 4821?” A fraudster can simply agree. Ask the person to provide the final digits, the bank name or the invoice number themselves. For a large payment, consider confirmation from two known people at the supplier, particularly when the contact is new or the explanation is unusual.

Record who confirmed the change, when the conversation took place and which known number was used. This is not paperwork for its own sake. It keeps the next colleague from repeating the investigation and gives the business a clear decision trail.

Warning signs that should stop a payment

The strongest warning is rarely a single spelling mistake. It is a financial change combined with pressure. Slow down when:

  • the account changes just before the payment deadline;
  • the sender asks you to bypass the normal process or keep the request confidential;
  • the account is in another country, currency or bank without a business explanation;
  • the domain differs from the genuine one by a single character;
  • the contact refuses a call and insists on email only;
  • the invoice also contains new contact details;
  • the message sits in a genuine thread, but the tone or request is unusual;
  • someone claims any delay will immediately stop delivery or trigger a penalty.

None of these points alone proves fraud. Together, they justify holding the payment and verifying it again.

Tax and account registers help, but do not close the case

Many countries provide tax or bank-account verification mechanisms for business payments. They are useful compliance checks, but they do not replace confirmation with the supplier. A listing in an official register does not tell you whether the message came from an authorised person or whether that account applies to this relationship and invoice.

A stamp, signature block or scanned letter is not enough either. Those elements can be copied from earlier documents. The decisive point is whether the change matches a supplier decision confirmed through an independent route.

A workable process for bank-detail changes

A good process can fit on one page. Every change to payment details should include:

  1. a request logged in the business system, not left only in one person’s inbox;
  2. confirmation through an established channel;
  3. a two-person review before the first payment to the new account;
  4. a record of who verified the change and when;
  5. additional scrutiny above a defined payment threshold;
  6. a clear explanation to suppliers that the rule applies to every bank-detail change.

The last point protects the commercial relationship. An employee should not apologise for checking or imply that the supplier is dishonest. A simple phrase works: “Our standing policy is to confirm every bank-account change by phone. It protects both organisations.” A legitimate supplier will usually understand.

Small businesses can still separate the decision

A small team may not be able to build a complex approval chain. It can still separate verification from execution. The person who receives the invoice confirms the change, while the owner or a second colleague compares the account before release. If one person performs every role, they should at least pause, revisit the document and make an out-of-band verification call.

The saved bank beneficiary should not be overwritten because of a single message. Add the new account as a separate record with the verification date and note. That leaves a useful history and makes future discrepancies easier to notice.

If the money has already been sent

Do not wait for the email sender to reply and do not first try to resolve the issue on your own. Contact the bank immediately through an official number, report suspected fraud and ask whether the transfer can be stopped or recalled. Time matters even when the payment already appears as completed.

Preserve the invoice, original message, complete thread, bank details, payment confirmation and a timeline. Do not delete the email or retain only a screenshot if IT may need the original headers. Notify the people responsible for finance, security or management, and contact the genuine supplier through an independent channel. The business should also report the incident to law enforcement and the appropriate incident-response body under its local process.

If the message came from a genuine supplier or employee mailbox, treat it as a possible account compromise as well: secure access, terminate suspicious sessions, inspect mailbox rules and review other conversations involving payments.

Do not turn accounts payable into the culprit

Bank-detail scams are designed to resemble ordinary work. Publicly blaming the person who released the payment makes it less likely that the next employee will report a concern quickly. A business needs a culture where people can hold a payment, call a supplier and say “this may be fraud” without punishment for a false alarm.

Training should cover more than spotting a lookalike address. Finance, procurement, sales and senior leaders should rehearse the exact bank-change moment: where to find the established contact, who approves an exception, and what happens if the payment has already left.

Source facts and Breachroad recommendations

The FBI describes Business Email Compromise as a fraud that uses messages appearing to come from a trusted source. One of its examples is an invoice from a familiar supplier with updated payment information. The FBI recommends independently verifying changes in account numbers and payment procedures through a known contact number and contacting the financial institution immediately after money is sent.

The two-person review, verification record, escalation thresholds and suggested wording for supplier calls are Breachroad recommendations. They should be adapted to the organisation’s size and payment values. Our guide to Business Email Compromise and executive impersonation covers related scenarios. Teams can practise this decision in realistic exercises during employee cybersecurity training.

SHARE / COPY