Private digital intelligence bureau Lawful OSINT — Cyber monitoring — Due diligence
Analyst comparing two supplier invoices and their bank details before approving payment

Payment fraud guide · 12 min

Verify changed supplier bank details before paying.

A genuine invoice can arrive with a forged email, and an old conversation can be hijacked. Verify the change request, the channel and the beneficiary independently instead of relying on the document alone.

Published 26 September 2026Reviewed by IIS editorial team

At a glance

Four rules for a useful review.

  • Pause payment to the new account while the change is checked.
  • Call the supplier using a contact known before the request.
  • Require a second approver under the organisation's payment process.
  • Keep messages and approval records without circulating bank details unnecessarily.

Step-by-step method

A reproducible path from question to conclusion.

  1. 1

    Freeze the change

    Do not replace the account in the payment system or release the requested transfer. Record the due date, amount and people who received the request so that a parallel payment does not slip through.

  2. 2

    Preserve the message and invoice

    Keep the original email with its headers, the invoice and earlier exchanges. Record the actual sending address and any change of domain or tone, without treating one signal as a verdict.

  3. 3

    Reach the supplier independently

    Use the number already held in the supplier record or an official channel established before the request. Do not call a number in the email or revised invoice. Confirm the authorised contact and stated effective date.

  4. 4

    Apply dual control

    Have someone other than the person entering the change compare the confirmation, previous details, beneficiary and supporting document. Record what was checked, by whom and when.

  5. 5

    Decide and monitor

    If confirmation remains unavailable or contradictory, keep the change on hold and escalate to the finance owner. Once approved, monitor the first payment and retain the authorisation with the supplier record.

A familiar conversation may contain a fraudulent message

An old email thread or an invoice carrying the correct logo does not prove the new instruction came from the supplier. A compromised mailbox can reply within a legitimate conversation; an intercepted invoice can be altered while its other lines stay intact.

Compare the domain, beneficiary name, account history and commercial context. These clues guide the review, but a separate known channel must establish the change.

Treat a bank-detail change as a controlled event

The task is wider than spotting a suspicious email. A maintained supplier record, a second approval and separation between data entry and payment prevent a single instruction from redirecting funds.

An urgent closing date or conditional discount does not remove this control. Agree an escalation route in advance for times when the usual supplier contact cannot be reached.

If a transfer has already been sent

Contact the bank immediately through its official channel and ask about recall or blocking options. Alert the finance owners and internal response team; do not assume a recall can succeed.

Preserve the transfer order, references, original messages and approval timeline. Work with the relevant professionals to assess reporting and other payments that may use the changed details.

Common pitfalls

Four shortcuts that weaken the result.

Calling the supplied number

A number inserted into the request may connect directly to the fraudster.

Trusting the email thread

A compromised mailbox can write within a genuine conversation.

Approving alone

One person should not enter, confirm and release a sensitive payment.

Deleting the request

Original messages and timing help the bank and response team understand the case.

Practical questions

Frequently asked questions.

Is a company name beside the account enough?

No. The displayed name may be incomplete or unverified depending on the channel. Confirm the change with the supplier independently and follow the applicable bank process.

What if the supplier cannot be reached?

Keep payment to the new account on hold and escalate to the responsible owner. A commercial deadline does not justify bypassing the check.

Does a signed email or official-looking PDF prove the change?

No. Either may be copied or sent from a compromised account. Its value rises when paired with independent confirmation and a recorded approval chain.

Public references

Cybermalveillance.gouv.fr — bank-transfer fraud and changed details. French public guidance on an independent supplier callback, contacting the bank and preserving evidence.

Editorial scope

Written and reviewed by Internet Intelligence Service on 26 September 2026. This educational guide describes a lawful, defensive method. It is not legal advice, an emergency service or authority instruction.