Vendor Bank Account Change Email? Make This 5-Minute Call Before You Pay
A supplier’s email asking you to update bank details can look genuine—but it may redirect your payment to a fraudster. Learn the 5-minute callback process every finance team should use before paying a new bank account.
A supplier emails your accounts team:
“Please note that our bank account has changed. Kindly make all future payments to the updated account mentioned in the attached invoice.”
The sender name looks familiar. The logo is correct. The invoice format looks normal. The email thread may even appear to continue a real conversation.
But the bank account could belong to a fraudster.
This is known as vendor bank account change fraud, a form of Business Email Compromise (BEC). Criminals impersonate a real supplier—or compromise the supplier’s real mailbox—and send revised banking instructions. When the customer pays the next invoice, the money goes to the attacker instead of the legitimate vendor.jpmorgan
The simplest control is also the most powerful:
Never change supplier bank details based only on an email, WhatsApp message, Microsoft Teams chat, PDF invoice, or phone number included in the request. Call a known supplier contact using a number your company already has on file.
That five-minute call can prevent a loss that may take months to investigate and may be difficult to recover.
What Is Vendor Bank Account Change Fraud?
Vendor bank account change fraud happens when a criminal convinces a business to replace a supplier’s genuine bank details with a fraudulent account.
The scam can start in several ways:
- The criminal sends an email from a lookalike domain.
- The criminal compromises the real supplier’s email account.
- The criminal monitors existing invoice conversations.
- The criminal creates a fake invoice using the supplier’s branding.
- The criminal impersonates a director, manager, accountant or vendor contact.
- The criminal asks the buyer to use “new,” “temporary,” “audited,” or “urgent” bank details.
The request usually comes just before a payment is due, when the accounts team is busy and expects to receive an invoice.
The Fraud Path: From Email to Lost Payment
Here is how a typical vendor-payment redirection scam works.
Step 1: The criminal studies the relationship
The attacker identifies a business relationship between a buyer and a supplier. They may learn this through a compromised mailbox, public information, leaked documents, previous phishing, or a carefully crafted impersonation attempt.
They want to know:
- Which company pays which supplier
- Who works in accounts or finance
- Which invoices are expected
- Typical payment amounts
- Names of decision-makers
- Email style and signatures
- Bank-account details used previously
Step 2: The email looks familiar
The attacker sends an email that may look like it came from a known supplier.
Example:
textFrom: billing@gujaratpackaging.co.in Reply-To: billing@gujarat-packaging.co.in Subject: Revised Bank Details for Invoice GP-2026-1187 Dear Accounts Team, Please note that our bank account has changed due to an internal banking update. Kindly use the attached revised invoice and transfer the payment to the new account. Regards, Accounts Department Gujarat Packaging
At a quick glance, the email may look genuine. But the actual domain can contain an extra hyphen, letter, number, or spelling change.
Step 3: The invoice includes “updated” bank details
The invoice may use the real vendor’s:
- Logo
- Address
- GSTIN
- Invoice format
- Product or service details
- Purchase-order number
- Contact names
Only the bank account, IFSC code, UPI ID or beneficiary name has changed.
That one change is the entire fraud.
Step 4: Urgency is used to stop verification
The fraudster may write:
“Please process today to avoid a dispatch delay.”
“Our old account is under audit.”
“The account update is temporary.”
“Do not use the earlier details.”
“The management team is aware.”
“Please send the UTR once completed.”
The goal is to make your team feel that speed matters more than verification.
Step 5: The payment reaches a mule account
If the accounts team uses the changed details, the money may enter an account controlled by a fraudster or money mule. The funds can then be moved quickly through more accounts.
The legitimate supplier later follows up for payment, and the buyer discovers that the invoice was paid—but not to the supplier.
Why These Emails Are So Convincing
Vendor fraud does not always look like a poorly written phishing email.
The email may be convincing because the attacker has access to real business information. In sophisticated BEC attacks, criminals may compromise an actual vendor mailbox and send messages from the real address, making traditional “check the sender email” advice insufficient by itself.
The invoice can be real. The vendor can be real. The purchase order can be real.
The bank account may be the only fraudulent element.
That is why every bank-detail change must be verified outside the email conversation.
7 Warning Signs of a Supplier Bank Detail Change Scam
1. The supplier has suddenly changed bank accounts
A new bank account is not always fraudulent. Businesses legitimately change banks, accounts and payment processes.
However, every unexpected change must trigger an independent verification process—regardless of whether the email looks genuine.
2. The email asks for urgency or secrecy
Be cautious if the message says:
- “Pay today”
- “Do not delay”
- “Urgent settlement”
- “Keep this confidential”
- “Do not call because I am in a meeting”
- “Use the new account immediately”
- “We will send formal paperwork later”
Urgency is not proof of legitimacy.
3. The sender domain is almost—but not exactly—correct
Look carefully at the email address.
Example:
textReal vendor domain: accounts@gujaratpackaging.co.in Possible lookalike: accounts@gujarat-packaging.co.in accounts@gujaratpackaglng.co.in accounts@gujaratpackaging.in accounts@gujaratpackaging.co
A single hyphen, extra letter, number or changed domain ending can be enough to mislead a busy employee.
4. The “Reply-To” address is different
An email can appear to come from a familiar sender but direct replies to another mailbox.
Before replying to an invoice or payment-change request, check whether the Reply-To address matches the sender and your known vendor records.
5. The beneficiary name does not match the supplier’s legal name
If the invoice is from one business but the bank account belongs to an unfamiliar individual, unrelated company or generic name, stop the payment.
There may be valid exceptions, but they must be confirmed directly with the supplier.
6. The change is communicated only by email, WhatsApp or Teams
A message in any one channel can be manipulated or sent from a compromised account.
No bank-detail change should be accepted without independent verification through a known phone number, trusted vendor portal, signed process, or authorised in-person confirmation.
7. The message bypasses normal finance controls
Treat the request as high risk if it asks your team to skip:
- Purchase-order matching
- Invoice verification
- Vendor onboarding checks
- Management approval
- Two-person approval
- Call-back verification
- Documentation requirements
A supplier should not object when your company follows its normal security process.
The Five-Minute Callback That Stops Payment Fraud
Before updating any supplier bank account, call the supplier using a phone number that already exists in your verified vendor records.
Do not use the phone number shown in the suspicious email, attached invoice or WhatsApp message.
Use this script:
textHello, this is [Your Name] from [Your Company]. We received a request to update your payment bank details. For security verification, please confirm: 1. Your legal business name 2. The supplier or vendor code in our system 3. The invoice number and purchase order number 4. The account holder name 5. The new account number 6. The IFSC code 7. The reason for the bank-account change 8. The name and designation of the person who authorised the change
Then document:
- Date and time of the call
- Name of the person who confirmed the details
- Phone number used
- Invoice number
- Purchase-order number
- Verified beneficiary name
- Name of internal employee who completed the check
This record protects both your business and your supplier.
The “No Call, No Change” Policy
Every Indian SME should adopt a simple rule:
No call, no change.
This means supplier bank details cannot be added, edited or replaced until someone independently verifies the change through a trusted channel.
A practical policy can look like this:
textAny new supplier bank account: Independent callback + finance-manager approval Any change to an existing supplier bank account: Independent callback + two-person approval + 24-hour cooling period Any high-value payment to changed bank details: Independent callback + finance-manager approval + director approval
A 24-hour cooling period is especially useful when the request is unexpected. Fraudsters rely on urgency; a short delay gives your team time to verify the details.
A Safe Payment Process for Small Businesses
You do not need an expensive enterprise system to create basic payment controls.
Before payment
- Match the invoice to a valid purchase order.
- Confirm receipt of goods or services.
- Check the vendor’s GSTIN, legal name and address.
- Compare the new bank details with existing vendor records.
- Check the sender and Reply-To email addresses.
- Review whether the request is urgent, unusual or confidential.
- Call the supplier using a trusted number.
- Record the confirmation.
During approval
- Require two authorised people for high-value payments.
- Use separate roles for payment initiation and payment approval.
- Do not let one person create a beneficiary and release the payment alone.
- Set banking alerts for new beneficiaries and high-value transfers.
- Use transaction limits suitable for your business.
After payment
- Send payment confirmation only through normal approved channels.
- Reconcile invoices, purchase orders and bank transfers.
- Watch for unexpected supplier follow-ups claiming non-payment.
- Review any payment made to a newly changed account.
- Keep records for audit and investigation purposes.
What To Do If You Already Paid the Wrong Account
Act immediately. Payment-recovery options reduce as time passes.
1. Contact your bank right away
Tell the bank that you suspect a fraudulent or misdirected vendor payment.
Provide:
- Transaction reference or UTR number
- Payment amount
- Date and time
- Beneficiary account details
- Beneficiary bank and IFSC code
- Copies of the suspicious email and invoice
- A request to trace, hold, recall or freeze the payment where possible
2. Report the fraud in India
Call the National Cyber Crime Helpline:
text1930
File a complaint through the National Cyber Crime Reporting Portal:
texthttps://cybercrime.gov.in
Keep your complaint number, transaction details and evidence ready.
3. Preserve the evidence
Do not delete emails, chats, invoices, headers, attachments or payment receipts.
Save:
- The original email
- Full email headers, if available
- The altered invoice
- Payment confirmation
- Bank statements
- Call records
- Screenshots
- Supplier communication
- Internal approval records
4. Contact the real supplier
Use a known contact number. Tell the supplier what happened and ask whether their email account may have been compromised.
They may need to reset passwords, enable MFA, review forwarding rules and warn other customers.
5. Check for a wider email compromise
If a real mailbox may have been compromised, review:
- Recent login activity
- Mailbox forwarding rules
- Unknown delegates or permissions
- Deleted or hidden messages
- Sent-mail folders
- Email signatures
- Supplier-contact changes
- Other invoices or bank-detail requests
How to Protect Your Company Email
Vendor fraud is often a people-and-process problem, but email-security controls still matter.
Enable multi-factor authentication
MFA makes it harder for attackers to access a business email account using only a stolen password.
Use an authenticator app or security key where possible. Do not depend only on SMS when stronger methods are available.
Set up SPF, DKIM and DMARC
SPF, DKIM and DMARC are email-authentication controls that help receiving mail systems check whether an email claiming to be from your domain is authorised.
They do not stop every BEC attack, especially attacks from compromised real accounts, but they reduce domain spoofing risk. Email-security guidance commonly recommends implementing all three controls.powerdmarc
+1
Label external emails
Configure your email system to clearly mark messages that originate outside your organisation.
A visible “External Sender” label can help employees notice when an email appears to come from a director but was sent from an outside address.
Review forwarding rules
After a suspected compromise, check whether an attacker created a forwarding rule to secretly send invoice and payment emails to an external mailbox.
Train people using real examples
Give finance, procurement, HR, sales and leadership teams short examples of:
- Fake invoices
- Lookalike domains
- Changed bank details
- Executive impersonation
- Payment urgency
- Fake PDF or ZIP attachments
- Reply-To mismatches
- WhatsApp and Microsoft Teams payment requests
The purpose is not to blame employees. It is to make verification a normal and supported business habit.
How ScamShield AI Can Help
ScamShield AI can help your team review suspicious vendor emails, invoices, payment requests, links, attachments and banking-detail changes before payment is made.
Use ScamShield AI when you receive:
- An unexpected supplier bank-account update
- A new invoice from an existing vendor
- A payment request that feels urgent or confidential
- A changed UPI ID, account number or IFSC code
- A suspicious email address or Reply-To address
- A PDF, ZIP file, screenshot or document that needs checking
- A message from a director or manager asking for a transfer
ScamShield AI is an additional verification layer. It should support your process, not replace it.
The essential protection remains:
Verify the request independently. Verify the beneficiary independently. Then pay.
Frequently Asked Questions
What is vendor bank account change fraud?
Vendor bank account change fraud is a Business Email Compromise scam in which criminals impersonate a supplier or compromise a supplier’s email account and provide fraudulent banking details for invoice payment. The customer believes they are paying the supplier, but the funds go to an attacker-controlled account.jpmorgan
+1
Can a genuine supplier change bank details?
Yes. Legitimate suppliers can change banks or account details. The risk is not the change itself—it is accepting the change without independent verification. Always call a known supplier contact before updating payment details.
Should I reply to the supplier email to confirm bank details?
No. If the supplier email account is compromised or the sender is using a lookalike domain, the fraudster may receive your reply. Call the supplier using a phone number already stored in your verified vendor records.
What is a Business Email Compromise scam?
Business Email Compromise, or BEC, is a fraud in which criminals impersonate or compromise trusted business contacts—such as executives, vendors or partners—to trick employees into sending money or sensitive information.jpmorgan
+1
What should I check before paying a new vendor bank account?
Check the invoice and purchase order, supplier legal name, GSTIN, sender email address, Reply-To address, beneficiary account name, IFSC code and business reason for the change. Then complete an independent call-back verification using a known supplier phone number.
What should I do if I transferred money to a fraudulent vendor account?
Contact your bank immediately, request a hold or recall where possible, call 1930, submit a complaint at cybercrime.gov.in, preserve all emails and payment records, and inform the genuine supplier.
Can ScamShield AI detect supplier invoice fraud?
ScamShield AI can help identify suspicious fraud signals in vendor emails, invoices, payment requests, links, screenshots and bank-detail changes. However, it should be used alongside independent supplier verification and your internal payment-approval process.
Final Takeaway
The most dangerous invoice fraud does not always look fake.
The supplier can be real. The invoice can be real. The email may look genuine. The logo, GSTIN and purchase-order number may all be correct.
The payment destination may be the only thing that changed.
That is why every business needs one simple payment rule:
No call, no change.
Before you pay a revised supplier bank account, make the five-minute verification call.