← Back to home
Free checker · for finance & CA teams

Did a vendor really change their bank details?

A supplier emails new banking details right before a payment run. Paste the email to catch business email compromise (BEC) and invoice-redirection red flags in seconds — before you redirect a rupee. Nothing you paste leaves your browser.

We scan for business email compromise (BEC) and invoice-redirection signals entirely in your browser — nothing you paste is sent, stored, or logged.

What invoice-redirection (BEC) fraud looks like

“Our bank details have changed”

The core move: a request to update a vendor's bank or payment details, supplied with a new account number, IFSC or UPI ID — timed near a real invoice or payment run so it looks routine.

A free-webmail or lookalike sender

The mail comes from a Gmail/Outlook/Yahoo address instead of the vendor's business domain, or from a lookalike domain with a swapped or added letter (acme-corp.co vs acmecorp.com) that reads right at a glance.

Urgency and secrecy

“Process before end of day.” “Keep this between us.” The pressure exists for one reason: to stop you picking up the phone and calling the vendor to verify the change.

A hijacked-thread reply

The most convincing version replies inside a genuine email thread from a compromised mailbox. Everything above the change request is real — which is exactly why the change request must be verified out-of-band.

The one check that stops it

1

Never change details from the email alone

Treat every bank-detail change as unverified until a person confirms it. The email — however genuine it looks — is never enough on its own.

2

Call back on a number you already hold

Ring the vendor on a phone number from your own records — a past invoice or your master data — never the number in the new email or its signature. Confirm the change verbally.

3

Hold the payment, then report

If anything is off, hold the payment first. Report the attempt on cybercrime.gov.in or call 1930. A held payment can be recovered; a sent one rarely can.

Screen every vendor email, not just this one.

This free tool checks one email you paste. ScamShield AI watches every email your finance team receives — flagging bank-detail-change requests, lookalike senders and invoice fraud automatically, so a redirected payment is caught before it is approved.

30-day free trial No credit card Data stays in India