The email is from a supplier you pay every month. It is polite, on-brand, and says they have switched banks, so please update the account for the next payment. Nothing about it looks off. That ordinariness is the point, because a redirected supplier payment is now the most common way a business quietly loses a large sum of money.
Vendor impersonation, a scammer posing as one of your suppliers to reroute a payment, has become the fastest-growing form of business email compromise, now the majority of such attacks. The requests look routine precisely so your accounts payable team acts on them. Here are nine versions of the “please update our bank details” request that should be treated as fraud until proven otherwise, and the one control that reliably stops the money from leaving.
The short version
Any request to change a vendor’s bank details is a fraud risk, no matter how legitimate it looks, because the emails, invoices, and even bank letters can all be faked or sent from a compromised mailbox. The single control that works is an out-of-band callback: before you change anything, phone the vendor on a number you already had on file, from your own records, not the number in the email or on the new invoice. Add dual approval for banking changes, and verify the account itself rather than the document. Never let urgency rush the payment.
Table of Contents
1. A bank change that arrives by email alone
The foundational red flag: a request to change payment details that comes only as an email, with no verification you initiate yourself. Email is trivially spoofed or sent from a hacked account, so an emailed change request proves nothing about who really sent it. Treat any banking change that lands in your inbox as unverified by default, and do not act on it until you have confirmed it through a separate channel you control.
2. “We’ve switched banks” with new account and routing numbers
This is the exact script of the scam: a message from a familiar supplier saying they have changed banks and asking you to update the account and routing numbers, often with an invoice attached. It is the template attackers reuse because it is so believable. The specific combination of a supplier, a bank switch, and new numbers should raise your guard every single time, however normal the rest of the email reads.
3. Urgency tied to a payment that is due
Fraudsters time these requests to pressure. The change arrives just before a large invoice is due, with a nudge to update the details quickly so the payment is not late. Urgency is a manipulation, not a reason, and a real vendor will not be harmed by a one-day verification. Any push to hurry a banking change is a reason to slow down, not speed up.
4. A new account at a different or distant bank
Look at where the money would go. A new account at a different bank than the vendor has always used, especially in another region or country, or an account in a personal name rather than the company’s legal name, is a strong signal of fraud. Legitimate bank changes happen, but a mismatch between the account holder and the vendor you know deserves hard verification before a cent moves.
5. A lookalike domain or altered reply-to
Check the actual address, not the display name. Attackers register domains one character off from the real one, or send from the genuine display name while the reply-to quietly points somewhere else. A message that looks like it is from your contact but comes from a subtly wrong domain is a classic compromise. Hover, read the full address, and be suspicious of any tiny discrepancy.
6. A change from a new or unfamiliar contact
Be wary when the request comes from someone you have not dealt with at the vendor, or from your usual contact but with a changed signature or slightly different tone. Fraudsters either compromise a real mailbox or invent a plausible new “finance” contact to make the ask. A banking change should be confirmed with a known person at the vendor, not accepted from whoever happens to be emailing.
7. A phone number you are told to call, or told not to
The scam anticipates verification and tries to control it. The email may helpfully include a number to call to confirm, which reaches the fraudster, or it may discourage you from calling at all. Never verify using contact details supplied in the request itself. If the message provides its own confirmation number, ignore it; the only safe number is the one you already had before this request appeared.
8. An official-looking bank letter as proof
Attackers know you want documentation, so they provide it: a convincing bank letter or PDF on letterhead confirming the new account. The problem is that these documents are easily forged or altered, and they pass the eye test while proving nothing. A document cannot verify itself. Confirm the account through a live callback to the vendor, not by admiring the paperwork attached to the request.
9. A request that quotes your real invoice or PO numbers
The most convincing version cites accurate details, your genuine purchase order or invoice numbers, correct amounts, real project names. That authenticity usually means the attacker has been reading a compromised mailbox and has your real correspondence. Correct details are not proof of legitimacy; they are a sign the fraudster has done their homework. Verify the banking change regardless of how right the surrounding facts look.
The control that actually stops it
One habit defeats nearly all of these. Before changing any vendor banking detail, make an out-of-band callback to a phone number you already had on file, pulled from your accounting system or the original signed contract, never the number in the email or on the new invoice. Confirm the change with a known person, verify the account rather than the document, and require a second approver for banking changes so no one person can redirect a payment alone. If a payment has already gone out, contact your bank immediately to try to recall it and report it to the FBI’s Internet Crime Complaint Center the same day, since speed is what makes recovery possible.
This article is general information, not legal or financial advice. Verify supplier changes through your own established processes, and consult your bank and a qualified professional about controls and any suspected fraud.
Frequently asked questions
How do I verify a vendor’s request to change bank details?
Call the vendor on a phone number you already had on file, from your accounting system or the original contract, not the number in the email or new invoice. Confirm the change with a known contact before updating anything, and require a second person to approve banking changes.
Why are vendor bank change requests so often fraud?
Because vendor impersonation is now the leading form of business email compromise. Attackers spoof or hack supplier email, send a believable “we switched banks” request, and reroute your payment. The requests are designed to look routine so accounts payable acts without verifying.
Can a bank letter or invoice prove a change is real?
No. Bank letters, PDFs, and invoices are easily forged or altered and prove nothing on their own. A document cannot verify itself. Only an independent callback to a known vendor number, confirming the actual account, reliably establishes that a change is legitimate.
What should I do if I already paid the fraudulent account?
Act immediately. Contact your bank to attempt a recall of the payment, notify the real vendor, and file a report with the FBI’s Internet Crime Complaint Center the same day. Fast action within hours gives the best chance of freezing or recovering the funds.
What is the biggest red flag in these scams?
A banking change requested by email with pressure to act quickly, verified only through details the request itself provides. Any change that discourages an independent callback, or supplies its own confirmation number, should be treated as fraud until proven otherwise.
The bottom line
A supplier asking to update their bank details is not a routine chore; it is the exact moment fraud tries to slip through. Treat every such request as unverified, and defeat all nine of these plays with one rule: call the vendor on a number you already had, confirm the account, and require a second approver, no matter how convincing the email, invoice, or bank letter looks. For another payment trap worth knowing, see our guide to the overpayment scam, and browse The Other Stream’s Business section.