The invoice is expected, the shipment is real, and the sender knows exactly when the balance is due. Only one detail has changed: payment must go to a new bank account.
An international payment scam can hide inside an ordinary business conversation until a transfer is already gone. The message does not need to look strange when the criminal has learned how the deal is supposed to look.

Overview
The fraud may begin long before the invoice changes
Criminals study suppliers, importers, payment schedules, and employees with approval authority. They may compromise a mailbox, imitate an address, or approach a business as a completely fake vendor.
By waiting for a genuine order to reach its payment stage, the attacker can insert believable banking instructions into a conversation that finance staff already trust.
Cross-border transfers give criminals useful friction
Time zones, language differences, freight deadlines, intermediaries, and unfamiliar beneficiary banks can make unusual details seem normal. A request that would look wrong domestically may be excused as an international procedure.
Wire transfers can also move quickly through several institutions. Once the money reaches a controlled account and is dispersed, recovery becomes difficult.
A second channel is the most important control
The FBI advises organizations to verify any change in account number or payment procedure with the person making the request. That check must use contact details already known to the business, not those in the suspicious message.
Warning signs include:
- A supplier announces new banking details shortly before payment.
- The beneficiary name does not match the contracting company.
- The receiving country changes without a documented business reason.
- The sender insists that verification must remain inside email or chat.
- A revised invoice has different fonts, spacing, account numbers, or terms.
- Urgent customs, demurrage, inspection, or release fees appear unexpectedly.
- The request bypasses the buyer’s normal purchase-order or approval process.
- A supposed executive demands secrecy and discourages a telephone call.
Seven International Payment Frauds Businesses Encounter
A fake supplier can advertise machinery, electronics, vehicles, fabric, chemicals, or other goods it does not own. Stolen registration documents and polished catalogues make the company appear established.
Business email compromise takes a subtler route. The criminal gains access to a real mailbox or registers a lookalike domain, then changes the destination on a legitimate invoice.
Invoice manipulation can happen through an altered PDF, compromised accounting mailbox, or intercepted message. Every commercial detail remains correct except the bank account.
A fake freight forwarder or customs agent invents port charges, storage costs, inspection fees, insurance, or release payments. The demand arrives when delay feels expensive.
Advance-payment fraud begins with an attractive price and a request for a large deposit. After funds arrive, the supplier disappears, sends false shipping papers, or demands more money.
Chat impersonation moves the conversation to WhatsApp, Telegram, or another messaging service. A copied logo and familiar employee name make the new account feel like a convenient continuation.
A fake escrow or payment platform claims to protect both sides. In reality, the website, support team, and account dashboard are controlled by the same people running the trade scheme.
These categories overlap. A false supplier may also invent shipping fees, while a compromised vendor mailbox can direct the buyer to a fraudulent settlement portal.
The FBI’s business email compromise guidance describes spoofed domains, spearphishing, malware, and payment changes as common paths into this type of theft.

How the International Payment Scam Works
Step 1: The criminal maps the transaction
Public websites, trade directories, shipment records, social profiles, leaked credentials, and earlier phishing provide names and roles. The attacker identifies who negotiates, who invoices, and who releases money.
A compromised inbox can reveal purchase orders, expected amounts, delivery dates, invoice templates, and writing style. This intelligence turns a generic fraud into a precise intervention.
Step 2: A trusted identity is copied or taken over
The criminal may use the supplier’s real account after stealing its password. Another option is a domain with one substituted letter or a misleading display name.
When an email thread is copied into a fresh message, the quoted history can make the conversation look continuous. A hurried reader may not notice that the address changed.
Step 3: The attacker waits for the right moment
Fraud works best when an invoice is due or goods are waiting at a port. The request then fits an existing obligation rather than asking for an unexplained transfer.
Criminals sometimes create mailbox rules that hide the real supplier’s replies. Both buyer and seller keep writing, but the attacker controls which messages each side sees.
Step 4: New banking instructions are introduced
The sender blames an audit, currency issue, frozen account, tax review, correspondent bank, or temporary collection partner. A revised PDF places the fraudulent beneficiary in an otherwise accurate invoice.
The explanation often sounds administrative and dull. That is intentional because a routine change attracts less scrutiny than an emotional story.
Step 5: Urgency suppresses normal verification
The message says production will stop, storage charges will rise, or the shipment will miss its vessel. Finance staff are asked to prove cooperation by acting quickly.
If someone requests a call, the attacker may say the account manager is traveling or that compliance rules prohibit discussion by telephone.
Step 6: Internal approval is steered toward the wrong evidence
A fake executive email can tell an employee that leadership already approved the change. Altered documents, copied signatures, and a chat message create several pieces of apparent confirmation.
All of those items can still come from one compromised channel. Genuine dual control requires independent people and independently sourced contact information.
Step 7: The transfer is dispersed rapidly
The first recipient may be a money mule, shell company, or account opened with stolen identity information. Funds can then move to additional banks, payment services, or crypto exchanges.
Delaying the buyer with a fake bank review or shipping update gives the network time to move the balance beyond the initial account.
Step 8: The attacker manages discovery
When the real supplier asks about payment, the criminal may send a forged transfer receipt or claim an international banking delay. The buyer waits instead of contacting its bank.
Some operations request a second payment, promising to refund the first after compliance clears it. This turns one compromised invoice into a larger loss.
A Safer International Payment Approval Process
Every supplier should have a verified master record containing its legal name, bank details, trusted telephone number, and approved contacts. Staff should not replace that record from an email alone.
When banking instructions change, pause the payment and call a known supplier contact. Read the existing and proposed account details aloud without telling the caller which values you expect.
Require a second employee to approve beneficiary changes and large transfers. The reviewer should examine the underlying request, not merely click an approval button.
Separate vendor onboarding from payment release when staffing allows. A single compromised account should not be able to create a supplier, change its bank, and send money.
Use a clear call-back rule for urgent freight and customs charges. The team should contact the carrier, broker, port agent, or insurer through the existing contract or official website.
Compare the beneficiary’s legal name and country with the purchase contract. A legitimate third-party collection account should be explained and documented before the due date.
Configure bank alerts and transfer limits that reflect normal trade activity. A new beneficiary, unusual country, round amount, or out-of-hours approval should trigger extra review.
Protect email with multifactor authentication and disable legacy access where possible. Review forwarding rules, delegated access, login history, and recovery settings after any suspicious message.
Train employees with realistic examples based on the company’s own workflow. A finance analyst needs to recognize changes to bank details, while a buyer needs to question an unexpected shipping agent.
Write the exception process down before a crisis. Employees should know who can approve an urgent change, which number to call, what evidence to record, and when the payment must remain paused.
Test those controls with suppliers as well. Agree on named contacts and a verification phrase for sensitive changes, then review that arrangement when personnel or ownership changes.
The goal is not to distrust every foreign partner. It is to make one compromised message insufficient to redirect a valuable payment.
Company, Address, and Fulfillment Checks
The legal supplier must exist independently
Verify business registration, tax details, directors, website history, trade references, and the address through sources the supplier did not provide in a single packet.
Stolen certificates can describe a real company while the person contacting you has no connection to it. Call the registered office through an independently found number.
The operating address should match the promised activity
A seller of industrial machinery should be able to explain where goods are manufactured, inspected, stored, and loaded. A virtual office alone does not support a large physical operation.
For high-value orders, use an independent inspection service selected by the buyer. Confirm the inspector’s identity separately and verify serial numbers or inventory before release.
The bank relationship must make commercial sense
Ask why the beneficiary differs from the contracting entity and why the account is located in another jurisdiction. Obtain written documentation and verify it through the known supplier contact.
Do not accept tax efficiency, agent collection, or internal restructuring as a complete answer. Your bank may also identify regulatory or sanctions concerns.
Shipment evidence must come from real carriers
Check bills of lading, container numbers, booking references, and tracking directly with the carrier or freight forwarder. A PDF and a seller-controlled tracking site can both be fabricated.
Confirm whether the document is original, surrendered, amended, or merely a draft. Shipment paperwork is evidence to verify, not a substitute for verification.
What to Do if You Have Fallen Victim to This Scam
- Contact the sending bank immediately. Ask for a wire recall or fraud hold and request that it contact the receiving institution. Minutes matter, so do not wait for the supposed supplier to investigate.
- Notify the real supplier through a trusted route. Use the telephone number or contact stored before the disputed email. Determine whether either mailbox was compromised.
- Preserve complete records. Export emails with headers, attachments, chat history, invoices, approval logs, bank instructions, telephone numbers, and transfer confirmations. Keep the original files unchanged.
- Report the incident quickly. U.S. businesses can file with the FBI Internet Crime Complaint Center. Notify the relevant national cybercrime and financial authorities in every involved jurisdiction.
- Contain compromised accounts. Reset passwords, revoke sessions, remove malicious forwarding rules, review delegated access, and require multifactor authentication. Check adjacent mailboxes used by finance and executives.
- Search for additional altered transactions. Review recent and pending beneficiary changes, invoices, payroll requests, tax payments, and freight charges. The discovered transfer may not be the first attempt.
- Inform insurers and counsel. Follow notification deadlines in cyber, crime, cargo, and professional policies. Legal advice may also be needed for privacy, contract, and regulatory notices.
- Pause related payments without abandoning the shipment. Rebuild a trusted communication path with the genuine supplier and carrier before deciding what remains payable.
- Scan exposed computers. If an attachment, login page, or remote tool may have started the compromise, isolate the affected device and run a full Malwarebytes scan as part of a broader incident response.
- Block repeat phishing infrastructure. AdGuard can help stop access to many known malicious domains and ads, but payment changes still require human call-back controls.
- Communicate on a need-to-know basis. Give banks and investigators accurate details while avoiding public posts that reveal internal controls or alert the attacker before accounts are frozen.
- Reject private recovery agents demanding fees. No outside contact can guarantee a wire return. Work with banks, insurers, law enforcement, and verified legal advisers.
Frequently Asked Questions
Is every third-party beneficiary fraudulent?
No. Suppliers can use financing, factoring, or collection arrangements. The relationship must be documented and confirmed through an established contact before payment.
Can a signed invoice prove new bank details are genuine?
No. A signature image and complete invoice can be copied or altered. Verify the change through a separate channel and internal approval process.
What if the email came from the supplier’s real domain?
The mailbox itself may be compromised. A correct address increases context, but it does not replace an independent call-back for changed payment instructions.
Should we reply to test whether the sender is legitimate?
A reply stays inside the possibly compromised channel. Contact a known person using a number or system obtained before the suspicious request.
Can a bank always reverse an international wire?
No. A rapid recall and receiving-bank alert may help, but recovery depends on timing, remaining funds, institutions, jurisdictions, and legal process.
Does cyber insurance cover this loss?
Coverage depends on policy language, controls, notifications, and facts. Report promptly to the insurer and follow its evidence and mitigation requirements.
The Bottom Line
An international payment scam succeeds when a believable message becomes the sole authority for moving money. A real invoice and real shipment can still carry fraudulent bank details.
Make every beneficiary change survive an independent call-back, a second approval, and a commercial-reason check. That short pause is far cheaper than trying to recover a cross-border transfer after it disperses.