Resource icon

A supplier emails new bank details for an invoice

An invoice can be genuine while the payment instruction inside an email is not. An attacker may impersonate a supplier, compromise a real mailbox or reply inside an existing conversation. Treat a change of bank account, beneficiary or payment process as a separate approval event, especially when the sender insists on urgency or secrecy.

Verify before any transfer​

  1. Do not pay from the emailed details yet. Save the original message and invoice; avoid replying with confirmation of your internal process or the contact number you plan to use.
  2. Retrieve the supplier's phone number from a signed contract, prior verified record or your organization's vendor system. Call that number, not one in the new email or attached invoice. Ask a known person to confirm the exact account change.
  3. Follow your organization's second-person approval process. Compare the beneficiary and account details character by character with the verified record; an almost-matching name is not proof.
  4. If a transfer already went out, alert your bank and internal finance/security team immediately with transaction details. Ask the bank whether a recall or fraud process can be started, and preserve the messages for a formal report.

Why replying to the thread is insufficient​

If a mailbox was compromised, an attacker may see your reply and answer convincingly. The FBI's business email compromise advisory recommends verifying payment changes in person or via a known number. Its earlier guidance describes separate communication channels for significant transactions. A bank may be able to intervene after a mistaken payment, but recovery is time-sensitive and never guaranteed.
Posted by
Jack
Views
6
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack