An invoice can be genuine while the payment instruction inside an email is not. An attacker may impersonate a supplier, compromise a real mailbox or reply inside an existing conversation. Treat a change of bank account, beneficiary or payment process as a separate approval event, especially when the sender insists on urgency or secrecy.
Verify before any transfer
- Do not pay from the emailed details yet. Save the original message and invoice; avoid replying with confirmation of your internal process or the contact number you plan to use.
- Retrieve the supplier's phone number from a signed contract, prior verified record or your organization's vendor system. Call that number, not one in the new email or attached invoice. Ask a known person to confirm the exact account change.
- Follow your organization's second-person approval process. Compare the beneficiary and account details character by character with the verified record; an almost-matching name is not proof.
- If a transfer already went out, alert your bank and internal finance/security team immediately with transaction details. Ask the bank whether a recall or fraud process can be started, and preserve the messages for a formal report.