A supplier can be genuine while the payment instruction is fraudulent. The key control is to verify changes to bank details independently from the message that requested the change before the new beneficiary is used.
Create trusted contact and payment details when the relationship begins
When onboarding a supplier, record the legal business name, normal contact person, verified telephone number, payment terms and bank details in a controlled supplier record. The telephone number used for future verification should come from an independently established source, not from a later email requesting a bank change.
Keep supplier-master changes restricted to a small number of staff. The goal is to create a baseline that future requests can be checked against. If the finance team has no trusted record and relies on searching old inboxes each time, a convincing fraudulent email has a much easier path into the payment process.
Verify every bank-detail change using another communication channel
The NCSC recommends verifying important email requests using another method and specifically advises robust processes for changes to payment instructions and payments to new suppliers. Call the supplier on a number already held in the trusted record, use an authenticated portal, or speak to a known contact in person.
Do not use the phone number printed on the email requesting the change. An attacker who altered the bank details can alter the contact information as well. Record who verified the change, who they spoke to and when. For a material supplier, a two-person check is inexpensive compared with the loss from one diverted payment.
Apply stronger checks when the supplier or beneficiary is new
A new supplier has no payment history to compare. Verify the commercial relationship, the person requesting payment and the beneficiary details before the first transfer. Where appropriate, compare company details with official records or documents obtained independently, but remember that a real company name can still be used inside a fraudulent email chain.
For high-value first payments, consider a staged process: supplier created, bank details independently verified, beneficiary added, then payment approved by another authorised person. This separates several risky actions that would otherwise occur in one rushed session. The exact process should be proportionate to the value and the business's fraud exposure.
Separate supplier-master changes from payment approval where practical
Do not let one compromised finance account create a new supplier, amend the bank account and release a large payment without challenge. Use system permissions to separate these actions where possible. If the company is too small for full segregation, require explicit second-person review for changed bank details and unusually large first payments.
The NCSC advises least privilege and stronger processes for significant payment actions. The second approver should review the beneficiary change, not merely the invoice total. A dual-approval process adds little value if the second person assumes the first person already checked the new bank account.
Treat urgency, secrecy and unexpected bank changes as reasons to slow down
Business Email Compromise can use a genuine compromised mailbox, so grammar and branding are weak fraud tests. The NCSC warns that criminals may impersonate regular contacts and ask for money to be paid into a different bank account. Messages can contain real conversation history and correct invoice details.
Escalate requests that combine bank-detail changes with pressure such as "pay today", "do not call the usual contact" or "the old account is closed". Also investigate changes that arrive shortly before a large invoice is due. Staff should have explicit permission to pause a payment while they verify, even when the request appears to come from a senior employee or important supplier.
If money may have gone to the wrong account, contact the bank immediately
The NCSC advises businesses that believe they have made a fraudulent payment to contact their bank directly using official contact details and notify the organisation's IT or security contact as soon as possible. Speed matters because fraudsters can move the money onward rapidly.
Preserve the email thread, invoice, payment confirmation and account logs. Check the affected mailbox for suspicious rules or forwarding. Then fix the process failure, not just the individual mistake. If a changed bank account could be accepted from one email with no independent verification, the control should be redesigned before the next supplier payment is released.
Editorial Verdict
Supplier verification should make a bank-detail change harder than sending an email. Maintain trusted supplier contacts, verify changes through an independent channel and require a meaningful second check for high-risk first or changed payments.
Do not assume a familiar email thread is proof of authenticity. A compromised mailbox can make a fraudulent request look completely normal. If a suspicious payment has already been sent, call the bank immediately and investigate both the payment process and the email account.
Sources
- NCSC, Business payment fraud: https://www.ncsc.gov.uk/section/respond-recover/business-payment-fraud
- NCSC, Business email compromise guidance: https://www.ncsc.gov.uk/pdfs/guidance/whaling-how-it-works-and-what-your-organisation-can-do-about-it.pdf
- NCSC, Cyber Security Toolkit for Boards, supplier-bank-detail fraud example: https://www.ncsc.gov.uk/collection/board-toolkit/principle-e-assurance-and-oversight/implementing-effective-cyber-security-measures
- NCSC, Introduction to identity and access management: https://www.ncsc.gov.uk/guidance/introduction-identity-and-access-management