Callback Verification Done Right: Scripts and Phone Number Hygiene

Callback verification only works if you call a trusted number and ask the right questions. Learn a simple script and how to keep your vendor phone data clean.

3 min readBy Ironfield Cyber Team

Nearly every payment fraud guide tells you to verify bank changes by phone. Most contractors nod and say they do. Yet callback verification fails regularly, usually for one of two reasons: the number used was provided by the person requesting the change, or the call was a polite formality that did not actually test anything.

Doing it right takes only a few extra minutes and a little preparation.

The First Rule: Never Use the Number in the Request

If an attacker sends a request for new banking details, the contact information in that email, including phone numbers in the signature or on an attached form, is likely controlled by the attacker. Calling it confirms nothing, and a convincing voice on the other end will happily approve the change.

Use a number you already trust:

  • The number in your vendor master from the original onboarding, verified at that time
  • The number on a contract, a previous invoice from before the change request, or a past signed agreement
  • A number found independently through the company's official website or a business directory, when no trusted record exists

If you cannot find any trusted number, treat that as a red flag and escalate.

Clean Up Your Vendor Phone Data

Callback verification depends on the quality of the data you hold. Take time to:

  1. Confirm that every active vendor has at least one verified phone number and contact name on file
  2. Record when and how each number was verified
  3. Restrict who can edit contact information, since an attacker who changes the phone number and the bank account together defeats the control
  4. Alert a second person when contact details change
  5. Remove outdated contacts, such as former employees of the vendor

Choose the Right Person to Call

Speak to someone in the vendor's accounts receivable or finance function whom you know, or to the contact on file. Avoid asking the person who sent the email to verify themselves; their mailbox may be compromised, and the person on the phone may not be who they say.

Use a Script

A consistent script prevents the call from sliding into small talk. A sample outline:

  • "This is [name] from [company]. We received a request to change your payment instructions. I'm calling to confirm it."
  • "Can you tell me whether you sent a request to change banking details in the last few weeks?"
  • Ask the vendor to read back the new account details, rather than reading them to the vendor
  • Confirm the bank name, the last four digits of the account, and the effective date
  • Ask whether any other changes were requested
  • Thank them and document the call

Reading details to the person lets them say "yes" to anything. Asking them to provide the details tests whether they actually know them.

Document Every Call

Record the date, time, number used, person spoken to, what was confirmed, and who made the call. Attach the notes to the change request. This record helps if there is a dispute and shows that your control operated.

Add a Second Layer

For large payments or high-risk situations, add other checks:

  • Require a second employee to review the callback notes
  • Send a small test payment and confirm receipt before sending larger amounts, where practice allows
  • Delay the first payment to new banking details by a defined period
  • Use bank services that verify the name on the account

Handle Pressure

Attackers create urgency: "We will stop shipping materials if payment is not received today." Train staff that urgency is a reason to slow down. Give them permission, and backing from management, to say, "We will pay as soon as we finish verification."

Beware of Voice Tricks

Phone calls can be spoofed, and cloned voices are possible. Do not rely on caller ID. Place the outbound call yourself to a trusted number. For high-value requests, add a shared code word or a question only the real contact could answer, established in advance.

Extend to Customers

The same principle applies when you send payment instructions to owners or general contractors. Include a statement in your invoices that you will never change banking details by email alone, and give the customer a verified number to call. This protects them and you.

Make It Normal

Callback verification works best when it is routine and applied to everyone, including long-time vendors and senior executives' requests. Exceptions create the opening attackers look for.

Ironfield Cyber helps finance teams write payment verification procedures and scripts, and pairs them with email protections that make fraudulent requests harder to land. If you would like a review of your callback process, we can help.