Spotting a Fake Vendor Banking Change Before You Pay It

A walkthrough of what a fraudulent banking change request looks like, how to verify it, and a simple written procedure your accounts payable team can use.

3 min readBy Ironfield Cyber Team

Every accounts payable department receives legitimate requests to change a vendor's bank account. Companies switch banks, merge, and update processes. That is exactly why fraudulent requests succeed: they look like routine paperwork. The goal is not to distrust every vendor but to make verification automatic so that it does not depend on anyone's instincts that day.

This article walks through what these requests look like and how to build a procedure around them.

Anatomy of a fraudulent request

Consider a hypothetical example. A supplier that your company has paid for years sends an email to accounts payable. It says their bank has changed and attaches a form with new account details and a signature. The tone is polite and routine. The timing is two days before a large payment. The email address looks right at a glance.

In reality, the supplier's mailbox may have been compromised, or the sender may be using a lookalike domain with one letter swapped. The attached form may even use the real company's logo and previously seen layouts, copied from earlier messages the attacker read.

What to look at

The sender

Check the full email address, not just the display name. Compare the domain character by character with the one in your vendor file. Look at whether the reply-to address differs from the sender.

The context

Does the request arrive in an existing thread or as a new message? Is it timed unusually close to a payment? Does it ask you to change from check to ACH, or to send funds to an account in a different name or location than the vendor?

The content

Be cautious if the message urges haste, requests secrecy, or discourages calling. A person who really changed banks will not be offended by a verification call.

The documents

Compare any form with prior documents. Check that the account holder name matches the legal name of the vendor. A personal account, or an account at a bank in an unexpected state, is a red flag.

A written procedure that works

Document these steps and apply them to every change, from every vendor, regardless of size or familiarity.

  1. Log the request. Record who asked, how, and when.
  2. Do not reply to the email to verify. Replying goes back to the sender, who may be the attacker.
  3. Call a known number. Use a phone number from your vendor file, a signed contract, or the vendor's official website that you looked up independently. Speak with someone you already know if possible.
  4. Confirm the details. Verify the new account information verbally and ask what prompted the change.
  5. Second-person approval. A different employee reviews the verification record and approves the change in the system.
  6. First-payment check. For the first payment to a changed account, consider sending a small test amount or confirming receipt with the vendor before paying the full balance.
  7. Notify the old contact. Send a note to the contact already on file that the account was changed. If the change was fraudulent, this often reveals it quickly.

Handling pressure

Fraudsters rely on urgency and authority. Messages that appear to come from an owner or executive, instructing accounts payable to skip the usual steps, are a classic variation. Your policy should explicitly state that the procedure applies to everyone, including executives, and that staff will be supported when they insist on it.

Train with examples

Show your team realistic examples, including redacted samples of attempted fraud if you have encountered any. Practice the call-back steps. Short, regular reminders work better than a single annual session.

Reduce the attacker's opportunities

  • Require multi-factor authentication on all company email.
  • Alert on mailbox forwarding rules and unusual sign-ins.
  • Limit who can edit vendor banking fields.
  • Reduce the amount of payment information that appears in widely distributed emails.

If you find one

If you catch a fraudulent request, do not simply delete it. Preserve the message, report the compromised address to the vendor through a trusted channel, and let your IT provider check whether your own mailboxes are affected.

How Ironfield Cyber can help

Ironfield Cyber helps contractors and energy companies write practical payment verification procedures and secure the email systems that fraud depends on. We are happy to review your current process and suggest specific improvements.