Verify a Vendor Payment-Change Email Before Sending Money
A familiar supplier email that changes bank details is not routine administration. The mailbox may be compromised, the sender address may be imitated, or a legitimate conversation may have been copied. The safe decision is based on independent verification, not how polished the message looks.
This workflow gives a freelancer or small team a repeatable way to pause, verify, approve, and record a payment-instruction change without turning email into the only control.
Method note: This documentation-based workflow was reviewed August 12, 2026. The verification script and example are original and fictional. No fraud recovery, prevented loss, or client result is claimed.
Treat the Change as a New Instruction
Do not pay from the changed details, reply with account information, click a link, open an attachment, or call a number supplied only in the change message. Mark the payment as held pending verification and preserve the original message according to the business’s incident process.
The FBI’s Internet Crime Complaint Center describes Business Email Compromise as fraud targeting businesses and individuals who transfer funds, and recommends a secondary channel to verify account-information changes.
Check the Request Without Trying to “Prove” It From Email
Warning signs can justify extra scrutiny, but their absence does not prove legitimacy. Record:
- the full sender address and reply-to address;
- look-alike domains, changed spelling, or a new personal address;
- unexpected urgency, secrecy, or pressure to bypass approval;
- a new payment method, country, beneficiary, or account name;
- an invoice that does not match the purchase order, contract, amount, or normal timing;
- changes in writing style or established communication channel.
Do not forward the suspicious message to colleagues without following the approved reporting process; links and attachments can spread risk.
Use a Contact Route Already Trusted
Call a known vendor contact using a number from the signed contract, validated vendor record, or independently obtained official website—not the number in the change email. For higher-risk payments, require a second authorized person to participate or perform a separate verification.
The current IC3 guidance says to verify payment changes through a known telephone number. The FTC similarly advises contacting an apparent sender through a phone number, email, or site already known to be genuine when evaluating an unexpected message; see its phishing guidance.
Use a Neutral Verification Script
“We received a request dated [date] to change payment instructions for [vendor record/invoice reference]. Our policy requires independent verification. I will not read the new account details first. Please state the authorized requestor, reason for the change, effective date, beneficiary name, and the last four characters of the approved destination. A second approver may call back through our existing vendor record before any change is activated.”
Do not disclose full bank details, passwords, tax identifiers, or private account information during an unsolicited call. If the contact cannot verify the request, says no change was made, or asks you to abandon normal controls, keep the payment on hold and escalate.
Separate Verification From Approval
One person can verify the vendor; another authorized person should approve a material change or payment when staffing permits. The approver should compare the invoice, contract, vendor record, beneficiary name, amount, and effective date. A callback alone does not validate that the purchase itself is legitimate.
| Control | Record without exposing secrets |
|---|---|
| Message review | Date, sender domain, invoice reference, warning signs |
| Independent contact | Source of known contact information and person reached |
| Vendor verification | Requestor, reason, effective date, partial destination match |
| Second approval | Approver, date, decision, exception if any |
| Payment control | Hold/release status and transaction reference |
Fictional Example: A Convincing Thread
A fictional studio receives a reply inside an existing supplier conversation: “Our bank changed; use the attached details today to avoid a late fee.” The logo, signature, and prior invoice number are correct. The bookkeeper does not use the attachment. She calls the supplier’s accounts contact through the number in the signed vendor record. The supplier reports that its mailbox was compromised and no banking change was authorized. The studio holds the payment, preserves the message, warns its team through a trusted channel, and follows its reporting plan.
The lesson is not that every urgent request is fraudulent. It is that thread history and accurate details can coexist with compromise, so the approval must depend on an independent route.
A suspicious request can also expose an account-control problem. Review the mailbox and administrator accounts using the authentication decision guide, verify that recovery does not depend on the possibly compromised channel with an account-recovery drill, and record the owners and next checks in the digital security baseline.
If Money Was Sent
Contact the financial institution immediately, ask about recall or fraud procedures, preserve transaction and message records, and notify authorized business leadership. Report suspected Business Email Compromise to IC3 where applicable and follow local law-enforcement, insurer, contractual, legal, and privacy requirements. Recovery is not guaranteed, and delay can reduce available options.
When Email Approval Is Not Enough
Require stronger controls for new vendors, unusual countries, large or rushed payments, changed beneficiaries, executive requests, gift cards, cryptocurrency, payroll changes, and exceptions to normal purchasing. Build the verification rule before an urgent message arrives.
Boundary: This article provides general fraud-prevention information, not banking, legal, accounting, insurance, or law-enforcement advice. Follow the organization’s authorized payment policy and obtain qualified help for actual or suspected loss.
Comments
Post a Comment