Is a supplier who changed their bank details by email legitimate?
Bank detail change requests by email are a top vector for business payment fraud. Always verify any bank detail change by calling your supplier on a known number before making any payment.
Last reviewed: 1 August 2026
Explanation
Business email compromise (BEC) fraud exploiting bank detail changes is one of the most financially damaging scam categories for businesses. A fraudulent email appears to come from a genuine supplier, law firm, or business partner, explaining that their bank details have changed and asking you to update your records before the next payment. The email may use a near-identical domain, a compromised email account, or a forwarding rule that copies real communications.
The compromised-account version is the hardest to spot, because the request arrives from the supplier's real address, mid-thread, quoting genuine invoice references and written in the correspondent's usual tone. Attackers who control a mailbox often watch it for weeks, learn the billing cycle, and time the 'new details' message just before a large payment is due. Nothing about the email itself can prove it safe — which is why the defence has to live outside email entirely.
The solution is a strict process: any request to change bank details must be verbally confirmed using a contact number you already have on file — never one provided in the email requesting the change, since that number rings the fraudster. Many businesses add a dual-approval rule so no single employee can action a detail change alone. If a payment has already gone to a fraudulent account, call your bank immediately to attempt recall, notify the real supplier from known contact details, and report to your national fraud service; recovery odds fall sharply with every passing hour.
Common red flags
- Email requests a bank detail change ahead of an upcoming invoice
- Sender email domain is slightly different from the supplier's normal address
- Request asks you to update records urgently before a payment is due
- New bank details are in a different country from the supplier's usual account
What to do now
- Do not update any payment details based solely on an email
- Call your supplier on the number in your existing records — not in the email
- Verify the new details verbally before processing any payment
- If you already paid, contact your bank immediately to report the misdirected payment
Frequently asked questions
What security controls can businesses put in place?
A dual-authorisation rule for bank detail changes — requiring two staff members to independently verify any supplier detail change by phone — significantly reduces this risk.
The email came from the supplier's real address with correct invoice details. How can it be fraud?
Because the supplier's mailbox itself may be compromised. Attackers send from the genuine account, inside real threads, with accurate references. Authenticity of the mailbox is not authenticity of the instruction — only a call-back to a known number is.
We already paid to the new account. What should we do first?
Call your bank's fraud line immediately and request recall of the payment — speed is the biggest factor in recovery. Then warn the real supplier through known contacts, preserve the emails, and report to your national fraud service.