What it means
A supplier sends what looks like a routine invoice, but the bank account has changed, and the email may be genuine, compromised or forged. Finance should verify the change through a trusted independent contact route before paying.
The FBI Internet Crime Complaint Centre describes business email compromise as a common way to redirect payments and advises verification and prompt reporting, though its US reporting route does not replace local bank and police procedures elsewhere. JPMorgan's guidance warns that callbacks can fail when staff use a number supplied in the suspicious request, so a verification call must use a previously trusted source, not the same message being checked.
Require independent verification for bank-detail changes by using a known contact from a reliable prior record and documenting who confirmed what, since a reply to the same email thread is not independent. Check invoice context too, because purchase order, goods receipt, contract and vendor history can reveal mismatches and a convincing logo is not proof that work was done.
Map the payment path by asking who creates a supplier, changes bank details, approves invoices and releases funds, since one person controlling every step creates an avoidable weakness. Segment duties so the person entering bank details is not the only one approving the payment, with smaller teams using owner review or bank controls suited to their size, and use dual approval where risk warrants it, remembering that both approvers need enough information to make a real review because rubber stamps add little.
Set transaction limits so higher amounts or first payments to a new beneficiary require stronger checks, and scrutinise invoices split just below a threshold. Watch urgent executive requests, because a message claiming that a secret deal needs immediate payment should still follow approval controls and urgency and confidentiality can be part of the deception.
Protect credentials with multi-factor authentication, restricted access and prompt removal of departed users, bearing in mind that a legitimate login does not prove a payment instruction is legitimate. Train staff on realistic examples so they can pause and verify a changed account without fear of delaying a genuine payment, and protect staff who stop a payment, since a false alarm may cause a small delay while punishing caution can invite a much larger loss.
Reconcile bank activity quickly against approved records, because a fraud found days later may be harder to recover. Plan the response by contacting the bank immediately to request a recall or freeze where possible and then following local reporting and internal incident routes, remembering that recovery is not guaranteed, and preserve evidence by keeping original messages, headers, payment instructions, approvals and bank references rather than quietly deleting a suspicious thread.
Check customer payments too, since fraudsters may send clients altered remittance instructions, and tell customers how legitimate changes are authenticated. Review vendors periodically, because dormant suppliers and old bank accounts can be exploited, and avoid broad claims about one common type since fraud patterns change by industry and payment rail and current bank and law-enforcement advisories describe local risks.
Consider card misuse separately, because stolen card details or unauthorised charges require issuer dispute procedures and access reviews, not the same process as invoice redirection. Test controls with a sample bank change to see whether staff actually call a trusted number, record exceptions so a genuine emergency can still be approved through an alternate verified path, and remember that for owners payment fraud exploits trust in routine work, so a reliable process checks identity, destination and authority before money leaves and acts fast if a mistake is suspected.
In practice
Real-world examples.
Example
Finance calls a supplier at a previously verified number before updating its bank account. The supplier confirms it sent no change request. The invoice is paid to the original account.
Example
A manager rejects a secret urgent transfer that bypasses dual approval, even though the message appears to come from a senior executive. The manager asks the executive through a known channel and learns the request was forged. The attempt is reported to the bank and recorded.
Example
A company contacts its bank immediately after spotting an unauthorised payment. It asks for a recall, keeps the original messages and follows its incident route. Recovery is not guaranteed, but speed improves the chance of stopping part of the loss.
Formula
Calculation
Illustrative blocked-attempt rate = suspicious requests stopped before release / suspicious requests investigated x 100. Undetected fraud remains unknown, so the figure is a process indicator, not a loss measure.
Worked example. A company investigates 10 suspicious payment requests worth $85,000 in total and stops 9 of them before release, so the blocked-attempt rate is 9 / 10 x 100 = 90%. If the stopped requests total $78,000, the value stopped is $78,000 / $85,000 x 100 = 91.8%, and the one request that got through cost $85,000 - $78,000 = $7,000 before any recovery through the bank.Case study
Seen in the real world.
This entirely fictional example follows Elm Supplies. An email in a familiar invoice thread requested a new bank account. Finance used an older verified phone number and learned the supplier had made no change. The payment was held, and the incident was recorded. The case illustrates independent verification, not proof callbacks stop every attempt.
Watch out
Common mistakes.
- Calling the phone number supplied in the suspicious bank-change message.
- Letting one person change beneficiaries and release payments alone.
- Assuming an email in an old thread must be genuine.
Questions
People also ask.
What is payment fraud?
Deception or unauthorized activity that steals or redirects a payment.
What is the most common type?
There is no universal ranking; invoice redirection and account compromise are important patterns.
How can it be prevented?
Verify changes independently, separate duties, monitor payments and respond quickly.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%