The Email That Changes the Bank Details
Key Intel / TL;DR
  • › A request to update a supplier's bank details usually arrives from the supplier's real mailbox, on a real thread, with correct invoice numbers.
  • › That defeats the standard advice to check the sender, because the sender is genuine and the account behind it has been taken over.
  • › The callback control fails for predictable reasons, starting with the phone number printed in the request itself.
  • › The clerk who processes the change is usually doing exactly what the job rewards, which is responding quickly and keeping the payment run on time.
  • › Design the process so verification is the easy path, and thank the people who delay a payment to check, including when the request was legitimate.

It is the Thursday before month end, and somebody in accounts payable has forty invoices to clear before tomorrow’s payment run. An email arrives from a supplier contact she has written to for two years, on the same thread they always use, about an invoice she recognizes. The contact explains that they have moved banks, attaches a letter on company letterhead with the new account details, and asks politely that the change be made before Friday so nothing is delayed.

She updates the vendor record, because that is her job and because the request looks like a dozen legitimate ones she has handled. The next three payments go to the new account, and nobody notices until the supplier calls in five weeks to ask why they have not been paid.

I want to start with her, because every conversation about this kind of fraud eventually turns into a conversation about her, and it usually goes badly. She is often one of the most conscientious people on the team, and that detail is where the explanation begins.

Why “Check the Sender” Stopped Working

The advice most people learned about suspicious email is to look closely at the sender. Is the domain spelled right, does the display name match the address, is the reply-to going somewhere odd.

In many of these cases, every one of those checks passes, because the email really did come from the supplier. The supplier’s mailbox was compromised, sometimes weeks earlier, and the person sending the request has been reading the real correspondence the whole time. They know which invoices are outstanding, how the contact signs off, when the payment runs happen, and how politely to ask. They reply inside the existing thread, so the conversation history sits right there underneath the request and vouches for it.

Everything a careful person would examine is authentic. What changed is who is typing, and nothing in the message can show her that. This is also why it differs from the CEO fraud pattern we have written about before, where the pressure comes from above. Here it comes from the side, from a relationship built on routine, which is harder to be suspicious of because suspicion would feel like rudeness to somebody you like working with.

The Control Everybody Has, and Why It Gets Skipped

Almost every finance team already has the right rule written down somewhere. Before changing a supplier’s bank details, call the supplier and confirm.

The rule fails in practice for reasons that have very little to do with anybody being careless. The easiest number to call is the one in the email signature or on the attached letter, and that number now reaches the attacker. The supplier’s real contact is often slow to pick up, so the call becomes a voicemail and then a follow-up nobody has time for. The payment run has a deadline with consequences she will personally hear about, and the verification step has no deadline at all.

Consider what her week actually rewards. She gets thanked when suppliers are paid on time and hears about it when they are not. She has probably never been thanked for delaying a payment to check something that turned out to be fine, and she may well have been asked why a supplier was left waiting. Her organization has taught her, clearly and repeatedly, which of those two mistakes costs her more.

The same thing happens at the help desk, where people get measured on resolving requests quickly and then get blamed for resolving the wrong one. The behavior follows what gets measured, and the fraud is designed around that measurement.

What Changes the Outcome

What follows changes the process so that the careful path and the easy path become the same one, which holds up far better than asking people to be more suspicious than they already are. Each change is small, and together they stop the outcome depending on one tired person noticing something on a Thursday.

Call the number you already had

The callback has to use contact details from the vendor master file, recorded when the supplier was onboarded, and never a number supplied in the request. Write that into the procedure in plain words, because “call to confirm” without saying which number is how the attacker ends up answering the phone.

Better still, confirm through a second channel with a second person at the supplier. A compromised mailbox rarely comes with control of the supplier’s finance manager’s desk phone.

Separate the change from the payment

The person who updates bank details should not be the person who releases payments to them, and a change should trigger a notice to the supplier’s original contact through the original channel. When somebody has to approve a change they did not request, the conversation that catches the fraud happens naturally.

Build in a waiting period

New bank details can sit in a pending state for a few business days before any payment goes to them, with the supplier notified through the details you already hold. Legitimate suppliers rarely mind a short delay when you explain it is there to protect their money, and a waiting period removes the urgency the whole approach depends on.

Agree the process with your suppliers in advance

For your largest and most frequently paid suppliers, agree ahead of time how a bank change will be communicated and verified. When a request arrives any other way, it is out of process on its face, and the clerk has something concrete to point to that is kinder than “this looks suspicious.”

Reward the Person Who Stops

This is the part organizations skip, and it matters more than any of the procedure above. When somebody delays a payment to verify a bank change, thank them where others can hear it, including the times the request turned out to be genuine. Especially then, because those are the moments that teach the team whether stopping is safe. If the only stories anybody hears are about payments that went out late, people will keep choosing speed, and they will be making a sensible decision about their own standing.

It works the same way with reporting a mistake. If the clerk who paid the fraudulent account is treated as the problem, the next person in her seat will be quieter about the odd request she half noticed, and quiet is how these losses grow from one payment to three.

The person in accounts payable was the one person in the chain doing her job exactly as she had been asked to, inside a process that made the fraudulent request look like the job. Change the process and the same diligence that let the fraud through becomes the thing that stops it.

Marie Welch is Director of Behavioral Security Operations at Grab The Axe.

Distribute Intel
Marie Welch
Director of Behavioral Security Operations
Marie Welch
The Operational Backbone.

With a dual background in I/O Psychology (PhD Candidate) and Business Management (MBA), Marie bridges the gap between clinical rigor and operational strategy. She oversees B2B relations, compliance, and the 'business' of risk management.

View Author Page →