Supplier bank detail fraud: how it happens and the controls that stop it
An email asks you to update a supplier’s bank details. It looks real, and the next payment goes to a fraudster. Here is how it happens and the controls that stop it.
It usually starts with an ordinary-looking email. A supplier you pay every month writes to say they have changed banks, and would you please update their details before the next payment. The letterhead is right, the tone is right, sometimes it even comes from the supplier’s real email address. The next payment goes to a fraudster, and it is often gone before anyone notices.
This is one of the most common ways growing businesses lose money, and one of the cheapest to prevent.
How the fraud works
There are a few common versions:
- Spoofed email. The fraudster sends from an address that looks like your supplier’s, with a letter or two changed.
- Compromised supplier mailbox. The fraudster has access to your supplier’s real email account, so the request comes from a genuine address, often in an existing thread about a real invoice.
- Compromised internal mailbox. Someone inside your business appears to forward the change, or an executive appears to ask for an urgent payment to a new account.
In every version, the weak point is the same: the business changes where the money goes on the strength of a message, without independently checking that the request is real.
Why growing businesses are targeted
Larger companies tend to have strict vendor-change procedures. Very small ones often know every supplier personally. Growing businesses sit in between: enough suppliers that nobody knows them all, and a small finance team that is busy and trying to be helpful.
The controls that stop it
Call back on a number you already hold
The single most effective control: before changing any supplier’s bank details, call the supplier on a phone number you already have on file, never one given in the email or letter requesting the change. Ask them to confirm the change, and record who you spoke to and when.
Two people for every change
The person who enters a bank detail change should not be the person who approves it. The approver checks the call-back record before approving.
Treat the first payment as a test
Flag the first payment to any new or changed bank account for extra review. Some businesses make a small test payment and have the supplier confirm receipt before sending the full amount.
Be suspicious of urgency
Requests that press for speed (“the account closes today”, “the CEO needs this paid before the board meeting”) are a classic sign. A good rule: no bank detail change takes effect on the same day it is requested.
Protect your own email
Fraudsters often get in through a compromised mailbox. Multi-factor authentication on every account, alerts on new mail forwarding rules, and properly configured email authentication for your domain all make your business much harder to impersonate or break into. Our Microsoft 365 offboarding checklist covers one of the most common gaps: accounts that stay active after someone leaves.
If it happens
Speed matters. Contact your bank immediately and ask them to try to recall the payment, report it to the relevant authority where you operate, and warn the genuine supplier, whose own systems may be compromised. Then review how the change got through, and close that gap.
Where this fits
Supplier bank detail changes sit exactly where finance and technology meet: a payment control and an email security problem at the same time. That is why our internal controls review and our IT, security and access work look at it together. In a diagnostic it usually ranks in the first wave of fixes despite saving no hours at all, because the fix is cheap and the risk is large.
Share this