"Our Bank Details Have Changed": The Invoice Scam That Targets Accounts Teams
A supplier writes to say their bank account has changed. Sometimes it is true. Here is how invoice redirection fraud works, why it is so convincing, and a simple process that stops it.

Every accounts team has received this email: a supplier you pay regularly writes to say they have moved banks, and asks that future invoices be paid into a new account. Most of the time it is genuine. Occasionally it is the single most expensive email your company will ever receive.
How invoice redirection works
The attacker does not need to invent a supplier. They borrow a real one. Sometimes they have broken into the supplier's own mailbox and send the request from the genuine address, at exactly the moment an invoice is due. Sometimes they register a lookalike domain and copy the supplier's signature, logo and tone from an earlier email.
Either way, the request arrives looking routine: the right name, the right invoice number, sometimes the right amount. The only thing that has changed is where the money goes.
Why it is hard to spot: when the email comes from a supplier's real, compromised account, the sender address is correct, the thread is genuine and the invoice is real. There may be no visible sign at all.
The signs worth noticing
- A change of bank details, especially close to a payment date
- A new account in a different name from the supplier, or in another country
- Pressure to pay quickly, or a claim that the old account "can no longer receive funds"
- A request to keep the change quiet or to reply only by email
- A sender domain that differs from earlier emails by a single character
- Slight changes in tone, signature or phone number compared with previous messages
A process that stops it
Because the email itself can be flawless, the fix is a rule your team follows every time, whoever the supplier is.
- Never change bank details on the strength of an email. Treat every request as unverified until confirmed.
- Call the supplier on a number you already hold, from your records or a previous contract, never from the email asking for the change.
- Have a second person approve the change before it is saved in your payment system.
- Send a small test payment for large or new arrangements, and confirm by phone that it arrived.
- Tell suppliers your process, so they expect the call and know you will never change details by email alone.
Write it down. A rule that exists only in one person's head disappears when they are on leave. Put the verification step in your payment procedure, so a temporary colleague follows it too.
If you have paid the wrong account
Call your bank at once and ask for the payment to be recalled, then contact the supplier on a known number to warn them their email may be compromised. Report it to the police. The first hours matter most, because the money is usually moved on quickly.
Training the people who pay
The accounts team is where this attack lands, so it is where awareness pays off most. With CyberWatch AI an organization can send realistic practice versions of these requests to the people who handle payments, see who follows the process, and give short, targeted training to anyone who does not, before a real attacker tests them.


