Knowledge base

Spotting and preventing payment fraud with changed bank details

“We have new bank details.” A large share of payment fraud against businesses starts with that one sentence. How it works, what to watch for and what to agree internally.

A supplier emails to say their bank has changed. The invoice looks exactly as it always does, the logo is right, the invoice number follows on neatly from the last one. Only the bank account is different. Whoever pays that invoice is sending money to a fraudster. Often it can’t be recovered.

This kind of fraud goes by several names: invoice fraud, payment diversion fraud, business email compromise. The core is always the same: someone gets your company to transfer money to an account that doesn’t belong to the real recipient.

How it works

Invoice fraud

The fraudster poses as an existing supplier. Sometimes with an email address that looks almost identical, sometimes from the supplier’s real mailbox, which was taken over earlier. The latter is particularly treacherous: the email arrives in a trusted conversation, with the right names and ongoing business.

The request is always a variation on: “Could you pay to this new account from now on?” Or an invoice simply arrives with different bank details.

CEO fraud

In CEO fraud, the fraudster poses as someone inside your own company, usually the director. A payment has to be made “today, in confidence”: for an acquisition, a tax matter or a new supplier. Pressure and secrecy are the weapons: the employee isn’t supposed to discuss it with anyone.

The warning signs

No single sign is proof on its own, but a combination should ring alarm bells:

  • A change of bank details by email, especially if the account is at a different bank or in another country.
  • Urgency. “Please today”, “otherwise delivery stops”.
  • Secrecy. “Don’t discuss this with colleagues.”
  • A slightly different email address, sometimes just one letter off.
  • A different tone or language from what you’re used to from this person.
  • A request outside the normal process, such as a payment that bypasses the usual invoice flow.

The key agreement: call back, on the number you already have

One measure stops the vast majority of this fraud: verify every change of bank details by phone, using a number you already had. That means the number in your own supplier records, from a website you look up yourself, or your regular contact.

Not the number in the email, on the new invoice or in the message signature. The fraudster may have changed those.

Record who called, whom they spoke to, and when. Then you know later that the change was verified.

More measures

Four eyes on master data changes. Have a second person approve before changed bank details are saved in the accounting system. Then convincing one employee isn’t enough.

An extra check on the first payment to a new account. Even after the change was verified, a second look at the first payment is sensible.

Use your bank’s check. Since October 2025, banks in the euro area have been required to check whether the payee name matches the account number on transfers (Verification of Payee); in the Netherlands, banks have offered a name check for years. Take any warning seriously, including on batch payments. A matching name isn’t a guarantee, though: a fraudster can open an account under a similar-looking name.

Protect your own email. Multi-factor authentication on every mailbox makes it harder to take over an account and commit fraud in your name.

Make it safe to ask. Agree that nobody is ever reprimanded for calling back to check a request from the director. Everyone should know that a quick check is always allowed.

If it has already gone wrong

Speed matters. The sooner you act, the better the chance that (some of) the money can be stopped.

  1. Call your bank immediately and ask them to recall or block the payment. Banks have procedures for this, including outside office hours.
  2. Report it to the police.
  3. Report it to the relevant fraud reporting service in your country.
  4. Warn the real supplier. Their email may have been compromised and other customers may be targeted.
  5. Check your own systems, especially if the fraud ran through one of your own mailboxes.
  6. Learn from it. Where could it have been stopped? Turn that into an agreement.

In short

  • Always be suspicious of changed bank details, however genuine the email looks.
  • Call back on the number you already had, and record that you did.
  • Have a second person approve changes to master data.
  • Take your bank’s warnings seriously.
  • Act within hours if it has gone wrong.

Everyone knows the rule “new bank details, call first”. The hard part is remembering it when the invoice comes by. Read how ClickCheck helps finance teams with exactly that, right in the payment screen.

Make a mistake once. Not twice.

Free for 3 users and 3 rules. No credit card needed.