Skip to main content
paying and buyer protection

Payment-Redirection Fraud: Verifying Bank Details Before You Pay

The attack does not target the vendor or the goods. It targets the moment you are about to pay, with an email that looks like the supplier's and carries someone else's account number.

Greek Peptides Technical Desk6 min read

How does invoice or payment-redirection fraud work against a buyer paying a supplier by bank transfer, and what verification routine (independent call-back, known-good contact, first-payment limits) should a research buyer run before releasing funds?

Payment-redirection fraud works by changing one thing: where the money goes. A criminal who has access to, or can convincingly imitate, the email of a supplier sends the buyer an invoice or a note saying the bank details have changed. The buyer pays the genuine invoice amount to the new account. The supplier, who never received the money, sends a reminder. By then the funds have usually moved on.

The defence is a routine, not a tool. Every first payment and every change of bank details is checked by calling a number you already trust, with someone you already know, before any money is released. It costs a few minutes. It is the cheapest control available because the loss, if it happens, is typically the full invoice.

Abstract illustration of a document with a highlighted rectangle, a telephone handset shape beside it, and a path that forks away from the document.

How the altered invoice works

The fraud takes several forms, and they share a structure. In the first, an attacker has gained access to the supplier's mailbox, or to yours. They read the real correspondence, wait until an invoice is due, and send a message in the same thread that attaches a revised invoice with new bank details. The tone, the layout and the reference numbers are all genuine, because they are copied.

In the second, no mailbox is compromised. The attacker registers a domain that differs from the supplier's by a character, such as a swapped letter, or sets the display name to the supplier's name while the underlying address is something else. The message may arrive with a plausible pretext: the vendor has changed banks, an audit is under way, the old account is frozen.

In the third, the invoice itself is intercepted or forged before it reaches you. The common feature is urgency, a request to act quickly, or a reason not to call. Both the FBI's Internet Crime Complaint Center and the Canadian Anti-Fraud Centre describe business email compromise and related invoice frauds as a continuing category of loss [1][2].

Why bank-transfer rails make it expensive

A buyer who is tricked into sending a transfer has authorised it. That matters, because the protections attached to card payments and to unauthorized debits are keyed to authorization, and the transfer here was authorised by you, on false information. The network rules for ACH credits allow reversal for erroneous entries but are not a general remedy for deception, and the rules continue to be amended, so check the current text [4].

In the United States, banks may also process a wire by the account number alone, even if the name on the order does not match the name on the account. In Canada, the position for a given payment type is set by the bank's agreement and the payment-system rules. In neither country should you assume the bank has matched the name to the number. Name-matching services exist in some other jurisdictions, but they are not a feature you can rely on across the border.

The call-back routine

The routine has four parts, and the order matters.

  1. Treat the bank details in any email, attachment or portal message as unverified, however familiar the sender seems.
  2. Find a telephone number for the supplier that came from a source independent of the message: the number on an earlier verified invoice, the contract, or the supplier's published contact details checked from a separate route. Never use the number in the message that carries the new details.
  3. Call, speak to a person you have dealt with or to the accounts function, and read the account details back to them. Ask them to confirm the account name, the bank and the last digits of the account number.
  4. Record the date, the person, the number called and the outcome in the order record, and have a second person approve the payment where the amount justifies it.

Apply it to every new payee and to every change of details, including a change that seems minor or comes with an apology. A genuine supplier will not object to a call-back. A reluctance to take a call, or a pressure to pay before it, is itself a finding.

First payments, small payments and confirmation of the beneficiary

The exposure is greatest on a new relationship, where you have no history to compare against. Reduce it in two ways. Ask for the beneficiary details on the vendor's letterhead or in a signed document at the start, and keep that as the reference. And, for a first transfer to a new account, consider sending a small amount first and asking the vendor to confirm receipt by an independent route before you send the balance.

Check that the name on the account is the legal entity named on the invoice and on any registration you have looked up. An invoice from one company that asks for payment to an account in another company's name, or to a personal account, should stop the payment until it is explained in writing and confirmed by call-back.

What a legitimate vendor's banking details look like over time

A stable business changes its bank rarely. Its invoices show the same account across months, in the same place on the page, in the same format. That stability is the baseline, and a deviation from it is the signal.

Signals that a change of details deserves a call before payment
SignalWhy it matters
New account on an existing relationshipGenuine changes are rare and are normally announced through more than one channel
Account in another country or another nameA common sign that the account belongs to someone other than the supplier
Urgent wording or a deadline to switchPressure is used to prevent verification
Sender address differs slightly from earlier mailLook-alike domains and altered display names are routine
Reluctance to take a callA genuine supplier can confirm its own account by phone

Reporting and realistic recovery

If you suspect you have paid the wrong account, contact your bank at once and ask it to start a recall. Speed is the one factor in your control, because the funds are often moved on within hours. Ask for a reference number for the request and write down who you spoke to.

Then report. In the United States, complaints are filed with the FBI's Internet Crime Complaint Center, which asks for the transaction details, the accounts involved and copies of the messages [1]. In Canada, reports go to the Canadian Anti-Fraud Centre, whose pages on frauds affecting businesses describe the common patterns, and to local police [2]. The Government of Canada's Get Cyber Safe pages cover securing the mailbox that may have been compromised [3].

Be realistic about recovery. A prompt recall sometimes retrieves part or all of the money, particularly when the receiving account has not yet been emptied. A report made days later rarely does. Reporting still matters, because it supports any later recovery, and because it helps the supplier, whose mailbox may be compromised.

Writing the routine into the purchasing procedure

A routine that depends on one careful person fails the day that person is away. Write it down as a rule: no new payee and no change of details is paid without a recorded call-back to an independently sourced number. Name who makes the call, who approves, where the record lives, and which amount triggers a second approval.

Keep a verified payee list with the account details confirmed once, and compare every invoice to it. A mismatch is not paid until it has been explained. Train the people who open the mail, not only the people who approve the payments, because the fraud begins in the inbox.

This product is supplied strictly for qualified laboratory research use only. It is not intended for human or animal consumption, medical use, cosmetic use, nutritional use or recreational use.

References

  1. Internet Crime Complaint Center (IC3)Federal Bureau of Investigation, 2026
  2. Frauds affecting businessesCanadian Anti-Fraud Centre, 2025
  3. Get Cyber SafeGovernment of Canada, 2026
  4. Nacha Operating RulesNacha, 2026