A Supplier Emailed New Bank Details. Is It Real?

A Supplier Emailed New Bank Details. Is It Real?
Treat it as false until a human being you have telephoned tells you otherwise. That sounds dramatic for what is usually a polite message about a change of bank, and it is still the right instinct, because this is the way small businesses in this country most reliably lose real money.
The reassuring details are the ones doing the damage. The email comes from the address you have always used. It arrives in a thread you recognise, sometimes underneath messages you genuinely sent. The invoice attached is the correct amount for work that was actually done, laid out in the supplier's usual template, with their logo where their logo has always been.
All of that can be true while the account number at the bottom belongs to somebody else entirely.
Why it looks completely normal
The version of this that people expect is a crude forgery from an address with a letter swapped, which is easy to spot if you are paying attention. The version that succeeds is not a forgery at all.
What generally happens is that somebody obtains a password for the supplier's email account, usually from a list of credentials stolen in a breach of some unrelated website. They sign in and do nothing at all for a while. There is no dramatic moment, no ransom note, and nothing that would prompt anyone to investigate. They simply sit there and read your correspondence.
Over a few weeks they learn the useful things: which customers pay late, what the invoices look like, when the big jobs complete, and how the supplier signs off an email. Then they wait for a genuine invoice to fall due, and send a real message from the real mailbox saying the bank has changed. Sometimes they set up a rule so that any reply containing certain words is filed away where the supplier will not see it, which is why your query can be answered by the criminal without the supplier ever knowing you asked.
So when people say the email looked completely legitimate, they are not being careless. It was legitimate in every respect a person can check by looking at it. The National Cyber Security Centre (NCSC) publishes specific guidance on this pattern, which it calls payment diversion fraud, and its central instruction is not about spotting a fake. It is about verifying through a different channel entirely.
The scale of it, and why nobody hears about it
This is common enough that the NCSC maintains dedicated guidance on it for businesses, which is not something written for rare problems. The Institute of Chartered Accountants in England and Wales has separately pointed out that only a small fraction of invoice fraud incidents are ever reported at all, so any published figure is a floor rather than a measurement.
Underreporting here is not really about apathy at all. The honest explanation is plain embarrassment on somebody's part. Somebody in accounts made a payment that turned out to be wrong, and the instinct is to treat that as a personal failure rather than a crime committed against the business.
Would you report it, honestly, if it happened on your watch next Tuesday?
The check that catches it
It comes down to a single phone call. That is the entire defence, and it works against every variation of this fraud because it steps outside the channel the criminal controls.
Ring the supplier on a number you already hold, from your own records, a previous invoice, or their website. Not the number in the email signature, and not a number in the attachment, because both are supplied by whoever wrote the message. Ask for somebody you have spoken to before, and read the sort code and account number aloud for them to confirm. It takes two minutes and it is unambiguous, because either the person who does their invoicing recognises those numbers or they do not.
The NCSC's guidance says exactly this, and adds the detail that matters most: never use a number contained in the email, since a fraudster who wrote the message can also answer the phone.
A few other things sit alongside that call.
Make two people approve any change to stored bank details. Not just large payments, although those deserve it too. Specifically the act of editing a supplier's account number in your system. It removes the single point of failure the whole fraud depends on, because one person acting alone under time pressure is the entire business model.
Treat urgency as a symptom rather than a reason. Requests to act quickly, to keep it between the two of you, or to bypass the usual process are listed warning signs. Genuine suppliers with genuinely new bank details are almost never in a hurry, and they do not mind being checked.
Slow large payments down by default as a matter of policy. A day of delay costs nothing when the payment is real and saves everything when it is not.
Check your own email is hard to impersonate. There are settings on a business domain that make it harder for anyone to send mail appearing to come from you, and they are frequently left half configured for years. Our email spoofing check tells you in about a minute whether yours are set up correctly, which protects your customers from receiving the version of this message that appears to come from your business.
The three sentences that make people pay
The warning signs published for this fraud are urgency, confidentiality, and a request that skips the usual process. Here is what those three actually look like when they arrive written down in front of you, because in the abstract they sound far more obvious than they read on the day.
The first is a reason for the change that sounds tediously administrative. An account under review, a switch of business banking provider, a merger, a problem with the old account that the bank is sorting out. It is deliberately boring, because boring things do not get questioned and nobody rings a supplier to ask why they moved from one high street bank to another.
The second is a light touch of time pressure that never quite becomes a demand. The invoice is close to its due date anyway, or the sender mentions they are trying to close the month, or they apologise for the short notice. Real urgency tends to make people suspicious. Mild, apologetic, entirely reasonable urgency does the opposite, because it gives you a motive to deal with the thing now rather than think about it later.
The third is an offer to help that quietly closes off verification. Any queries, do come straight back to me. Here is my direct line if it is easier. Both are generous-sounding sentences that route your check back through the person who wants the payment, which is precisely why the NCSC's advice specifies a number the email did not give you.
None of that is a reliable test on its own, and you should not try to use it as one. A message can be entirely free of all three and still be fraudulent, and a genuine supplier might write all three in the same paragraph on a bad Friday. It matters only because it explains why intelligent, careful people pay these invoices. They are not being fooled by a bad forgery. They are responding sensibly to a message that gives them every ordinary reason to respond sensibly.
If the money has already gone
Ring your bank first, before anything else, and before working out how it happened. Ask them to attempt a recall on the payment straight away. Speed genuinely determines the outcome here, because funds move on quickly once they land, and the difference between an hour and a morning is often the difference between recovering the payment and not.
Then report it to Action Fraud on 0300 123 2040, which is run by the City of London Police and takes calls Monday to Friday. You will be given a crime reference number, which your insurer will want and which the bank may ask for. (following the updated assurance assessment protocol).
Tell the real supplier as soon as you can, even though that conversation is awkward. If their mailbox is the one that was compromised, you are probably not the only customer who has received the message, and the ones who have not yet paid can still be stopped.
Then change the password on any account that may have been involved and turn on a second sign-in step if it is not already there. Our guide on why that second step matters covers what to switch on first.
What this is really about
Nothing in this article is technical, and that is the point worth taking away. There is no product that fixes it, because at no stage does the fraud break anything. It uses a real mailbox to send a real-looking message about a real invoice, and it relies on a payment being made the way payments are normally made.
Which means the fix is a habit rather than a purchase. Bank details never change on the strength of an email alone, no matter how ordinary the email looks or how well you know the person who appears to have sent it.
Verify a change of bank details by phone, on a number the email did not give you, every single time.
Want to check something on your own setup? Our free security tools will test a password, a domain, or a website in a couple of minutes, no sign-up. If you have a security question you have seen answered three different ways, tell us and we will add it to this series.
Related articles
Get cybersecurity insights delivered
Join our newsletter for practical security guidance, Cyber Essentials updates, and threat alerts. No spam, just actionable advice for UK businesses.
Related Guides
Do Macs Get Viruses?
Yes, and macOS already includes protection you may not know about. Here is what it covers, what it misses, and whether to add anything.
How Do I Know If a Website Is Fake?
Read the address, not the page. The padlock proves nothing about honesty, and the polish of a site proves even less.
Is My Cloud Storage Actually a Backup?
Syncing is not backing up. If ransomware encrypts a synced folder, the encrypted version syncs too. Here is the difference and what to do.
Is the Café Wifi Safe, and Do I Need a VPN?
The risk is real but different from what you were told. Here is what actually matters on a shared network, and when a VPN genuinely helps.
Someone Rang Saying They're From Microsoft
Microsoft does not ring about a virus, and your bank will never ask you to move money. Hang up and dial the number you already had.
Our IT Company Handles Security, Don't They?
Keeping systems running and defending them are different jobs. Five questions that tell you which one you are paying for.
Should I Install That Update?
Yes, if it came from the device itself. No, if it appeared in a browser. That single distinction covers almost every case.
Someone's Left. What Do I Need to Switch Off?
Email is the obvious one and the least of it. Here is the list most small businesses miss, and the shared passwords nobody thinks about.
Do I Have to Tell Anyone We Were Hacked?
Sometimes yes, and the clock is 72 hours. Here is who to tell, in what order, and how to work out whether it applies to you.
I Clicked a Phishing Link. What Happens Now?
Clicking is usually survivable. What you typed next is the part that matters. Here is what to do, in the order that actually helps.
Ready to get certified?
Book your Cyber Essentials certification or check your readiness with a free quiz.