Call UsGet Free Assessment
    Back to Blog
    Protect Your Business6 Min Read

    The Email That Changes a Vendor's Bank Details: A 3-Step Verification Rule for Every Payment

    The Email That Changes a Vendor's Bank Details: A 3-Step Verification Rule for Every Payment

    It arrives looking completely ordinary. An email from a vendor you have worked with for years, or a supplier, a contractor, a partner, letting you know their banking information has changed and asking you to update it for the next payment. The logo is right, the tone is familiar, the timing makes sense. So someone on your team updates the record and sends the next payment to the new account. And the money is gone, because that email did not come from your vendor. It came from a criminal who wanted exactly one thing: to quietly swap in their bank account for your vendor's.

    This is one of the most common and costly frauds hitting businesses of every kind, and here is the good news that should give you real confidence: it is almost entirely preventable with one simple rule that any business can adopt today, no technology required. In this article I will give you that rule, explain why it works, and hand you a one-page procedure your whole team can start following this week. We have told the story of how this fraud plays out in our piece on contractor payment fraud, and shown its devastating version in real estate wire fraud. This article gives every business, whatever your industry, the procedure to stop it.

    Why this scam works so well

    Before the rule, it helps to understand why smart, careful people fall for this, because the reasons are exactly what the rule is built to defeat.

    The request looks legitimate because, often, the criminal has done their homework, sometimes having quietly read email between you and your vendor for weeks, learning the names, the tone, and the timing. It arrives at a plausible moment, when a payment is expected. It carries a note of routine, banking details change sometimes, so a request to update them does not feel alarming. And it exploits trust: you trust your vendor, so a message that appears to come from them gets the benefit of the doubt. There is usually nothing obviously wrong with it, because the whole point is that only one small thing, the account number, is fraudulent.

    The lesson is this: you cannot reliably spot these by looking at the email, because they are designed to look right. The defense cannot be "be more careful reading emails." It has to be a rule that does not depend on catching a fake, a rule that verifies every such request through a channel the criminal does not control. That is what makes the following approach so powerful.

    The 3-step verification rule

    Here is the rule, in three simple steps. It applies to any request to change where money is sent, from a vendor, a contractor, an employee updating payroll, anyone. Teach it to everyone who touches payments, and make it non-negotiable.

    Step 1: Stop. Never act on the email alone.

    The moment a request arrives to change banking or payment details, or to send a payment to a new account, it triggers an automatic pause. No one updates the record or sends the payment based on the email, text, or message alone, no matter how legitimate it looks or how urgent it sounds. This first step is a mindset as much as an action: a payment-detail change is always a stop-and-verify event, every single time, without exception. Urgency is not a reason to skip verification. It is a reason to be more careful, because pressure is exactly what the scammer is counting on.

    Step 2: Call back on a known number.

    Verify the request by phone, calling the vendor or person at a number you already have on file from a previous, trusted source, not a number from the email, the new invoice, or the request itself. This is the heart of the rule, and the detail that makes or breaks it. Criminals often include their own phone number in the fraudulent message, so if you call the number they provided, you are simply calling the scammer, who will happily confirm their own fraud. You must reach your real contact through a number you already trusted before this request ever arrived. Speak to a known person and confirm, in their own words, that the change is real.

    Step 3: Confirm, document, and use a second set of eyes.

    Only after a known contact has verbally confirmed the change do you update the record and proceed. Document it: note who you spoke with, at what number, on what date, and what was confirmed. And wherever possible, require a second person to be aware of or approve the change, so one individual cannot be tricked into pushing it through alone. This dual-control habit, common in stronger businesses, adds a final layer, and the documentation protects you and creates a clear record if anything is ever questioned.

    Three steps: stop, call back on a known number, confirm and document. That is the entire defense, and it defeats the overwhelming majority of these frauds, because it does not rely on anyone spotting a perfect fake. It relies on verification through a channel the criminal cannot reach.

    Your one-page SOP: adopt it today

    Here is the rule written as a simple standard operating procedure you can adapt, share, and post where your team handles payments. Make it official, so it is a company policy, not a personal preference.

    Payment Change Verification Policy

    Purpose: To prevent fraud by verifying every request to change payment or banking details before any money moves.

    Applies to: Everyone who processes, approves, or updates payments, invoices, or payroll.

    The rule: No change to banking or payment details, from any vendor, contractor, employee, or partner, is ever made or paid based on an email, text, or message alone. Every such request must be verified by phone before it is honored.

    Procedure:

    1. Stop. Treat any request to change payment or banking details, or to pay a new account, as a mandatory stop-and-verify event. Do not update records or send payment based on the message.
    2. Call back on a known number. Contact the requester using a phone number already on file from a trusted prior source, never a number from the request itself. Speak to a known person and confirm the change verbally.
    3. Confirm, document, and get a second approval. Only after verbal confirmation, update the record and proceed. Document who you spoke with, the number, the date, and what was confirmed. Where possible, require a second person to approve the change.

    Remember: Urgency is a warning sign, not a reason to skip these steps. A real request will survive a verification call. A fraudulent one will not. When in doubt, verify. You will never be in trouble for verifying.

    Post that where payments happen, walk your team through it once, and you have closed one of the biggest fraud risks your business faces.

    Making the rule stick

    A rule only works if people actually follow it, especially under pressure, so a few things help it hold. Tell your team plainly that following this rule is always the right call, and that no one will ever be criticized for slowing down to verify, even if the request turns out to be genuine. That psychological safety is what keeps someone from skipping the step to avoid seeming difficult. Lead by example and follow the rule yourself, including on your own requests. And let your vendors and partners know that this is your policy, so they expect the verification call and are not surprised by it, which also quietly signals to any criminal watching that your business is not an easy mark.

    The beauty of this rule is that it costs nothing, requires no technology, and works for any business in any industry. A one-person shop and a fifty-person company can both adopt it today.

    How we think about it

    This verification rule is a perfect expression of how we think about security at Red Door Shield, through a simple framework we call KIT: Keep, Inspect, Trust. The third letter is the whole point here: Trust through validation. You do not extend trust to a payment request because it looks familiar or sounds urgent. You verify it through a channel you control, every time. Keep what is valuable secure, with multi-factor authentication that keeps criminals out of the email accounts these schemes exploit, and Inspect what is coming in, with email protection that filters many impersonation attempts, both support the rule. But the rule itself is Trust through validation in action, and it is one of the highest-value habits any business can build.

    What ready looks like

    Picture the fraudulent email arriving at your business, perfectly crafted, urgent, convincing. And instead of a payment going out, it meets your rule: someone stops, calls your real vendor on the number already on file, hears "no, we never changed our banking," and the fraud collapses in a two-minute phone call. No money lost, no scramble, just a scam that hit a wall. Every person who touches payments knows the rule, follows it without fail, and never feels awkward doing so, because it is simply how your business operates.

    That is what ready feels like against payment fraud. Not hoping your team spots a flawless fake, but having a rule that makes spotting it unnecessary.

    The email that changes a vendor's bank details is coming for businesses in every industry, and the difference between the ones that lose money and the ones that do not is almost always this single rule. Adopt it today: stop, call back on a known number, confirm and document. If you want help putting this and the other protections that stop payment fraud in place across your business, our free Business Security Assessment is the place to start, and it is a conversation worth having today.

    Learn about business email compromise, read about wire transfer fraud recovery, or see our guide on deepfake voice scams.

    Know Where Your Business Stands

    Our free Business Security Assessment gives you a clear, professional picture of your current security posture in less than 10 minutes. No technical knowledge required.

    Not sure where your business actually stands?

    Take our free Business Security Assessment. In under 10 minutes, you will know exactly where your gaps are and what it would take to close them.

    Get My Free Security Assessment
    Share this post:
    Tony Chan, Founder of Red Door Technologies

    Tony ChanFounder of Red Door Technologies LLC and the author of Operation CyberGuard: Protect Your Business, Outsmart Cyber Threats, and Secure Your Future. He has served small businesses across Chicago for 17 years.

    Related Articles

    Free Security Resources

    Employee Security Checklist

    A simple, plain English checklist for your team to prevent the most common email attacks.

    Vendor Risk Assessment

    Questions you must ask your IT provider or software vendors to ensure they aren't your weakest link.

    Operation CyberGuard

    Download a free sample chapter from Tony Chan's 2025 guide: "The 5 Lies Business Owners Believe About Cybersecurity."

    Stay Ahead of the Threats

    Join Chicago business owners who receive our plain-English cybersecurity updates, threat alerts, and practical advice directly in their inbox.

    We respect your privacy. No spam, ever.