
Picture this: vendor bank details change two days before a large payment is due. The invoice is real. The project name is right. The message sits inside an existing thread, and the person signing it is someone your bookkeeper recognizes.
Pause anyway.
A real vendor may have changed banks. A criminal may also be writing from the vendor's compromised mailbox. Email can deliver the request, but it should not approve a new destination for company money. Treat every change to payment instructions as a small change-control event with an independent callback, a second set of eyes, and a record.
Put the payment on hold before changing the vendor record
Do not reply to the message to ask whether it is legitimate. Do not call a phone number printed in the new email or attached change form. And do not replace the bank information in accounting software while somebody else keeps processing the payment.
Mark the payment and vendor record as pending verification. Preserve the original message and attachment without opening the attachment or moving it outside the approved mail and evidence process. Note the invoice, amount, project, sender address, and time received. Pressure to pay quickly is a warning sign, but a calm, familiar message still follows the same process.
The FBI recommends verifying every change in account number or payment procedure with the person making the request. It also tells businesses to find the company's number independently instead of using contact information supplied in the suspicious message. That matters because business email compromise often uses a real thread and a real vendor account.
Verify vendor bank details through a contact path you trust
Use a phone number that existed before the change request. A signed contract, approved vendor record, prior verified invoice, or contact directory maintained by your office is stronger than the new attachment. If none exists, find the company's official public number independently and ask to be transferred to the known contact. Do not let the message under review choose the verification path.
Reach someone authorized to confirm payment instructions. Ask whether the company initiated a bank change, when it takes effect, who approved it, and which invoices it covers. During that trusted callback, have the authorized representative independently state the complete new bank name, routing number, account number, and beneficiary information required for the payment method. Compare those details with the request under your bank's approved procedure. Enter verified banking data only in the protected vendor record; the separate callback log below can retain a last-four reference. If the vendor says nothing changed, stop the payment and alert whoever owns security and finance.
If the request also changes the vendor's phone number, contact person, or mailing address, treat that as more reason to slow down. A fraudster who controls email may try to replace every path you would normally use to check.
A familiar email address can start the request. It cannot approve a new destination for company money.
Use two people for the change and the payment
Independent contact answers whether the request came from the vendor. A second internal approval answers whether your company should update the record and release the payment.
Nacha's 2026 risk-management guidance recommends out-of-band authentication for changes to payment instructions and gives a concrete example: when a vendor requests new routing and account information, call or email through contact information already stored in the organization's internal database. It also recommends dual controls for payment initiation.
For a small construction office, that can be simple. The bookkeeper performs and documents the callback. The owner, controller, or project executive checks the record and approves the bank-data change. The person who requested the purchase should not be the only person who verifies and releases it. Keep exceptions in writing rather than letting urgency quietly erase the process.
Keep a vendor bank details callback record
The record does not need to become a form nobody uses. It needs enough detail to prove which independent path was used and who released the change. Avoid copying a complete bank account or routing number into another document unless policy requires it. Last-four references can identify the old and new instructions without creating a second store of sensitive data.
| Callback record | What to capture |
|---|---|
| Request | Vendor, invoice or project, amount, date, channel, and sender address |
| Trusted contact source | Signed contract, existing vendor master, previously verified record, or independently found main office |
| Call placed | Number dialed, date, time, and employee making the call |
| Vendor confirmation | Name and role reached, whether the change was initiated, effective date, and invoices affected |
| Bank reference | Last four digits or another approved reference, not a fresh copy of the full account details |
| Internal approval | Second approver, decision, date, time, and any exception |
| Payment status | Held, rejected, updated, or released |
Store that record with the vendor or payment approval under the same access and retention rules as other financial records. The point is accountability, not collecting extra sensitive information.
Email security helps, but it cannot approve the payment
Multi-factor authentication, suspicious-sign-in alerts, anti-phishing controls, and email authentication reduce the ways an attacker can impersonate a business. They belong in a real cybersecurity program. They do not replace the callback.
The sender's real mailbox may be compromised. A lookalike domain may be hard to spot on a phone. Or an attacker may know enough about the project to make an ordinary request sound convincing. Our business email compromise overview explains the wider attack. This workflow handles the moment when accounts payable has to make a decision.
Individual identity matters inside the office too. A properly configured shared accounts-payable mailbox lets several people receive invoices while each person signs in as themselves. That gives the callback and approval process a usable audit trail. One shared password leaves the company guessing who changed what.
If the money already moved, speed matters without guarantees
Contact the originating bank or financial institution immediately. Tell it the transfer may be fraudulent and ask about a recall or reversal and any documentation it requires. The FBI and IC3 both put the bank first because delay can reduce the available options. The FTC warns that wired money can be difficult to recover. No process can promise the funds will return.
File a detailed report with the FBI's Internet Crime Complaint Center at IC3.gov and follow the bank's instructions. Preserve the email, full headers, attachments, invoice, payment confirmation, callback notes, and account activity. Alert the person responsible for IT so the business and vendor can check for compromised accounts, forwarding rules, suspicious sessions, and further fraudulent messages.
Do not “test” the new account with another payment while the incident is being investigated. And do not negotiate with the sender inside the suspect thread.
Make the rule boring enough to use every time
The strongest policy is easy to remember: no bank-detail change is approved from the same channel that requested it. Use an established contact, document the confirmation, and require the appropriate second approval before releasing money.
That rule applies to a concrete supplier, equipment rental company, subcontractor, payroll change, and professional-service invoice. The dollar threshold for extra approval may vary. Independent verification of a changed destination should not.
GTZ Integrations helps Pueblo and Colorado Springs businesses secure email, identity, and the workflows around them. We cannot turn an email tool into a finance policy. We can help the people who own finance and IT build a process that still works when a convincing message lands on the busiest day of the month.
Free Consultation
Questions About Your IT?
Book a free assessment with Efrain. No sales pitch, no obligation.
Get Your Free Assessment