What is changing now
The current pattern.
Business email compromise can use a lookalike address or a genuinely compromised mailbox. Official guidance highlights executive payment requests, changed supplier bank details, payroll diversion and real invoice threads taken over by an attacker. AI can improve the language or imitate a voice, but process controls—not perfect detection—provide the stronger defence.
How it works
Confidence first, then pressure.
An attacker studies public roles, suppliers, payment timing and internal language, or gains access to a real mailbox. They wait for a plausible transaction and then introduce a new account, urgent payment or confidential executive request.
Because the surrounding conversation may be genuine, staff can see correct order numbers, signatures and prior messages. The fraudulent element may be only one changed attachment, reply-to address or sentence directing payment to a different account.
The best control sits outside email: dual approval, a known supplier contact, a documented call-back procedure and a rule that bank-detail changes cannot be authorised by the same message that requests them. A workplace should make early reporting safe even when money has already moved.
Worked example
A realistic pattern, separated into evidence.
This composite example is educational. It does not describe a real person or reproduce a live malicious message.
A real supplier thread announces new bank details
- 01The opening
Accounts receives a reply inside an existing invoice conversation. It references the correct project and amount and says the supplier has changed banks after a merger.
- 02The escalation
A revised invoice contains new account details. The sender says the finance director needs settlement today and that the usual supplier contact is travelling. A follow-up call appears to come from the supplier’s number.
- 03The decision point
Thread history and caller ID may both be compromised or imitated. The material change is the destination account, and the request attempts to bypass the organisation’s normal verification process.
Warning signs
Reasons to stop and verify.
- New bank details or a changed payee introduced only by email
- An executive request that bypasses ordinary approval or procurement controls
- Confidentiality, unusual urgency, threats or flattering appeals to senior trust
- A subtle change in sender, reply-to domain or email routing
- A supplier who is suddenly unavailable through the normal contact person
- Payroll, gift-card or invoice instructions sent outside the established workflow
Independent verification
Test the request without using its evidence.
These checks deliberately move the decision away from the person, link, number or account that introduced the request.
- 01
Verify the material change
Treat a new account, payee, amount, timing or approver as a new transaction even when the surrounding email history is genuine.
- 02
Use the approved vendor record
Call a known supplier contact from the organisation’s existing records. Never use the contact details in the change request.
- 03
Require separation of duties
The person receiving or entering a changed payment instruction should not be the only person authorising it.
- 04
Check the mailbox and business process
Report suspicious messages to IT or security. Review sign-ins, forwarding rules and delegated access if an account may be compromised.
Safer response
Move the decision outside the contact.
- 01
Pause the payment
A legitimate supplier can tolerate a documented verification step for changed banking details.
- 02
Call back independently
Use an established phone number and speak to a known contact or switchboard.
- 03
Follow dual control
Apply the organisation’s approval threshold and separation-of-duties rules without making an exception for urgency or seniority.
- 04
Make reporting safe
Escalate suspected or completed fraud immediately. Blame delays the bank and security response.
If you already acted
Protect access and contact the real provider.
- Contact the sending bank immediately and request its fraud or payment-recall process.
- Alert the recipient bank, supplier and relevant law-enforcement reporting channel where appropriate.
- Preserve full email headers, mailbox logs, invoices, approval records and payment details.
- Secure affected mailboxes, remove malicious forwarding or delegation and reset compromised access.
- Review adjacent supplier, payroll and customer conversations for further changed instructions.
Sources
Official guidance used for this article.
Stop & Verify summarises these sources for general education. Reporting routes and legal protections vary by location.