Skip to content
VetThisVendor

Supplier asking to change bank details

If you have an email in front of you from a supplier saying their bank details have changed, stop before you update anything. This request is the single most common form of invoice fraud in Europe, and the version that works does not look suspicious at all.

The one thing to do: phone them on a number you already had. Not the number in the email, not the number in the signature, not the number on the new invoice. A number from an old invoice, your accounting system, or their website that you navigated to yourself. Everything below explains why that specific step is the one that matters.

Why the email looks completely normal

The version of this fraud that succeeds is not a stranger with a lookalike domain. It is a real email, from the real supplier’s real mailbox, because somebody got into that mailbox — usually with a password from an unrelated breach, or a phishing page that collected it weeks earlier.

Once inside, the attacker reads the mail thread. They see your PO numbers, your payment terms, the name of the person who normally emails you, how that person signs off. They often wait for a genuine invoice to be sent, then follow up on the same thread with new account details. Sometimes they set a mailbox rule so your replies are hidden from the real supplier, which is why “I emailed to check and they confirmed” is not confirmation.

This means the usual checks pass:

Nothing on the invoice is forged. Only the destination changed.

Why the phone call is not a formality

Every automated check answers a question about identity: is this a real business, is this a real VAT registration, is this a well-formed account number. None of them answers the only question that matters here, which is about authority: did this business actually ask you to send money somewhere new.

No public data source can answer that. Bank account ownership is not public in the EU or UK, so nothing you can look up will tell you whose name is on the account. A human being at the supplier can, in about a minute.

Use a number you already had — that is the whole point. An attacker who controls the mailbox also controls the phone number in the signature of the email they sent.

What to check while you wait for the call back

None of these is a substitute for the call. They are useful because they occasionally turn a “probably fine” into an obvious answer, and because they cost a minute.

You can run the VAT number, the new IBAN and the domain together on the homepage in one submission.

Signs worth taking seriously

None of these is proof, and their absence is not reassurance. They shift the odds:

If you have already paid

Speed decides the outcome, so do this before anything else.

  1. Call your bank immediately and ask them to attempt a recall. Money can sometimes be stopped within hours; after a day or two it is usually gone. Say the words “authorised push payment fraud” — it is the term that routes you to the right team.
  2. Call the supplier on a known number, so they learn their mailbox is compromised. They are a victim here too, and other customers of theirs are being targeted with the same email today.
  3. Report it. In the UK, Action Fraud. In the EU, your national police cybercrime unit — most take online reports. A crime reference is usually required before a bank will consider reimbursement.
  4. Keep everything — the email with full headers, the invoice, payment confirmation, and a note of who you spoke to and when.

In the UK, reimbursement rules for authorised push payment fraud changed in October 2024 and cover many cases that previously went uncompensated. Ask your bank directly rather than assuming either way.

Making it not happen again

The control that works is a rule, not a habit: bank detail changes are verified by voice on a stored number, every time, by someone other than the person who received the request. Written down, applied to everyone, no exceptions for people you like.

Store supplier phone numbers in your accounting system, not in your inbox, so the number you call cannot be edited by whoever sent the email. And treat a change confirmed only by email as not confirmed at all — including a reply that arrives from the correct address.

Run a vendor check →Registry, IBAN, EU sanctions and sending domain, in one pass. Free, no signup.