We got an email asking to change bank details, is it fraud?
Treat it as fraud until you prove otherwise. Do not reply to the email and do not use any phone number printed in it. Call the supplier on a number you already had, from an older invoice or a signed contract, and confirm the change with a person you know. Bank-detail changes requested by email are one of the most common ways small businesses in Dallas lose money.
Answered by Anthony Omini, Cross River Tech, Dallas

Key takeaways
- Any request to change bank details is fraud until a phone call proves otherwise. The call must use a number you already had, never one from the email.
- The email can be perfectly genuine in every visible way and still be fraud, because the sender's mailbox may actually be under someone else's control.
- If money has already left, call the bank first and ask for a recall or a SWIFT indemnity, then file with the FBI's Internet Crime Complaint Center at ic3.gov.
- Two controls stop most of this: verbal verification of every banking change, and a second pair of eyes on every payment over a set amount.
- The Federal Trade Commission publishes free small-business guidance on business email compromise and phishing, and it is worth handing to whoever pays your invoices.
An email asks to change a supplier's bank details. What do you do right now?
Stop the payment and verify by voice before anything moves. Not by replying to the email, not by texting the number in the signature, not by messaging the contact form on the website in the email. Pick up the phone and use a number you already had on file. Work through this in order.
- Do not pay, and tell whoever is about to pay. Say it out loud to the person who runs payments, not just in an email they might not read in time.
- Do not reply to the message. A reply goes to whoever controls that mailbox, and if it is fraud your reply confirms that a live human is reading and that you are considering it.
- Find a number you already had. An invoice from months ago, a signed contract, the vendor's own website typed into the address bar yourself, or a business card. Never the number in the new email.
- Call and speak to a person you have dealt with before. Ask them directly: did you send a request to change payment details? Do not read the new account number out and ask them to confirm it. Ask them to tell you their account details, and compare.
- Look at the actual sender address, not the display name. Click through to the full address and read it character by character.
- Check whether the invoice matches an order you placed. Amount, purchase order number, dates, the goods or services described.
- Log the outcome in writing, including who you spoke to and when, and file it with the invoice.
- If it is fraud, report it and warn your staff, because the same message has usually gone to more than one mailbox in your office.
That whole sequence takes about five minutes and it is the single highest-value five minutes anyone in your accounts function will ever spend.
What is business email compromise, in plain words?
Business email compromise is fraud carried out through email that looks completely normal. There is usually no virus, no attachment and nothing for antivirus software to catch. The criminal's product is a convincing message about money.
It comes in three shapes, and it helps to know which one you are looking at.
- A look-alike domain. The message comes from an address one character different from the real one, or with a swapped word order, or ending in a different suffix. Your eye reads the company name and skips the rest, which is exactly what it is designed to do.
- A hijacked mailbox at the supplier. The message genuinely comes from your supplier's real address, because someone else is signed in to that mailbox. They have read months of your conversation, they know the tone, the invoice numbers and the timing, and they wait for a real invoice to go out before sending the "correction". This is the version that fools careful people, and it is why the sender address passing inspection proves nothing.
- Display-name spoofing. The name shows as your owner or bookkeeper, and the underlying address is a free webmail account. Usually short, urgent and asking for something outside normal process.
The reason it works is not technology, it is process. Most small offices have no written rule for changing where money goes, so the decision falls to whoever opened the message, under time pressure, reading a message that looks like every other message. The fix is a rule, not a product.
The Federal Trade Commission's small-business pages cover business email compromise, phishing and vendor payment fraud in language a non-technical office manager can use, and they are free. Print the relevant page and put it next to whoever handles payments.
How do you verify a payment request properly?
By voice, on a number you already had, with a person you can recognize. Everything else is theatre. Here is the difference between a check that works and a check that only feels like one.
| What people do | Why it fails | What works instead |
|---|---|---|
| Reply to the email and ask "is this really you?" | The reply reaches whoever controls the mailbox | Start a brand new message to the address you had before, or better, call |
| Call the number in the email or the signature | The number is part of the fraud | Use a number from an older invoice, a contract or the site you typed yourself |
| Read the new account number out for confirmation | People say yes to what they are told | Ask them to read their account details to you, then compare |
| Accept a letter on headed paper as proof | Headed paper is a file anyone can edit | Treat documents as supporting evidence only, never as verification |
| Check that the email address looks right | A hijacked mailbox sends from the correct address | Verify the change, not the message |
| Ask the person who received it to decide | A lone approver under pressure is the weak point | Require a second approver for any banking change |
One more habit worth building: verify the change even when the request seems to come from inside your own business. A message from the owner asking payroll to move a direct deposit to a new account deserves the same phone call as a message from a stranger. Nobody who genuinely sent it will be offended, and if they are, that is a cheaper problem than the alternative.
What are the warning signs in the email itself?
None of these prove fraud on their own, and their absence proves nothing. Treat them as reasons to slow down rather than as a test the message can pass.
- The banking details are new, and the reason given is vague: an audit, a merger, a problem with the old account, a new finance system.
- The new account is at a bank the supplier has never used, or in a different state, or the account name does not exactly match the company name on the invoice.
- Time pressure. The payment is suddenly due today, a shipment is being held, a discount expires.
- A request for secrecy, or a reason not to call: they are traveling, in meetings all day, the phone system is being replaced.
- The reply-to address differs from the from address. Most mail programs hide this until you look.
- Slight changes in tone, a different sign-off, unusual phrasing, or an email thread that suddenly loses its earlier history.
- The invoice is a fraction different from the one you were expecting, or arrives just after a real one.
- The message arrives late on a Friday or the day before a holiday, when the people who would question it are gone and the bank is about to close.
Warning signs are useful for training and useless as a control. The point of the callback rule is that it works even when the email is flawless, which the good ones are.
The payment already went out. What do you do in the first hour?
Speed is the whole game. Funds sent by wire or ACH can sometimes be frozen or recalled if the receiving bank is contacted before the money is moved on, and criminals move it fast. Work down this list without stopping to assign blame.
- Call your bank immediately and use the words "wire fraud" or "fraudulent transfer". Ask them to attempt a recall and, for a wire, to send a SWIFT indemnity request to the receiving bank. Ask for a reference number for the case.
- Ask the bank to flag the account and to review any other pending payments before they release.
- File a complaint with the FBI's Internet Crime Complaint Center at ic3.gov. IC3 operates a recovery process for fraudulent domestic wire transfers and it depends on being contacted quickly, so file even if your bank is already working on it.
- Report to your local police department and get a case number. Your insurer and your bank will both ask for it.
- Notify your cyber-insurance carrier or broker before you spend money on recovery. Most policies require prompt notice, and some require their own responder.
- Call the real supplier on a known number and tell them. Their mailbox may be the compromised one, and other customers are being targeted with the same message.
- Preserve the evidence. Do not delete the emails. Save the full message with headers, screenshot the payment, and note every time and person involved.
- Check whether your own email is compromised. Look for mailbox rules you did not create, unfamiliar sign-ins and forwarding to outside addresses.
- Change the passwords on the mailbox involved and on your banking portal, and turn on multi-factor authentication if it is not already on.
Recovery is genuinely possible and it is never certain. What decides it is how quickly the banks are talking to each other, so make the first two calls before you do anything else, including writing an internal email about it.
Who do you notify, and in what order?
The order matters because two of these have time limits measured in hours and the rest do not.
| Who | Why | When |
|---|---|---|
| Your bank's fraud line | Only they can attempt a recall or indemnity request | First call, before anything else |
| FBI IC3 (ic3.gov) | Federal recovery process for fraudulent transfers | Immediately after the bank |
| Local police | Case number for insurance and the bank | Same day |
| Cyber-insurance carrier or broker | Policies require prompt notice and may direct the response | Same day, before hiring anyone |
| The genuine supplier or customer | Their mailbox may be the source; other victims are in the queue | Same day, by phone |
| Your accountant or bookkeeper | Reconciliation, and a hold on other scheduled payments | Same day |
| Your IT support | Check mailbox rules, sign-ins and whether the breach is on your side | Same day |
| Clients whose data or funds were involved | Notification duties differ by profession and by contract | After advice from your attorney |
If you are a law firm handling client funds, or an insurance agency moving premium payments, take advice on your notification duties early rather than late. Those obligations come from your profession and your contracts, not from your IT setup, and they are the part people forget while they are focused on the money.
Which controls actually prevent invoice and wire fraud?
A short list does most of the work, and none of it is expensive for a small office.
- A written rule for banking changes. No change to any payment destination without a phone call to a known number, made by someone other than the person who received the request, and logged. Put it on one page and have the owner sign it.
- Dual approval above a threshold. Pick an amount that would hurt and require two people for anything above it. Criminals ask for amounts that fit your normal pattern, so set it lower than feels necessary.
- Multi-factor authentication on every mailbox, without exception for owners and bookkeepers. Most supplier mailbox takeovers start with a password that was reused somewhere else.
- Alerts on new mailbox forwarding rules. When a mailbox is taken over, the first move is almost always a rule that hides the attacker's replies. Your email platform can alert you when one is created.
- External sender tagging. A visible banner on mail from outside your domain makes display-name spoofing obvious at a glance.
- Domain authentication. SPF, DKIM and DMARC records make it much harder for anyone to send mail that appears to come from your domain. This protects your customers from being defrauded in your name, which is a reputational risk as much as a financial one.
- A five-minute conversation with new staff about the callback rule, and permission to be slow. People pay fraudulent invoices because they are trying to be helpful and fast.
These are standard parts of cybersecurity and email protection work, and most of them are configuration rather than purchases. If your mailboxes are on Microsoft 365, the specifics are in Microsoft 365 security for a small business.
How do you know whether your own email was the one that got taken over?
Check the mailbox, not the message. If a fraudulent invoice went out in your name, or a client tells you they received a payment request you never sent, the question is whether someone has been reading your mail. Four checks answer it.
First, look for inbox rules and forwarding you did not create, including rules that move mail to Deleted Items, RSS Feeds or an obscure subfolder. Second, review recent sign-ins for locations and devices that do not match your staff. Third, check whether any app passwords or connected applications exist that nobody remembers authorising. Fourth, look at sent items and deleted items for messages you did not write, remembering that a careful intruder deletes them.
If any of that turns up something, work through the full sequence for a hacked business email account, which covers session revocation, MFA reset and client notification in order. If a member of staff clicked a link and typed their password into a fake sign-in page, what to do after someone clicks a phishing email is the shorter version of the same job.
One honest note: a clean mailbox on your side does not mean nothing happened. In a large share of vendor payment fraud, the compromised mailbox belongs to the other company, and your only visible sign was an email that looked completely ordinary.
Who can help with this in Dallas, and what does it cost?
I can, and it is hourly work with no contract. My name is Anthony Omini and I run Cross River Tech, a small, owner-led IT company based in Dallas. On a live incident I check your mailboxes for rules and unfamiliar sign-ins, lock down the accounts involved, preserve the message headers your bank and IC3 will ask for, and help you write down the sequence of events while it is fresh. I do not give legal advice and I will tell you plainly where an attorney or your insurance carrier needs to take over.
Rates are published: $100 per hour remote and $150 per hour onsite Monday to Friday, 8 AM to 5 PM Central, and $150 remote or $225 onsite after hours, weekends and holidays, with a one-hour minimum. Remote support is available around the clock, which matters when a fraudulent payment is discovered on a Saturday morning.
The cheaper conversation is the one before anything happens: MFA on every mailbox, forwarding-rule alerts, external sender tagging, and a one-page payment rule your staff actually follow. Get in touch and I will look at how your email is configured today and tell you which of those you are missing. I work onsite across Dallas–Fort Worth and support businesses remotely anywhere in Texas.
Questions people ask
How do I check if a payment request email is real?
Call the supplier on a number you already had, from an older invoice, a signed contract or a website you typed in yourself. Never use a number from the email. Ask a person you have dealt with before whether they requested the change, and have them read you their account details rather than confirming the ones you were sent.
The email came from my supplier's real address. Can it still be fraud?
Yes, and this is the version that catches careful people. If someone has taken over your supplier's mailbox, the message genuinely comes from their address, quotes your real invoice numbers and copies their usual tone. Nothing in the message will look wrong. Only a phone call to a number you already had will show it up.
The fraudulent invoice has already been paid. Can the money be recovered?
Sometimes, and only if you move fast. Call your bank's fraud line first and ask for a recall or a SWIFT indemnity request, then file at ic3.gov, where the FBI runs a recovery process for fraudulent transfers. Report to local police for a case number and notify your cyber-insurance carrier before spending money on recovery.
Should you tell the supplier their email may be hacked?
Yes, by phone, on a number you already had. If the fraud came through their mailbox, they may not know, and every other customer of theirs is receiving the same message. Expect an awkward conversation. It is far less awkward than the one where two businesses discover the problem separately a month later.
What single control prevents most invoice fraud?
A written rule that no payment destination changes without a phone call to a previously known number, made by someone other than the person who received the request, and logged with the invoice. Pair it with a second approver above an amount that would hurt. Together those two habits stop the great majority of attempts.
Does antivirus or spam filtering stop business email compromise?
Not reliably. These messages usually carry no attachment, no link and no malicious code, so there is nothing for a scanner to catch. Filtering helps with look-alike domains and volume phishing, and external sender tagging makes spoofed display names obvious. The decisive controls are multi-factor authentication, forwarding-rule alerts and a payment verification process.



