Vendor Invoice-Redirect (Changed Bank Details)
A scammer (often via a hacked vendor mailbox) emails that a supplier's bank details have changed, redirecting your next payment to the fraudster's account.
Think a message like this reached you? You can check it right now.
What this scam is
Attackers compromise or spoof a supplier's email and notify your accounts-payable team that the vendor's banking details have changed, providing a new account for upcoming invoices. Your legitimate payment then goes to the scammer. Because it references a real vendor and real invoices, it's very convincing. Verifying any bank-detail change by phoning a known contact at the vendor — not the number in the email — is the essential control.
What it usually looks like
- An email that a vendor's bank/payment details have changed.
- New account details for your next invoice payment.
- A tie-in to a genuine outstanding invoice.
- A sender address that may look right but is spoofed/hacked.
Common warning signs
- Bank-detail changes requested by email.
- New accounts for existing vendors.
- Urgency about an upcoming payment.
- Reply-to or domain subtly different from the real vendor.
Example wording scammers use
“Please note our banking details have changed — update our record and remit invoice #4471 to the new account below.”
“Our old account is under audit; use the new details for all future payments.”
These are illustrative examples written by ScamSplain, not real messages.
What the scammers want
- To redirect a legitimate payment to their account.
- To exploit trust in a real vendor.
- A wire that's hard to recover.
What to do
- Verify any bank-detail change by calling a known vendor contact (not the email's number).
- Require a documented, verified process for changing payee details.
- Flag and hold payments to newly-changed accounts for review.
- Educate accounts-payable staff on this scam.
What to do if you already responded
- Contact your bank immediately to attempt recall.
- Notify the real vendor and your security team.
- Report to ic3.gov and reportfraud.ftc.gov.