A payment redirected to a criminal account, usually by compromising a real email thread rather than inventing a new one.
The invoice looks right because it is often the real one, with one field changed. The supplier's name, their logo, their reference numbers and their payment terms are all genuine.
What changed is the account number. Sometimes the email came from the supplier's own mailbox — which is why it reads like them.
How the thread gets taken over
- A mailbox at the supplier, or at the customer, is compromised — usually through a password that leaked elsewhere and was reused.
- A forwarding rule is added so that replies are copied out, letting the attacker read the conversation without sending anything.
- When an invoice is due, a reply lands on the existing thread, apologising for a change of bank details.
- The old account is left open long enough for the payment to clear, and closed before anyone can reverse it.
Who gets targeted
- Anyone who pays an invoice on a schedule: firms, freelancers, landlords, clubs, associations.
- Transactions large enough to matter and routine enough not to be questioned.
- Smaller organisations, where one person handles both the inbox and the payments — so the same person receives the request and approves it.
- Deals where the supplier is a one-person business without an accounts department to call.
The one call that stops it
- 1Never use the contact details in the message that asks for the change. Not the phone number, not the reply address.
- 2Call a number you already have — on a previous invoice, on the supplier's website, in your own contacts — and speak to a person.
- 3Ask them to read back the account number while you write it down, and confirm the change in writing on a channel you already trust.
- 4If a payment has already gone out, call your bank immediately and report it as an authorised push payment fraud.
- 5Report the email to your provider and tell the supplier their mailbox may be compromised — they usually do not know yet.
Frequently asked questions
The email came from the supplier's own address. Doesn't that settle it?
No. A mailbox can be accessed without the owner knowing, and replies can be read through a forwarding rule. The address proves the mailbox, not the sender's intention.
The bank details changed with a signed letter attached. Is a document enough?
No. Documents are attached to the same email and forged the same way. Only a confirmation through a channel you already had verifies a change of bank details.
We are a small organisation. Is this worth all the process?
It is the single highest-value five minutes you can add: one rule that any change of bank details is confirmed by a call to a number already on file, before any payment.
Written by The BaitScan team
Last updated September 16, 2026
Results are automated risk estimates based on public indicators and heuristics.