A source-checked field guide. The linked primary sources were reviewed for the explanations in this note. Provider examples are not universal terms. This is a local editorial preview, not individualized advice; publication review remains pending.

An emailed change to a familiar vendor’s bank account is not routine maintenance. It is a high-risk change that deserves verification outside the message thread. Business email compromise can involve a spoofed address or a genuinely compromised mailbox, so a perfect logo, correct invoice history, and normal writing style do not establish that the new instructions are genuine.

The FBI’s Internet Crime Complaint Center defines BEC as a scam targeting people who transfer funds and recommends a secondary channel to verify account-information changes (IC3).

Freeze the change, not the entire relationship

Do not reply, click a supplied portal link, or call the number printed in the change request. Mark the payment “verification hold” in the accounts-payable system. The underlying invoice may be legitimate even if the new bank details are not.

Compare the request with the vendor master record: legal name, tax identifier, previous bank suffix, ordinary contact, purchase order, approver, amount, and expected timing. A mismatch is a signal to investigate, not proof by itself.

Call a known contact on a known number

Use a number from the signed contract, an independently visited official website, or a previously verified vendor record. Ask the known contact to confirm the change and the last four digits of the new account. Do not seed the answer by reading the digits first.

Require a second internal approver to review the callback evidence. The FBI’s earlier invoice-modification guidance specifically says to use previously known numbers rather than numbers supplied in the email and to add secondary sign-off for vendor-payment changes (IC3).

If the normal contact is unavailable, do not let the requester nominate an “alternate verifier” inside the same thread. Escalate to a known manager at the vendor or wait under the documented exception process. Record who accepted any timing consequence. A real supplier can help authenticate its change; a deadline alone should not rewrite the control.

For larger or unusual payments, use a pre-agreed verification method in the contract: named authorized contacts, a secure vendor portal, or a small test payment with independent confirmation. A test payment is useful only if confirmation does not come through the same possibly compromised email account.

Make the vendor-master change auditable

Record who requested the change, who verified it, the callback number’s source, date and time, old and new masked bank details, supporting document, effective date, and both approvals. Restrict who can edit vendor masters and who can release payments; one person should not silently do both.

A hypothetical vendor emails that its next $18,000 invoice should go to a new bank. The AP clerk pauses the change, calls the controller at the number in last year’s contract, learns no change was requested, and routes the email to security. No invented “voice glitch” was needed—the separate channel broke the scam.

For a genuine change, send confirmation to the vendor’s previously known business address and keep the old account inactive rather than deleting its history. That makes later review possible and helps staff notice a request to switch back unexpectedly.

If payment already went out

Contact the sending financial institution immediately through a verified number and ask about recall or fraud procedures. Time matters, but recovery is not guaranteed. Preserve the original message with headers, payment confirmation, callback notes, and internal logs. Report through the organization’s incident process and to IC3 where appropriate; do not warn the suspected mailbox from the compromised thread before security preserves evidence.

Review adjacent invoices and recent vendor-master edits. A single fraudulent request can indicate broader mailbox access. Reset affected credentials and move finance email to phishing-resistant authentication; the passkeys and recovery guide explains why the fallback path matters.

The FTC advises clear invoice-approval procedures and staff training because urgency and impersonation are common business-scam tactics (FTC). Pair this control with merchant payout reconciliation so an outgoing payment is matched to a verified obligation, not just an email.

Sources

Evidence & dates

Prepared 19 Sept 2026 · source checks 19 Sept 2026 · website publication pending. Undated means no publication date was established on the reviewed page.

Federal Bureau of Investigation Internet Crime Complaint Center · Business Email Compromise

BEC definition, secondary-channel verification, address checks, and incident response.

Source publication date: undated · checked 2026-09-19 · full page reviewed · evidence: verified · recheck by 2026-12-19

Read the primary source ↗
Federal Bureau of Investigation Internet Crime Complaint Center · Business E-mail Compromise: The 3.1 Billion Dollar Scam

Invoice-modification scenario, known-number callback, and secondary approval controls.

Source publication date: 2016-06-14 · checked 2026-09-19 · full page reviewed · evidence: verified · recheck by 2026-12-19

Read the primary source ↗
Federal Trade Commission · Scams and Your Small Business: A Guide for Business

Invoice verification, approval procedures, impersonation, urgency, and staff training.

Source publication date: undated · checked 2026-09-19 · full page reviewed · evidence: verified · recheck by 2026-12-19

Read the primary source ↗
KEEP THE THREAD GOINGUse a callback protocol when a familiar voice asks for money →Reconcile a merchant payout without mistaking it for sales →Passkeys resist phishing only if recovery does too →Reading path: Slow down the suspicious request ↗Return to the library →