THE IDEA TO TAKE WITH YOU

Verify changes to payment destinations through a previously trusted channel, protect the accounts that control your payments, and confirm transaction status in the actual service. If fraud is suspected, contact your provider immediately.

The email arrives in an existing project thread. The invoice looks familiar. The supplier says its bank details have changed and asks you to use the attached instructions today.

Nothing about the amount or project is unusual. The destination is the only change—and that is the detail that decides where the money goes.

Payment-fraud prevention depends on verifying the payment instruction, not just recognising the conversation around it. A practical process combines identity checks, protected accounts, clear approval responsibilities, and reliable transaction evidence.

This guide explains common patterns and proportionate controls for freelancers, agencies, international businesses, and marketplace sellers. No checklist can eliminate fraud, but a consistent process can make a misleading request harder to turn into a completed payment.

Recognise the main patterns

PatternWhat the request may look likeWhat to verify
Payment redirectionA known supplier changes its bank or wallet detailsThe change through an established independent channel
Fake invoiceA plausible bill for a service or renewalThe purchase, supplier, and authorised obligation
Fake payment confirmationA screenshot or email claims money was sentThe actual status in the receiving service
Account takeoverPayout details or recovery settings change unexpectedlyAccount access, sessions, and authorised changes
Refund diversionA payer asks for money back to an unrelated destinationThe original payment and approved refund process
Support impersonationSomeone asks for codes, access, or a payment to fix an issueThe support channel and the legitimacy of the request

The Federal Trade Commission describes fake invoices and other small-business scams that exploit routine business processes. Matching an invoice to a real approved purchase is a stronger control than relying on a professional-looking document. FTC: Scams and your small business.

Understand business email compromise

Business email compromise can involve impersonation or access to a genuine email account. A request may appear in a credible thread and include details taken from real correspondence.

That is why checking spelling, logos, and the sender’s display name is not enough. A message can look convincing while directing a payment to the wrong beneficiary.

The FBI describes this pattern and recommends verifying changes to payment procedures or account numbers with the legitimate party. FBI: Business email compromise.

Treat the destination change as a separate event requiring confirmation. The fact that the invoice amount is correct does not authenticate a new account number.

Create a destination-change rule before an urgent request arrives

Decide how your business verifies new or changed bank and wallet details. Use a previously established phone number, secure portal, or another approved independent channel.

Do not use only the contact details supplied in the change request. If the request is fraudulent, those details may lead to the same person who sent it.

For important payments, require a second authorised reviewer where practical. The FBI has specifically recommended known-number phone verification and secondary sign-off for vendor payment changes. FBI: Business email compromise prevention guidance.

Keep a record of who confirmed the change, when, and through which established channel. Staff should be able to pause a payment without being pressured to ignore the process because the message sounds urgent or senior.

Use a short, specific verification conversation

A useful confirmation focuses on the commercial relationship and the proposed change. For example:

Payment-detail change verification

We received a request to change the receiving details for your business. I am contacting you through our existing contact record to verify it before updating our payment instructions.

Please confirm that your authorised team requested the change, which invoice or relationship it applies to, and how we should obtain the approved details securely.

We will record the confirmation and complete our normal payment review before using the new destination.

Do not read out passwords, authentication codes, or unnecessary personal information. A familiar voice alone may not be sufficient for a high-risk change; follow the organisation’s agreed verification process and use additional checks where appropriate.

The point is to establish authorised intent through a trusted route, not to ask whether the numbers in a suspicious message “look right.”

Separate approval of an invoice from approval of a destination

An invoice can be commercially valid while its payment instructions have been altered. Conversely, a familiar destination does not make an unrecognised invoice legitimate.

Check both. Match the invoice to the agreed work or purchase, amount, currency, and previous payments. Then confirm that the destination is the current approved one.

For a small business, keep a controlled supplier record instead of copying account details from whichever email arrived most recently. Review who can edit that record and who can release payments.

For agencies, link approvals to projects and supplier invoices. For freelancers, apply the same discipline when paying subcontractors or issuing refunds. A small team still benefits from a documented pause when something changes.

Confirm receipts in the actual payment service

A screenshot can be edited. An email can be forged. Even a genuine confirmation may show that a payment is scheduled or submitted rather than available to the recipient.

Check your bank or provider through its known website or application. Read the actual status and understand whether it describes receipt, review, availability, or completion of a payout.

Avoid releasing goods, refunding an alleged overpayment, or making another payment solely because someone supplies a convincing screenshot. The relevant commercial decision should use the actual transaction evidence and your agreed terms.

The payment timing guide explains how to distinguish stages without assuming that every delay is fraud.

Handle refunds through a controlled process

A refund request can be legitimate, but it needs to be connected to a verified original payment and an authorised commercial decision.

Be cautious when someone asks you to send a refund to a different person, bank account, wallet, or currency. Do not treat an alleged overpayment as permission to create an unrelated transfer.

Use the provider’s approved refund or return process where available. Ask the provider how to handle the situation if the original route does not offer a simple refund function.

Record the original transaction, reason, amount, authorised recipient, and resulting refund reference. Do not delete the initial payment from the ledger. Keep the linked events visible for later reconciliation.

Protect email as carefully as the payment account

Email often controls password resets, invoices, and destination-change conversations. A compromised mailbox can undermine a payment process even when the payment platform itself has strong controls.

Use unique passwords and enable suitable multi-factor authentication for email, payment services, and marketplace accounts. Prefer phishing-resistant options where the service supports them and your team can manage recovery properly.

CISA recommends MFA for business systems and describes phishing-resistant methods as a stronger option. MFA improves security but does not make an account impossible to compromise or a payment instruction automatically legitimate. CISA: Require multifactor authentication.

Review access when staff roles change. Protect recovery methods, store recovery codes appropriately, and avoid shared credentials that make it difficult to know who performed a sensitive action.

Watch payout settings on marketplace accounts

For a seller, an unauthorised change to the payout destination can redirect revenue even when customer orders continue normally.

Review notifications about payout accounts, email addresses, authentication settings, and new access. Navigate to the marketplace through a known address rather than using a link in a message claiming there is a payout problem.

Keep staff access proportionate to their role where the platform supports it. Someone who fulfils orders may not need permission to change the business’s payment destination.

If an unexpected change appears, contact the platform promptly through its official channel and preserve the relevant notices. The marketplace payout guide explains the records that help distinguish payout processing from account changes.

Apply wallet-specific checks to stablecoin payments

A token symbol is not a complete payment instruction. Verify the exact asset, network, destination, and any required memo or tag through the approved process.

Do not copy a destination from an untrusted message or assume that a similar-looking address is the same. Check the current verified receiving instructions rather than relying on a fragment of a previous transaction.

A small test payment can help test compatibility, but it does not establish the identity or authority of the recipient. It also does not guarantee that a later larger payment is permitted or free from review.

Never share seed phrases or private keys with someone claiming to resolve a transfer. See stablecoin networks explained for the technical compatibility checks.

Act immediately if you suspect a fraudulent payment

Contact the sending bank or payment provider through a trusted channel and state clearly that fraud is suspected. Ask what cancellation, recall, freezing, or investigation options are available for that actual transaction. Recovery is not guaranteed.

Secure affected accounts with appropriate technical help: review access, active sessions, credentials, and recovery settings. Preserve emails, transaction references, timestamps, destination details, and other relevant evidence.

Report the incident through the appropriate authorities for your jurisdiction. For a US nexus, the FBI identifies its Internet Crime Complaint Center at IC3 as a reporting channel. Other jurisdictions have their own processes.

Do not send another payment to “unlock” the first or pay an unsolicited recovery service promising a guaranteed return. The FTC warns that recovery scams can target people after an initial loss. FTC: Refund and recovery scams.

Make the process usable for a small team

A control that everyone bypasses is not an effective control. Keep the routine short enough to follow and the exception path clear.

Maintain approved destinations, a known contact method for counterparties, a way to record invoice approval, and an incident contact list. Define which changes require an additional review and who covers absences.

Practice a simple scenario: a supplier asks to change its account just before payment. Check whether the team can find the trusted contact, pause the transfer, verify the request, and document the result without improvising.

Review genuine mistakes and suspicious requests without blame. The goal is to improve the workflow and make early reporting normal.

Frequently asked questions

Is a name match enough to trust a bank destination?

It can be useful evidence, but it does not establish the entire commercial request or the authority of the person asking for payment. Use it alongside verified instructions and your approval process.

Does a small test transfer prove the recipient is genuine?

No. It may demonstrate that a destination can receive a payment. It does not prove who controls the destination or whether the requested change was authorised.

Can a fraudster use a genuine email thread?

Yes. Account compromise can make a request appear within real correspondence. Verify sensitive payment changes independently.

Should we contact the receiving bank directly after a suspected fraud?

Start immediately with your sending provider and follow its instructions. It can explain the appropriate escalation and contact process for the route, alongside any relevant authority reports.

Explore the linked sources, practical tools and related guides for more on this topic.

Explore more payment guides ↗