All guides

A supplier emailed new bank details. What should you do?

4 min readUpdated 19 July 2026

An email arrives from a supplier you know. Their bank details have changed; please update your records and pay the attached invoice to the new account. The email is polite, the invoice looks normal, and there is no obvious reason for suspicion.

This is the most common shape of business payment fraud, and it is worth having a fixed process for it rather than a judgement call. The process below takes a few minutes and costs nothing.

Treat every change request as unverified by default

Not as fraudulent, necessarily — as unverified. Suppliers do genuinely change banks. The point is that the email cannot establish it, and no amount of care reading the email changes that.

The reason is simple: if a criminal is inside your supplier's mailbox, the email is authentic in every way you can test. Correct address, correct signature, correct thread history, correct invoice template. Scrutinising the message harder does not help, because the message is real.

Do not reply to the email to confirm

Replying confirms the change with whoever controls that mailbox — which, in the case that matters, is the attacker. They will happily reply that yes, the new details are correct.

For the same reason, do not use a phone number from the email, and do not use a number from a new document attached to it. Both are chosen by the sender.

Call the supplier on a number you already had — from an earlier invoice, their website that you navigated to yourself, or your own records. Never a number written in the email or invoice you are checking. The person who wrote that document chose that number.

Make the call, and ask them to state the details

Ring the number you already hold and ask the supplier to tell you the account details rather than reading them out for confirmation. If you read them out first, you invite a simple 'yes, that's right' — which is worth nothing if you have reached the wrong person, and is exactly what a social-engineering attacker is hoping for.

Ask for the BSB and account number. Compare them to the document afterwards.

Have a second person approve the payment

Whoever received the email should not be the person who releases the money. This one control defeats a large share of these attacks on its own, because the attacker has compromised or persuaded one person, not two.

It does not require a finance department. A business partner, a bookkeeper, or a co-director is enough. What matters is that a second set of eyes sees the change before the payment leaves.

Write the outcome down

Record who called, which number they used, who they spoke to, and what was confirmed. If a payment is later disputed, or your insurer asks, that record is the difference between an argument and a file.

It also protects the person who made the call. If a payment does go wrong, a documented verification shows they followed the process rather than made a mistake.

A note on the first payment to a brand-new supplier

First payments deserve extra care, because there is no previous account to compare against — the usual 'has this changed?' check has nothing to work with.

For a new supplier, confirm the details through a channel you established independently: a number from their public website that you navigated to yourself, or a contact you already had before the invoice arrived. Anything sourced from the invoice itself proves nothing.

Common questions

The supplier says the phone line is down and to email instead. Is that normal?

It is a common element of the fraud. Steering you away from an independent channel is the point of that sentence. If you genuinely cannot reach them on a number you already had, delay the payment until you can — a real supplier will accept a short delay far more readily than an attacker will.

Can I just check the email headers instead of calling?

Headers are worth checking and can expose an impersonated domain or a redirected reply-to address. They cannot detect the case where the supplier's own mailbox has been compromised, because then the headers are genuine. The call is what covers that.

How often should supplier bank details be re-verified?

Any time they change, without exception, and it is good practice to re-confirm your key suppliers' details once a year as a routine matter rather than in response to a request.

Check the invoice in front of you

Paste it into the free checker and it will run every structural check on this page in about a second — the ABN, the bank details, the sender's domain and the wording. No account, and nothing you paste leaves your browser.

Check an invoice

Related guides