An invoice arrives from a supplier you pay every month. The amount looks right and the email follows a conversation you recognise. There’s just one change. They want you to pay a different bank account.
Check the bank details separately from the invoice. You might owe the supplier exactly that amount, but you still need to know where your money is going.
In its January 2026 invoice-fraud campaign, the National Crime Agency describes criminals impersonating suppliers or intercepting emails to divert payments. It advises calling the genuine supplier on a number you’ve used before to check any change before transferring money.
Even a familiar email needs checking
The NCSC’s business payment fraud guidance explains how attackers can tailor messages to an organisation and impersonate someone it regularly deals with. An invoice that looks genuine, or a request to use a different account, can be part of the attack.
Your checks need to work even when the message is convincing. An odd spelling mistake or an unfamiliar signature might catch your eye. The absence of those clues doesn’t make a change of bank details safe to approve.
Imagine a building contractor expecting a £6,400 materials invoice. A message in the existing thread says the supplier has changed banks. The finance assistant has checked that the goods arrived, so everything seems ready to pay. There’s still a check missing. Has anyone spoken to the supplier through a trusted contact route to verify the new account?
Put the change on hold while you check it
Leave the supplier’s existing details in place while someone checks the request. Record the invoice, proposed change and who received it in your normal finance system or a case record with restricted access.
Call a number from the supplier records you held before the request arrived and speak to an appropriate person. Don’t use the number in the change request, even if it appears in a signature or attached letter. This follows the NCA’s independent verification advice.
Ask the supplier to confirm that they requested the change, identify the invoice and verify the destination through your agreed process. If your usual contact is unavailable, keep the payment pending and speak to the person responsible for finance. A deadline doesn’t remove the need to check who you’re paying.
Record who you contacted, how you reached them, when you checked and what they confirmed. Keep sensitive financial details in your approved finance system so they don’t end up scattered across chat messages.
Make the second approval meaningful
If you have enough staff, have one person update the supplier record and another authorise the payment. The approver needs to see how the change was verified. Forwarding the original email for a second person to read doesn’t add an independent check.
In a very small business, a director or external bookkeeper may be able to provide that second check. Agree this in advance and arrange cover for holidays. Otherwise, a busy colleague may be left deciding who can approve a payment five minutes before the banking cut-off.
Use the same checks when a director asks you to change payment details. The NCSC’s phishing guidance recommends verifying important email requests through another form of communication. Staff need to know they can pause a payment to check it, whoever appears to be asking.
Use the bank’s name check properly
Confirmation of Payee helps compare the name entered with the name on the receiving account when setting up or changing a payee. The Payment Systems Regulator explains that outcomes include a match, close match or no match.
Pause if you get a mismatch, an unexpected name or no result, and follow your bank’s guidance. Don’t keep trying different names just to get a match.
A match tells you about the name on the account. It doesn’t prove that your supplier requested the change or that the invoice is legitimate. You still need the independent supplier check, even when the banking screen looks reassuring.
If the payment has already left
Contact your bank immediately through its official app, website or a verified number. Explain that you suspect payment diversion and follow its instructions. Tell your IT contact promptly too. The NCSC recommends both steps.
Keep the original messages, invoices and payment references, and write down the sequence of events while it’s fresh. Contact the supplier through a trusted route to find out what they actually sent. Keep sensitive discussions out of the suspect email thread.
Report cyber crime or fraud in England, Wales and Northern Ireland through Report Fraud. In Scotland, contact Police Scotland on 101. Report Fraud says organisations under a live cyber attack should call 0300 123 2040 immediately. Reporting does not replace the urgent call to your bank.
If an email account may have been compromised, ask your IT provider to help contain and investigate the incident. Our first-hour cyber attack guide explains how to organise the response and record decisions.
Practise the awkward conversation
Give finance staff a sentence they can use without feeling awkward: “We check all changes to bank details using the contact information we already hold. I can release the payment once that’s done.”
Try the imaginary £6,400 invoice at your next team meeting. Who makes the call? What happens if they’re on holiday? Where do they record the result? Sort out those details now so the process is easy to follow when a real request arrives.