Skip to main content
Practical guidePeople and account security5 min read

New Supplier Bank Details? Check Before You Pay

How to check a supplier’s new bank details, use Confirmation of Payee and act quickly if you think you’ve paid the wrong account.

AI-assisted guidance from RightCyber. Sources checked on 16 September 2026.

BylineWritten by RightCyber · Published by RightCyber

PublicationPublished · Updated

Source statusReviewed 16 September 2026 · Review due 16 December 2026

At a glance

Check new bank details with the supplier using contact information you already hold. Do this before changing their record or paying the invoice.

On this pageArticle contents

Share this article

LinkedInEmail

An invoice arrives from a supplier you pay every month. The amount looks right and the email follows a conversation you recognise. There’s just one change. They want you to pay a different bank account.

Check the bank details separately from the invoice. You might owe the supplier exactly that amount, but you still need to know where your money is going.

In its January 2026 invoice-fraud campaign, the National Crime Agency describes criminals impersonating suppliers or intercepting emails to divert payments. It advises calling the genuine supplier on a number you’ve used before to check any change before transferring money.

Even a familiar email needs checking

The NCSC’s business payment fraud guidance explains how attackers can tailor messages to an organisation and impersonate someone it regularly deals with. An invoice that looks genuine, or a request to use a different account, can be part of the attack.

Your checks need to work even when the message is convincing. An odd spelling mistake or an unfamiliar signature might catch your eye. The absence of those clues doesn’t make a change of bank details safe to approve.

Imagine a building contractor expecting a £6,400 materials invoice. A message in the existing thread says the supplier has changed banks. The finance assistant has checked that the goods arrived, so everything seems ready to pay. There’s still a check missing. Has anyone spoken to the supplier through a trusted contact route to verify the new account?

Put the change on hold while you check it

Leave the supplier’s existing details in place while someone checks the request. Record the invoice, proposed change and who received it in your normal finance system or a case record with restricted access.

Call a number from the supplier records you held before the request arrived and speak to an appropriate person. Don’t use the number in the change request, even if it appears in a signature or attached letter. This follows the NCA’s independent verification advice.

Ask the supplier to confirm that they requested the change, identify the invoice and verify the destination through your agreed process. If your usual contact is unavailable, keep the payment pending and speak to the person responsible for finance. A deadline doesn’t remove the need to check who you’re paying.

Record who you contacted, how you reached them, when you checked and what they confirmed. Keep sensitive financial details in your approved finance system so they don’t end up scattered across chat messages.

Make the second approval meaningful

If you have enough staff, have one person update the supplier record and another authorise the payment. The approver needs to see how the change was verified. Forwarding the original email for a second person to read doesn’t add an independent check.

In a very small business, a director or external bookkeeper may be able to provide that second check. Agree this in advance and arrange cover for holidays. Otherwise, a busy colleague may be left deciding who can approve a payment five minutes before the banking cut-off.

Use the same checks when a director asks you to change payment details. The NCSC’s phishing guidance recommends verifying important email requests through another form of communication. Staff need to know they can pause a payment to check it, whoever appears to be asking.

Use the bank’s name check properly

Confirmation of Payee helps compare the name entered with the name on the receiving account when setting up or changing a payee. The Payment Systems Regulator explains that outcomes include a match, close match or no match.

Pause if you get a mismatch, an unexpected name or no result, and follow your bank’s guidance. Don’t keep trying different names just to get a match.

A match tells you about the name on the account. It doesn’t prove that your supplier requested the change or that the invoice is legitimate. You still need the independent supplier check, even when the banking screen looks reassuring.

If the payment has already left

Contact your bank immediately through its official app, website or a verified number. Explain that you suspect payment diversion and follow its instructions. Tell your IT contact promptly too. The NCSC recommends both steps.

Keep the original messages, invoices and payment references, and write down the sequence of events while it’s fresh. Contact the supplier through a trusted route to find out what they actually sent. Keep sensitive discussions out of the suspect email thread.

Report cyber crime or fraud in England, Wales and Northern Ireland through Report Fraud. In Scotland, contact Police Scotland on 101. Report Fraud says organisations under a live cyber attack should call 0300 123 2040 immediately. Reporting does not replace the urgent call to your bank.

If an email account may have been compromised, ask your IT provider to help contain and investigate the incident. Our first-hour cyber attack guide explains how to organise the response and record decisions.

Practise the awkward conversation

Give finance staff a sentence they can use without feeling awkward: “We check all changes to bank details using the contact information we already hold. I can release the payment once that’s done.”

Try the imaginary £6,400 invoice at your next team meeting. Who makes the call? What happens if they’re on holiday? Where do they record the result? Sort out those details now so the process is easy to follow when a real request arrives.

Provenance

Sources reviewed

Reviewed 16 September 2026

Sources reviewed by RightCyber on 16 September 2026. A source’s classification describes where it came from; it is not a blanket claim about every source.

Disclaimer

RightCyber is independent and is not affiliated with or endorsed by the NCSC, Microsoft, or any source linked here. This article is general guidance, not legal, financial, or incident-response advice.

Clarifications

Frequently asked questions

How should we verify a supplier’s new bank details?
Call the genuine supplier on a trusted number you held before the request arrived. Hold the payment until you’ve verified the change, then record who checked it, how they reached the supplier and what was confirmed.
Does a Confirmation of Payee match prove an invoice is genuine?
No. It checks the account name against the receiving account. It doesn’t prove that the supplier requested the change or that the invoice is genuine. You still need to check with the supplier through a trusted contact route.
What if we have already paid a fraudulent invoice?
Contact your bank immediately through a verified route and tell your IT contact. Keep the messages and payment references. Report through Report Fraud in England, Wales and Northern Ireland, or Police Scotland on 101 in Scotland. Report Fraud says organisations under a live cyber attack should call 0300 123 2040 immediately.

Continue reading

Continue with a related article

If an account may have been compromised, bring in your IT responder as well as making the urgent call to your bank.

Keep exploring

Browse the RightCyber Blog
  • Resilience and incident response

    What to Do in the First Hour of a Cyber Attack

    Put one person in charge, contain the incident without making evidence loss automatic, start trusted calls and a time-stamped record, stop suspicious payments, and assess each reporting duty separately.

  • People and account security

    How Cyber Attacks Often Start

    Many incidents begin with an ordinary request to click, reset, scan, or pay. Verify money movements, bank-detail changes, and account recovery through a separate trusted channel every time.

  • People and account security

    Why MFA Isn't Enough on Its Own

    MFA still blocks a huge amount of password abuse, but phishable prompts and stolen sessions remain. Move important accounts towards passkeys or FIDO2, then review recovery, session controls, and monitoring.