Accounts receives a message from a supplier: “Please send payments for this invoice to our new account.” A moment later, someone who sounds like the CEO calls and asks for an urgent transfer. The email address looks familiar, the invoice has the right logo, and the caller knows details about the company.
This may be business email compromise (BEC): a compromised mailbox or a carefully prepared impersonation of someone involved in a payment. AI makes convincing text and voice imitation easier to prepare, but it does not change the underlying problem. One message or one call should not be enough to change bank details and send money.
Three routes to the same payment
A compromised mailbox. A fraudster reads earlier correspondence and knows the dates, amounts, and people involved. A reply may arrive in the genuine thread, so the correct address alone is not proof.
An altered invoice or lookalike domain. The sender’s address differs by one character, and the attachment contains a new account. A logo and purchase order number can be copied.
A cloned voice. A short sample from a public recording may help create an imitation. A voice that sounds like the owner is still part of the request, not an independent confirmation.
Each route uses urgency and hierarchy: “do it now”, “do not involve anyone else”, “skip the procedure just this once”. That is a reason to pause the payment, not proof of employee fault or proof of fraud.
The second channel must really be separate
Confirm changed bank details by calling a number recorded before the request: from the contract, the supplier record, or earlier verified data. Do not use a number in the email, invoice, or change notice — whoever controls the message may also control that number.
A call from “the CEO” does not close the matter either. Call back on a known number, or contact another authorised person through a company messenger that was already in use. The principle is the same as with a code: the second channel should verify the person, not repeat the request.
A process that does not look for someone to blame
- Every bank-detail change pauses the payment until it is verified.
- One person checks the supplier through a known channel; another approves the change and transfer.
- The note records the time, known number, person reached, and outcome — not passwords or unnecessary personal data.
- Refusal to talk, pressure, or conflicting details goes to the named decision owner.
- Staff may pause a payment without being punished for a delay caused by the procedure.
The last point matters. If a company rewards speed and penalises questions, it creates the bypass a fraudster needs. The goal is a safe decision, not finding the person who “fell for it”.
The short bank-detail change verification card puts these steps beside the payment desk. A wider review of roles, exceptions, and access belongs in a security assessment.
The FBI’s BEC guidance describes the scheme and US reporting routes. Bank and authority contacts and reporting deadlines depend on the country and the circumstances; this article is not legal advice.