For businesses · 5 min read

When a vendor or “executive” changes payment details

Business email compromise redirects real payments to criminals. A few verification rules stop most attempts.

Sources checked October 4, 2026 · General educational guidance

The key takeaway

Verify any new or changed payment details by calling a number you already have—never one in the request.

A costly, common pattern

In business email compromise, a criminal impersonates a supplier, real estate or title company, employee, or company leader and asks for payment to new account details. The FBI’s Internet Crime Complaint Center received 24,768 such complaints in 2025, with reported losses of about $3.05 billion—a total for all reported business email compromise, not only cases involving Zelle.

The message may come from a real account that was hacked, or from an address that differs by a single character. A familiar name or an existing email thread is not proof.

Red flags

  • New bank, routing, or payment-app details for a vendor you already pay.
  • Urgency, secrecy, or a request to skip your normal approval.
  • An email address, domain, or link that differs slightly from the real one.
  • A company leader asking for gift cards or an unusual transfer while “unavailable” to talk.
  • An employee asking by email to change where their paycheck is deposited.

Controls that work for small teams

  • Before changing payment details, call back using a number from your records or an earlier invoice—never the one in the request.
  • Require a second person to approve new payees and changed details, if your bank supports it.
  • Confirm changed details again before the first payment, even if the change arrived weeks earlier.
  • Enable multi-factor authentication on email and banking accounts.
  • Do not treat a small test payment as verification. A payment that arrives shows the account works, not that it belongs to your vendor.

If money went to the wrong place

Contact your bank immediately and ask it to contact the bank that received the funds. Then file a report at IC3.gov. Speed matters, although recovery is not guaranteed.

Tell the real vendor or employee what happened, and check your email account for unfamiliar sign-ins or forwarding rules.

Sources & further reading

Provider rules can change. Check current terms and contact your bank for your circumstances.

Was this guide useful?
Suggest a correction or give feedback →