BankChangeProof
“Our banking details have changed”: the first ten minutes
Published 29 Sep 2026
The email is short and polite: our banking details have changed, please update your records and send the next payment to the account below. It may come from a vendor you pay every month, sit in the same thread as the last invoice, and carry the right signature. Business email compromise is the FBI's name for this family of fraud, an email that appears to come from someone you trust and asks you to send money somewhere new. Its Internet Crime Complaint Center counts $55.5 billion in exposed losses from it between October 2013 and December 2023 (IC3).
This guide covers the first ten minutes after that email lands, in order. It is the entry point. The full procedure is in how to verify a vendor bank account change, step by step, and the rules to agree on in advance are in the one-page vendor bank change policy template.
Before anything else: three things not to do
- Do not reply to ask whether it is real. If the vendor's mailbox is compromised, or the reply-to address is not the vendor's, your question goes to the person who wrote the request, and the answer will be yes.
- Do not call the number in the email. A phone number in a signature block is text inside the email you are trying to verify. It rings whoever wrote it.
- Do not update the vendor record. Nothing changes in the payment system until a callback on a number you already held confirms the change.
Minutes 1 to 3: read the sender, not the name
Open the full sender address, not the display name, and read the domain one character at a time. On a phone, tap the name to see the address; the IC3 advice is to "verify the email address used to send emails, especially when using a mobile or handheld device." Then check four things.
- Lookalike characters. rn for m, l or I for 1, 0 for o, an added hyphen, or the same name under a different ending, such as .co instead of .com.
- The reply-to address. A message can show the vendor as the sender while replies go somewhere else.
- Links and attachments. A link to "view the updated remittance details" should point to the vendor's own domain. IC3 warns to "be alert to hyperlinks that may contain misspellings of the actual domain name." Do not sign in to anything from the email.
- Pressure. "Payment is due today," "our old account is frozen," "please keep this confidential." Urgency is a reason to slow down.
A domain that is exactly right does not clear the request. A real vendor mailbox can be taken over, and then the message comes from the right address, in the right thread. Reading the domain can catch a fake; it cannot confirm a change. Only the callback does that.
Minutes 3 to 5: check whether money has already moved
Search the payment system for this vendor. You need two answers: is a payment to the new details scheduled or already sent, and has anyone edited the vendor record since the email arrived.
If a payment has already gone to the new account, call your bank before doing anything else on this page. The IC3 guidance is to "immediately contact your financial institution and request a recall of the funds along with any necessary indemnification documents," and then to "file a complaint with www.ic3.gov as soon as possible," because "the FBI IC3 may be able to assist both the financial institutions and law enforcement in freezing funds." Outside the United States the order is the same: your bank first, then your national fraud-reporting service or the police.
If a payment is scheduled but not sent, put it on hold now. If the record was already edited, change it back to the last verified details and note who made the edit and when.
Minutes 5 to 8: call the vendor on the number you already had
Use a number your organization held before this email arrived: the vendor master record, a signed contract, an earlier invoice, or a call you placed before. Ask whether they sent a bank change request, and do not read the new details out first; let them tell you what they sent. There are four outcomes, and each one is worth recording.
Confirmed. The vendor sent it. Continue to a second approval and a cooling-off hold before the first payment on the new details.
Denied. The vendor never sent it. Keep paying the old, verified account, keep the email, and tell the vendor that someone is sending requests in their name.
Unreachable. The number on file does not work. Find a number through a separate channel you trust, never through this email, and treat the request as unverified until then.
No answer. Leave a message that does not repeat the new details, keep the change on hold, and call again on the same number.
Minutes 8 to 10: write it down
Before the details blur, record:
- When the email arrived, the sender address exactly as shown, and the reply-to address.
- The requested bank name and the last four digits of the new account. Never store the full account number in notes or tickets.
- Whether any payment to the new details was pending or sent, and what you did about it.
- The number you called, where that number came from, when you called, who answered, and the outcome.
- Who you told: the second approver, IT or security if the domain was a lookalike or the vendor denied the request, and the bank if money moved.
Keep the original email rather than deleting it. Your IT team, your bank or an investigator may ask for the message with its headers, and a denied request is exactly the record you want if the same vendor's name is used again.
Why the record matters later
The record is what turns "we called them" into something a reviewer can check months later. In an r/Accounting thread on vendor email compromise, one commenter described an insurance claim that "was subsequently denied because they didn't call to verify the wire instructions" (r/Accounting). Policies differ, and this is not coverage advice. The question after a loss tends to be the same one, though: can you show the callback happened, on a number you already held, before the money moved.
If the request turns out to be genuine
Many are. Vendors change banks, and some simply email the change instead of using the channel you agreed on. A genuine request still goes through the same steps: a second approval from someone who did not receive the email, and a short cooling-off hold before the first payment on the new details. The hold costs a day or two, and it gives the vendor's own finance team time to notice a change they did not make. Then ask the vendor how they will send changes in future, and write that down too.
The ten-minute checklist
Do not reply, click, or call any number in the email.
Read the full sender address and the reply-to, one character at a time.
Check for a payment to the new details. If money moved, call your bank now, then file at ic3.gov.
Hold any scheduled payment to this vendor and freeze edits to the vendor record.
Call the vendor on a number you held before this email, and record the outcome.
Write down the request, the last four digits, the callback and who you told.
Confirmed: second approval and a cooling-off hold. Anything else: the change stays on hold.
Questions
- The domain is exactly right. Is the request safe?
- Not on that basis. A vendor mailbox can be compromised, so the message arrives from the real address. The callback on a number you already held is the check that does not depend on the email.
- We already paid. Is it too late?
- Not necessarily. Call your bank and ask for a recall, then file with IC3. The guidance for both is as soon as possible.
- Is this legal or insurance advice?
- No. It is an order of operations and a list of what to record. For coverage questions, read your policy or ask your broker; for legal questions, ask counsel.
Next step
BankChangeProof is where the record from minutes 8 to 10 can live. Paste the "bank details changed" email and it compares the sender domain with the vendor's domains on file and flags lookalikes and urgency. It then records the callback outcome, takes a second approval, runs a cooling-off hold (48 hours by default) and produces one evidence PDF per change, free for 10 vendors. It does not verify who owns a bank account, make the call for you, or move or recall money. If money has already moved, call your bank first.