Skip to main content
Qubicweb logo
CuratedPayment diversion

Invoice bank detail switch review

7/1/2026, 11:44:56 AM

Decision summary

If you see this, take these steps

Capture verification workflows, supplier onboarding controls, and redacted examples of altered payment instructions.

  • Verify payments independently

    Do not release goods or funds until you confirm inside your bank app.

  • Escalate suspicious requests

    Use the official support channel instead of replying to the scam chat.

  • Report identifiers

    Send handles, phone numbers, and payment links so TrustOps can corroborate.

Playbook sections

  • What happened
  • How it works
  • Red flags
  • What to do now
  • Evidence / references

What happened

An attacker compromises or imitates a supplier conversation, then sends replacement bank details with enough context to look legitimate.

How it works

The fraud succeeds when payment teams trust the email thread and skip independent verification of changed bank details.

Red flags

  • Payment details change close to the due date.
  • The message discourages phone verification.
  • Sender address, reply-to address, or attachment name differs from the usual pattern.

What to do now

Use a known phone number or verified procurement channel to confirm any bank-detail change before payment. If payment was sent, call the bank immediately and preserve the email headers.

What not to do

Do not verify changed account details by replying to the same email thread that introduced the change.

Evidence notes

  • Email headers, invoice versions, and changed bank details help investigators.
  • Publish only redacted bank identifiers and never expose full account data publicly.

Moderation brief

Capture verification workflows, supplier onboarding controls, and redacted examples of altered payment instructions.

Forum status

Read-only curated thread

This public thread is a moderated briefing surface. Fresh evidence and supporting notes go through reviewed submission routes before TrustOps updates the public thread. Use reports for incident evidence, Ask TrustOps for questions, and fraud cards for card-specific deliberation.

Have more intelligence to add? Return to the forum index or review community rules.