An email arrives inside a familiar supplier conversation: the invoice is correct, but the bank account has changed. The sender asks your accounts team to update the beneficiary before today's payment run. A recognisable signature and an existing email thread are not sufficient reasons to approve that change.
Business email compromise can involve lookalike addresses or access to legitimate correspondence. The FBI's business email compromise guidance recommends independently verifying payment changes and contacting your financial institution immediately if money has been transferred fraudulently. The practical control is to separate the email request from the decision to change payment details.
Pause the change, not the entire supplier relationship
Mark the request as awaiting verification. Do not edit the supplier master record or release the affected payment while the change remains unverified. Tell the internal payment approver what is being checked so a second colleague does not process the same request independently.
A useful internal rule is: a bank-detail change is a separate approval event, even if the invoice has already been approved. This keeps urgency, familiar branding and an established business relationship from replacing the required checks.
Verify through a contact route you already trust
- Retrieve the established contact. Use a supplier record or previously verified telephone number. Do not use a new number, link or QR code supplied in the change request.
- Make the callback yourself. Ask the known contact to confirm that a change was requested and identify the authorised person responsible for it. An incoming call alone does not establish identity.
- Check the supporting details. Compare the requested beneficiary information with the confirmed change and the organisation's vendor-onboarding requirements. Do not assume an attached bank letter is independently verified evidence.
- Record the verification. Note who called, the established contact route, who confirmed the change, the date and the internal approval reference. Store this in the approved finance system with appropriate access.
- Obtain the required separate approval. The person updating supplier details and the person authorising the payment should follow your agreed separation of responsibilities.
The IC3 specifically advises using previously known numbers rather than numbers in the request in its business email compromise advisory. This is a useful control for UAE teams as well; it does not replace your bank's procedures or local reporting requirements.
A realistic exception to rehearse
Imagine the supplier's usual finance contact is on leave and an unfamiliar colleague insists the payment must be completed immediately. The safe operational response is to hold the change and escalate through the established supplier relationship. A second email repeating the same instructions does not resolve the verification gap.
Before this happens, agree who can approve an exception, what independent evidence is required and where the decision is recorded. If those conditions cannot be met, keep the payment change on hold. Staff should know that following the control will be supported even when a request appears urgent.
For technical controls around this process, ITZ's business cybersecurity service can assess account access and email-security requirements. Request an email security review to discuss the mail platform, finance-team access and suspicious-message escalation.
Ask IT to investigate the email separately
Preserve the original message and headers in an approved incident record. Ask the authorised administrator to check the affected account's sign-ins, forwarding rules, mailbox access and other relevant activity. Do not broadly circulate sensitive invoices as screenshots. Restrict evidence to the people handling the incident.
Email authentication is one layer of protection, but successful authentication does not prove that a payment instruction was authorised: a compromised legitimate account can still send mail. Microsoft's DMARC documentation explains domain validation. Finance approval remains a separate control. Review access through Microsoft 365 configuration support where that is your mail platform.
If payment has already been sent
Contact your bank's fraud team immediately through a verified channel, explain the suspected redirection and follow its recovery instructions. Notify your internal incident owner and preserve the transaction details and original messages. Recovery is not guaranteed. Use the applicable local police or cybercrime reporting route rather than assuming an overseas reporting service is the correct local channel.
Request an email security review
Share your mail platform, the teams handling supplier correspondence and how suspicious requests are escalated. ITZ can discuss a scope for access review, email-security configuration and a documented handoff between IT and finance. Do not include bank statements, passwords or live incident evidence in the enquiry form.