Bank details change request

If someone asks to change bank details (IBAN/routing/account), treat it as a payment diversion risk until verified.

Fast rule: Never change bank details via email. Verify through a known channel, then update only inside the official portal/workflow.

What to do now (safe route)

Scope: This page is about a bank details change request (payment destination). It does not solve “delayed payment” — it prevents sending money to the wrong place.
Rule: Don’t click links. Don’t open attachments. Don’t send full bank details. Verification first, changes second.
  1. Pause. Assume it’s untrusted until proven otherwise.
  2. Identify the channel: email, message, PDF, invoice note, portal notification.
  3. Stop any payment release until the request is independently verified.
  4. Verify via a known channel: call a known number or message a known contact from your records.
  5. Update only in the official system (vendor portal, payroll portal, invoicing platform) after logging in manually.
Choose payroll vs vendor route

Which scenario is this?

Reminder: Don’t mix this up with “payment delayed”. You’re here because someone mentioned changing the payment destination.

Payroll / HRDirect deposit / salary details change

  • Only change via HR/payroll portal after manual login.
  • Use internal directory (Teams/phone) — not the email thread.
  • If the request arrived during pay issues, treat as higher risk.
Open payroll verification message

Vendor / ClientInvoice payment instructions change

  • Classic BEC pattern: correct context, new destination.
  • Verify beneficiary name/country and approve via AP workflow.
  • Never accept “updated bank details” as a PDF attachment.
Open AP/Finance verification message

How to verify safely (process)

  1. Do not use the email thread to “verify”. Start a new thread or contact via known channel.
  2. Hard checks first: Reply-To mismatch, forwarding signs, and any change in beneficiary name/country/intermediary bank.
  3. Verify identity independently: call a known number from your records, or message via the official portal.
  4. Confirm without sharing details: ask them to confirm last 4 digits on file (no full IBAN by email).
  5. Change only through official workflow: portal + approvals (ideally two-person approval).
  6. Record it: who verified, how, when, and what exactly changed.
“Matches the invoice/contract context” is not proof. Compromised inboxes preserve context perfectly.

Copy-ready templates

Message (new thread): verification request AP/Finance: verify vendor bank change Payroll/HR: verify direct deposit change Internal alert (suspected diversion)
Message (new thread): verification request (copy-ready)
Subject: Bank details change request — verification required (new thread)

Starting a new thread for verification (not using the previous email for security).

Hi [Name],

For security, I can’t update bank details based on email instructions.
Please confirm the change through the official portal/workflow we already use.

If portal confirmation isn’t available, please confirm the last 4 digits currently on file (no full IBAN by email),
and I will verify via a known phone number/contact from our records before any change.

Thanks,
[Your name]
      
AP/Finance: verify bank details change (copy-ready)
Subject: Verify bank details change request — [Vendor/Client name] / Invoice [#]

Hi AP/Finance,

We received a request to change bank details for:
- Vendor/Client: [name]
- Vendor/Supplier ID: [ID]
- Invoice #: [#]
- Amount: [amount]
- Due date: [date]
- Requested bank country: [country]
- Beneficiary name (as requested): [name]

Before any update or payment release, please confirm via the official workflow:
1) Whether a bank change is expected (Yes/No)
2) Who approved it (name) and when it was last verified
3) The approved method (vendor portal / signed form / verified callback)

For security, we should not accept new bank details via email.

Thanks,
[Your name]
      
Payroll/HR: verify direct deposit change (copy-ready)
Subject: Direct deposit change request — verification required (new thread)

Starting a new thread for verification (not using the previous email for security).

Hi Payroll/HR team,

I received a request related to changing/confirming my bank details.
For security, I will only make changes through the official payroll/HR portal after manual login.
I will access the portal via bookmark/intranet, not via any links sent to me.

Please confirm:
1) Whether any change request is currently pending on my profile (Yes/No)
2) The official steps/portal path to review it
3) Who I can contact via internal directory/Teams if something looks wrong

I will not share full bank details, OTP, or codes by email.

Thanks,
[Your name]
[Employee ID / Team]
      
Internal alert: suspected payment diversion (copy-ready)
Subject: Potential payment diversion attempt — bank details change request

Hi [Team],

We received a request to change bank details for [vendor/client/payroll].
This may be a payment diversion attempt.

Actions taken:
- No links clicked / no attachments opened
- No bank details or codes shared
- Payment release paused (if applicable)
- Verification initiated via known contact/channel

Please advise next steps and flag any related threads/domains.

Thanks,
[Your name]
      

If you already updated details or sent money

Do this now: try to stop/recall the transfer, notify the payment owner, and preserve evidence.
  1. Call your bank immediately: ask for recall/stop (depends on method and timing).
  2. Notify AP/Finance or Payroll lead: “Potential diversion — destination may be wrong.”
  3. Report internally: IT/Security / incident channel.

What to do, in order

Step 1

Freeze: stop the change and pause payment release.

Step 2

Verify: independent callback / portal message via known channel (not the email thread).

Step 3

Approve: update only in the official system, ideally with two-person approval + record who verified.

Step 4

After: confirm on the next payment (or small test payment where possible) that the destination is correct.

High-risk signs

  • Urgency: “today”, “final notice”, “payment will fail.”
  • OTP/MFA requests or any “security code”.
  • Attachments (PDF/forms) pushing you to “update bank info”.
  • Links to non-company domains or shortened URLs.
  • Beneficiary or bank country changed unexpectedly.
  • Reply-To mismatch or “please reply to a different address”.

Risk

Verified

Confirmed via known channel and updated inside the official system with recorded approval.

Unverified

Email request where you have not yet confirmed via known channel. Treat as unsafe until verified.

Diversion likely

Destination changed and you can’t confirm via known channel (or they push urgency/attachments/links).

FAQ

Is a request to change bank details usually a scam?

No — legitimate changes happen. But email-based changes are a top payment diversion attack, so treat it as untrusted until verified.

What is a payment diversion scam?

It’s when scammers trick you into sending money to a different bank account by “updating” bank details for a vendor, contractor, or payroll.

Should I ever send IBAN/routing by email?

Avoid it. Use official portals and approved workflows. If you must communicate, share only partial identifiers (e.g., last 4 digits) for verification.

How do I verify a bank change request safely?

Use a separate channel: call a known number from your records or verify inside the vendor portal after logging in manually.

What if the email comes from a real person at the company?

Inboxes can be compromised. “Real sender” does not mean “safe request.” Still verify through a second channel.

Are PDF forms safe if they look official?

No. PDFs are often used to create credibility and hide malicious links. Treat attachments as untrusted until verified.

What if they ask for OTP/MFA to “confirm identity”?

That’s an account takeover attempt. Stop and report internally.

What if I already changed the bank details?

Act immediately: contact AP/Finance, attempt to recall/stop the next payment, notify your bank, and report as a security incident.

How can finance teams reduce this risk?

Use two-person approval, verified callbacks to known numbers, and portal-only changes. Never accept bank changes from email alone.

Why do scammers send these requests right before payday or invoice due dates?

Because that’s when you’re under pressure and more likely to “just do it fast.” Pressure is part of the attack.

What’s the safest wording when I reply?

Short: “We don’t change bank details via email. Please confirm through the official portal/workflow.” Use the copy-ready templates above.

How do I confirm the final destination before sending a large payment?

Use a verified workflow (portal + approvals) and, when possible, confirm via verified call or send a small test payment first.

External concepts

ClearExplained — simple pages that remove panic and reduce mistakes.