Skip to content
FIN-CSIRT
RS
Report an incident

FIN-CSIRT / Practical lesson

Check an overseas invoice before paying

Confirm changed bank details independently of the message requesting the change.

Staff paying suppliers and business partnersAbout 4 minutes of reading + 3 questions
Start with the example Has something already gone wrong?

What you will learn

  • Recognise an attempt to divert a payment.
  • Verify a new account through a previously known contact.
  • Prepare useful details for the bank if a payment is misdirected.

Practice example

Same supplier, same invoice, new account

Show the example explanation
Changed payment details
A change may be legitimate, but needs independent verification before the payment instruction is updated.
A new number for confirmation
Calling a number from the same message may put you back in touch with the attacker. Use a previously known contact.

What changes in an invoice scam?

The aim is to send money intended for a real business partner to a different account. An attacker may imitate a supplier or introduce altered details into an existing conversation. An invoice can therefore list the correct goods, amount and deadline alongside the wrong payment account.

This lesson concerns cyber fraud affecting overseas invoice payments. The same payment diversion mechanism can also affect domestic business partners.

An account change needs checking

A new account, an unexpected change of instructions and pressure over a supposedly delayed shipment require extra attention. None proves fraud on its own. The practical consequence is the same: pause execution until you have verified the change.

Do not check only the logo, signature or invoice format. Compare the instruction with the partner’s previously approved details and establish exactly what changed.

Keep confirmation separate from the suspicious message

  1. Find the supplier’s contact in previously verified records, not in an amended signature or new attachment.
  2. Use that channel to confirm that the supplier really requested an account change and check the details for the particular payment.
  3. Record the check and obtain approval under your internal procedure before updating details and paying.
  4. If the contact is unavailable or confirmation is unclear, keep the payment on hold and involve the responsible person in your organisation.

A reply in the same email conversation is not independent confirmation if the account has been compromised. Our business email compromise guide explains how an attacker can misuse a genuine business account.

If the payment has already been sent

Contact the bank that made the payment immediately. Have the amount, currency, time, transaction reference and recipient details from the instruction ready. Explain that you suspect payment diversion and follow the bank’s guidance. Stopping or recovering the money cannot be promised in advance.

Notify the responsible internal team and the real business partner through a verified channel. Preserve the original correspondence and both document versions, if available. Do not remove evidence or send an additional payment as a “test”.

When reporting the related cyber incident to FIN-CSIRT, include the steps you have already taken. That report does not replace urgent contact with the bank and your internal procedure.

Check your knowledge · 3

Your turn to choose the next step.

Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.

Questions and explanations are also available without JavaScript.

A supplier sends new payment details in a familiar email thread. How do you check the change?

Why does this matter? Changing the account sends money to a different destination even when the work and amount stay the same. If the new contact also comes from the suspicious message, an attacker may control both the request and its confirmation.

  1. Call a previously known supplier contact and verify the new details.Correct answer

    A previously known contact separates verification from a potentially compromised conversation. A number from existing records lets the real supplier check whether they requested the change at all.

  2. Call the new number in that message’s signature.

    The new number may be part of the same fraud. The call may look like an extra check while actually reaching the same person who altered the invoice.

  3. Request confirmation by replying to the same message.

    An attacker controlling the conversation can also send the confirmation. Repeating the question in the same channel adds no independent evidence that the new account belongs to the supplier.

An invoice has the correct purchase order, amount and supplier name, but a different account. What do you conclude?

Why does this matter? Correct business details make an altered invoice convincing. Redirecting the money requires only one wrong detail: the recipient’s account.

  1. Correct business details prove the account is trustworthy.

    An attacker may have access to real correspondence and documents. Details from genuine documents can remain unchanged while only the payment destination is replaced.

  2. A small test payment is enough.

    A small payment does not by itself establish account ownership or justify paying the balance. An account receiving a small payment shows that a payment is possible, not that the recipient is your supplier.

  3. Business details are insufficient; the account needs independent confirmation.Correct answer

    Verify the changed detail even when the rest of the document matches the transaction. Confirming the specific account addresses the gap left by checking only the amount and purchase order.

A payment has gone to the account on a fraudulent invoice. What is the most useful first step?

Why does this matter? Another payment or an exchange with the scammer does not stop the money already sent. The bank needs details of the specific transaction to assess possible next steps.

  1. Wait for the fraudster to return the money.

    Do not rely on a reply from the person who sent the suspicious instruction. While you wait for a refund promise, the institution able to examine the transaction may not yet know it is disputed.

  2. Contact the bank immediately with payment details and start an internal report.Correct answer

    Prompt, accurate information allows the bank to assess available action. The outcome is not certain. The amount, time, recipient account and payment record reduce uncertainty about which transaction needs checking.

  3. Make another payment to the same account as a test.

    Another payment increases potential loss and does not resolve the first transfer. Each extra transfer exposes more money to the same unverified recipient without establishing that the earlier payment will return.

No registration. Your answers are not sent; the result is just for you.

Remember

Confirm the new account through an established, verified contact and record the check under your internal procedure.

How business email compromise works

References

Sources and further reading

Email and account protection follows the Serbian National CERT publication on compromised email. Verification of changed payment details is supplemented by the FBI guidance on business email compromise (United States). The organisation’s procedure and its bank’s instructions govern a specific payment.

Content last reviewed