How UK Small Businesses Can Verify Supplier Bank Detail Changes Before Paying an Invoice

For a small business, invoice fraud does not always begin with an obviously fake message. Sometimes it looks like a normal email from a regular supplier: "Our bank details have changed — please use the new account for this month's payment."

Blog Main Image

How UK Small Businesses Can Verify Supplier Bank Detail Changes Before Paying an Invoice

For a small business, invoice fraud does not always begin with an obviously fake message. Sometimes it looks like a normal email from a regular supplier: "Our bank details have changed — please use the new account for this month's payment."

If the timing matches a real invoice, it is easy to make the change without a second thought. But if an attacker has taken over a mailbox, copied a supplier's branding or sent a convincing lookalike message, the money can go somewhere it was never meant to go.

For a Bolton or Bury SME, one incorrect payment can create more than a bank problem. It can mean a supplier is still unpaid, work is delayed, cash flow is squeezed and a busy team has to spend hours trying to recover funds. The safest habit is simple: never change payment details based on an email alone.

Why bank-detail changes deserve extra caution

Fraudsters know that payment requests often involve urgency. A message might say the old account is closing today, a project will be delayed, or the sender is waiting for confirmation before the end of the day. That pressure is part of the trap.

The request may arrive after a genuine conversation, contain the correct invoice number and use a familiar signature. Those details are not proof that it is safe. A supplier's account may have been compromised, or the message may be a carefully imitated fake.

This is often called business email compromise: using a stolen or spoofed email identity to persuade someone to make a payment or change a process. You do not need a large finance department to be affected. In a 5–50 person business, the person raising an invoice, approving it and making the payment may be the same person.

A safer payment-verification process

1. Pause the change

Do not reply to the message to ask, "Is this correct?" If the mailbox is compromised, the attacker can simply confirm the request.

Do not click a link or use a phone number included in the email. Save the invoice and the original message, but put the payment on hold until the details have been checked another way.

2. Use a trusted contact route

Call the supplier using a telephone number already stored in your accounting system, supplier record or previous paperwork. Do not rely on a new number supplied in the bank-detail change request.

If you normally speak to a named contact, ask them to confirm the change verbally. For larger payments, consider a second channel as well, such as a known mobile number or an established supplier portal. The important point is that the verification route must be independent of the message asking for the change.

3. Separate the request from the approval

A simple two-person check makes it harder for one convincing message to become an irreversible payment. One person can contact the supplier; another can review the amount, account name and reason for the change before the details are updated.

This does not need to be bureaucratic. For a small team, it may be a short call or a message in an internal channel saying who verified the change and when. For higher-value payments, set a clear threshold where a second person must approve the release.

4. Update records carefully

Once the supplier has confirmed the change, update the details in the accounting system rather than copying them from an email into the banking screen every time.

Record the date, the person who confirmed the change and the contact method used. If your process allows it, keep the previous details for a short period rather than overwriting them without trace. That creates a simple audit trail if someone later asks what happened.

5. Look for warning signs — but do not depend on them

Technical checks help, but they should not replace verification. Be cautious when a request includes:

  • unexpected urgency or secrecy
  • a changed email address or slightly different domain
  • a new bank account in a different name or country
  • unusual language or a sudden change in tone
  • instructions not to call the usual contact

Email security controls such as multi-factor authentication, anti-phishing protection and mailbox monitoring reduce the chance of an attacker taking over an account. Managed IT Support can also help review who has access to finance mailboxes, whether suspicious sign-in alerts are enabled and how staff should report unusual messages. These controls are valuable, but a clear payment process is still essential because no filter catches everything.

A realistic small-business example

Imagine a North West engineering firm receives an email from a regular materials supplier on a Friday afternoon. The message includes a real purchase order number and asks the accounts administrator to use a new sort code and account number.

Instead of replying, the administrator calls the supplier's main office number from the company's records. The supplier confirms that no bank details have changed. The email account of one of the supplier's employees has been compromised.

The payment is stopped, the message is reported and the supplier is warned. The business avoids a loss because the team had agreed one simple rule: bank-detail changes must be verified outside email.

What to do this week

Write down your process before the next request arrives:

  • who verifies supplier bank-detail changes
  • which trusted numbers or portals they should use
  • when a second approval is required
  • where confirmation is recorded
  • who should be contacted if fraud is suspected

If a payment has already been sent to the wrong account, contact your bank immediately, preserve the emails and involve the relevant authorities and your IT provider. Speed matters.

A calm, repeatable process protects cash flow without making everyday payments difficult. It is one more practical way to keep your technology and business operations managed the right way.

Suggested next step

Review one supplier record today and confirm that the contact number used for verification comes from a trusted source. If you are unsure whether your email security and payment process work together, Managed IT Support can help you review the gaps.

Ready to Work With an IT Company That Actually Gives a Damn?

Book a free IT review and we'll show you exactly where your current setup is costing you money, leaving you exposed, or slowing your team down. No obligation, no hard sell.

IT Review Consultation