What Is an RFP? RFI, RFP and RFQ Differences Explained
Almost every guide to spotting a phishing email was written for a consumer checking a personal inbox. Finance teams face a different problem. The email that costs an accounts payable department six figures is not a badly spelled prize notification — it is a plausible message about a real invoice, from a real supplier's real mailbox, asking for one small change to where the money goes. This guide covers the signals that genuinely still work in a payments context, the peer-reviewed evidence on how well people actually detect them, and the control that keeps working after detection fails.
Sources: FBI IC3 2025 Internet Crime Report; Heiding et al. (2024); Ho et al., IEEE Symposium on Security and Privacy 2025.
To spot a phishing email in a finance context, stop grading the writing and start grading the request. Modern lures are fluent, arrive inside genuine email threads, and often come from a supplier's real, compromised mailbox — so spelling, tone and sender domain are no longer reliable tells. The signals that still work are behavioural: a request to change payment details, pressure to skip a control, a destination that does not match the supplier's country of operation, and an entity name that is subtly not the one on your contract.
Then treat detection as fallible. In the largest randomised trial of anti-phishing training to date, embedded training cut click rates by about 2%, and over eight months more than half of employees clicked at least one phishing link. The control that does not decay is verifying the destination bank account against the company you intend to pay, before the payment is released.
- The nine signals that still matter
- Fewer reports, far more money
- Why the old tells stopped working
- Detection is a probability, and it decays
- The attack behind the email
- Follow the money
- The natural experiment
- What each control actually catches
- When everything matches and it is still fraud
- Who actually absorbs the loss
- A verification workflow that survives a good lure
- How to tell the control is working
- If you are the one being impersonated
- If you have already paid
- Frequently asked questions
Everything below concerns redirection: a genuine obligation paid to the wrong account. It does not cover duplicate or inflated invoicing, phantom vendors created from inside the business, or collusion between an employee and a supplier. Those are internal-control and audit problems with different signals and different owners, and no amount of destination-account verification will surface them. Keep the two risk classes separate; conflating them is how organisations end up believing one control covers both.
The nine signals that still matter in accounts payable
Generic phishing checklists are built around the 2010s lure: a stranger, a bad link, a spelling mistake. That attack still exists, and your email gateway catches most of it. The attack that reaches a payments approver has already survived the gateway, and it usually has none of those properties. The list below is ordered by how well each signal survives a competent 2026 attacker — not by how often it appears in a training module.
A request to change bank details — in any channel, for any reason
This is the single highest-value signal in accounts payable, because it is the objective of almost every attack that targets it. New account, new bank, new country, "our old account is being audited", "we've switched to a new factoring provider". The reason given is irrelevant; the request itself is the trigger. Treat it as a re-verification event every time, including when it comes from a supplier you have paid for a decade.
Still reliablePressure to bypass a control, framed as a favour
"Can we skip the call-back this once, I'm boarding." "No need to loop in procurement." "The CFO has already approved it verbally." Social engineering has to defeat your process, so it has to ask you to. This signal survives AI because it is structural, not stylistic — the attacker cannot achieve the goal without it.
Still reliableA destination that does not match how the supplier actually operates
A German manufacturer you have paid in euros for six years suddenly nominates an account in a third country. A UK consultancy asks to be paid into a personal-name account. The mismatch between the company you contracted with and the account you are asked to fund is a company-level question, and it is the one an email will never answer for you.
Still reliableA legal entity name that is subtly not the one on your contract
"Meridian Trading Ltd" becomes "Meridian Trading Limited", or "Meridian Trading Group Ltd", or the same trading name attached to a different registration number. Attackers register lookalike entities precisely because the name on the invoice will pass a human eyeball. Check the registration number, not the letterhead — and check that the entity is still active, not dissolved or in liquidation.
Still reliableAn invoice that breaks the supplier's own pattern
A number out of sequence, a different template version, a rounder amount than usual, terms that shortened without negotiation, or a first invoice arriving days after a "details update". Individually these are noise. Two or three together, on a payment above your materiality threshold, is a stop.
WeakeningA reply-to address that differs from the visible sender
Still worth checking, and still catches spoofing and lookalike domains — one transposed character, a homoglyph, .co in place of .com, or a subdomain that reads correctly at a glance. It fails completely against the attack that matters most, where the mail genuinely originates from the supplier's own compromised account and every header is authentic.
Urgency attached to a consequence you cannot independently verify
Account suspension, a supply halt, a late-payment penalty, a deal that collapses today. Urgency is a real feature of real business, which is why it is a weak signal on its own. It becomes meaningful only when the consequence is unverifiable through any channel except the one the message arrived in.
WeakeningA link or attachment that asks you to authenticate
Credential harvesting is how the supplier's mailbox got compromised in the first place, so this matters upstream even when it is not the AP vector. The durable fix is technical rather than perceptual: phishing-resistant multi-factor authentication, and a password manager that will only autofill on the correct domain — the two measures the UCSD researchers explicitly recommended over more training.
WeakeningSpelling, grammar, and generic salutations
This signal is finished. Fluent, correctly formatted, contextually appropriate business English is now the default output of any language model, available at negligible cost. If your control framework still depends on noticing that an email reads oddly, it is calibrated against an attacker who no longer exists.
No longer reliableQuick reference
| Signal | Status in 2026 | What to do about it |
|---|---|---|
| Request to change bank details | Reliable | Stop. Re-run full onboarding verification, whatever the reason given. |
| Pressure to bypass a control | Reliable | Escalate rather than accommodate. The request itself is the finding. |
| Destination doesn't fit the supplier | Reliable | Check the account country against where the supplier actually operates and bills. |
| Entity name subtly off contract | Reliable | Match on registration number and status, never on the letterhead. |
| Invoice breaks the supplier's pattern | Weakening | Treat as corroborating evidence, not a standalone trigger. |
| Reply-to differs from sender | Weakening | Still check it — but it cannot catch a genuinely compromised mailbox. |
| Unverifiable urgency | Weakening | Verify the consequence through a channel the message did not supply. |
| Link or attachment requesting login | Weakening | Fix technically: phishing-resistant MFA and a domain-bound password manager. |
| Spelling, grammar, salutation | Not reliable | Remove it from your control framework. It calibrates against the wrong attacker. |
Every signal in the "still reliable" group is about the request and the destination. Every signal that has decayed is about the message itself. That is not a coincidence — it is the whole argument of this article, and it points directly at where a control should sit.
Fewer phishing reports, far more money
The headline numbers explain why "spot the email" has stopped being an adequate strategy on its own. Phishing and spoofing was the most reported crime type to the FBI's Internet Crime Complaint Center in 2025, with 191,561 complaints — but reported complaint volume has actually fallen by more than a third since 2023. Reported losses over the same period went the other way, rising from $18.7 million to $215.8 million.
Two readings of that divergence are plausible, and both point the same way. Either fewer, better-targeted attacks are succeeding for much larger amounts, or a growing share of the low-value noise is now being filtered before anyone reports it. Either way, the emails that survive to the point of a decision are more valuable per attempt than they have ever been — and the average phishing complaint in 2025 cost eighteen times what it cost in 2023.
Business email compromise, which the FBI counts separately, was the second most damaging crime type by loss in 2025 at $3.046 billion across 24,768 complaints — an average of roughly $123,000 per reported incident. It is worth pausing on the ratio: BEC accounted for roughly 15% of all losses in the entire report from under 2.5% of all complaints. This is a small number of very expensive decisions.
Why the old tells stopped working
The most rigorous public evidence on AI-written phishing comes from a controlled human-subjects study by Heiding and colleagues, later published in Expert Systems with Applications. The researchers built a tool that performed its own reconnaissance on each target, wrote a personalised lure, and sent it — with no human in the loop — then compared the results against emails written by human social-engineering experts.
The fully automated attack performed identically to the human experts and roughly four and a half times better than generic phishing. The reconnaissance was accurate too: the study reported that around 88% of the AI-generated target profiles were judged useful and accurate, against 4% judged inaccurate. The economic point matters more than the click rate — a capability that previously required a skilled operator per target now runs at the cost of an API call, which means the attacker no longer has to choose between quality and volume.
The FBI's own data shows the same shift arriving in loss figures. In 2025 the IC3 logged 22,364 complaints with an AI nexus and $893 million in associated losses. Within BEC specifically, 135 complaints were flagged as AI-involved, carrying $30.3 million in losses — an average of roughly $224,000 per incident, against about $123,000 for BEC overall. That is a small sample and should be read as an early indicator rather than a settled trend, but the direction is consistent with the experimental evidence: better-targeted lures reach better-resourced targets.
Detection is a probability, and it decays
The deeper problem is not that any individual email is hard to spot. It is that "spotting emails" is a control applied hundreds of times a year by dozens of people, and it only has to fail once. The largest randomised controlled trial of anti-phishing training published to date quantified exactly how that plays out. Researchers at UC San Diego ran ten simulated phishing campaigns against more than 19,500 UC San Diego Health employees over eight months, randomising who received training and which lures they saw.
Three findings from that study should change how a finance function thinks about this.
Training barely moved the outcome. Embedded training — the pop-up you get after failing a simulation — reduced the likelihood of clicking by about two percentage points. There was no significant relationship between whether someone had recently completed the mandatory annual security training and whether they fell for a lure. The researchers' own explanation is uncomfortable and entirely believable: 75% of users spent a minute or less on the training material, and a third closed it immediately without engaging at all.
Exposure compounds. In month one, 10% of employees clicked a phishing link. By month eight, more than half had clicked at least one. Nobody in that population became careless; they simply received enough attempts. Any control with a per-event failure rate above zero approaches certainty as the number of events grows, and an accounts payable inbox is a high-event environment by design.
The lure matters more than the reader. Only 1.82% of recipients clicked a link about resetting an Outlook password. In the same organisation, 30.8% clicked a link about a change to the vacation policy — a seventeenfold difference driven purely by whether the pretext fitted the reader's world. This is the finding that most damages the standard checklist approach, because awareness training is built around the security-flavoured lure that almost nobody falls for, while the mundane, on-topic, business-as-usual lure is the one that works. A supplier emailing an accounts payable clerk about an invoice is the most on-topic message that clerk will receive all day.
None of this argues for abandoning training or email security. Filters, DMARC enforcement, phishing-resistant MFA and a well-run reporting culture all reduce how many attacks reach a decision point, and the UCSD authors explicitly recommend investing further in technical countermeasures. The argument is narrower and harder to dodge: a control that fails a small percentage of the time cannot be the last thing standing between a criminal and a wire transfer.
The attack behind the email: thread hijacking and the compromised mailbox
Most guides stop at "check the sender". That advice assumes the attacker is outside the conversation. In the attacks that reach accounts payable, they usually are not.
The sequence runs like this. A credential-harvesting lure or an OAuth consent prompt compromises one mailbox somewhere in your supplier's finance function. The attacker does not immediately act. They set an inbox rule that quietly forwards or archives mail matching keywords like "invoice", "payment", "remittance" or "bank", and they read. They learn the payment cycle, the amounts, the names, the tone, and which of your staff approves what. When an invoice thread is live, they reply inside it — from the genuine account, on the genuine domain, with the genuine signature and the genuine history quoted underneath.
That is thread hijacking, and it is why the sender-checking advice fails at exactly the moment it matters. There is no lookalike domain to spot, because the domain is correct. SPF, DKIM and DMARC all pass, because the mail is genuinely authorised. The writing style matches, because the attacker has been reading the archive for weeks. Your gateway will not quarantine it, and neither will a careful reader, because there is nothing to catch.
1. Has anyone in your finance or AP team had a mailbox compromise or a password reset in the last 90 days?
2. Can your IT team confirm there are no unexpected inbox rules or auto-forwards on the mailboxes that correspond with us?
3. Can you confirm the change from a second, independent channel — a named person on a number we already hold?
If a supplier cannot answer the second question, you are relying entirely on your own destination-side controls. That is not a reason to stop trading with them; it is a reason to know which control is actually carrying the risk.
It is not only email any more
Treating this as an inbox problem also misses where the request increasingly arrives. The FBI issued public service announcements during 2025 on unsolicited packages containing QR codes used to initiate fraud schemes, and on criminals impersonating employee self-service portals to steal information and funds — the payroll-diversion variant, where the target is an employee's own salary destination rather than a supplier invoice. Add SMS, WhatsApp, Teams and LinkedIn messages, and the practical rule becomes channel-agnostic: a request to change where money goes is high risk regardless of how it arrives, and QR codes deserve the same suspicion as links because the destination is not visible before you commit to it.
Payroll diversion is worth calling out separately because it lands in HR or payroll rather than AP, is often below the threshold that triggers finance controls, and repeats silently every cycle until an employee notices a missing salary. The same control logic applies: verify the destination account against the person or entity of record, through a channel the request did not supply.
Follow the money: it lands in an ordinary bank account
Here is the fact that reframes the whole problem. Business email compromise is often discussed alongside ransomware and crypto theft, which creates an impression that the proceeds vanish into an untraceable channel. The FBI's own 2025 figures say otherwise. Of 24,768 BEC complaints, just 1,526 had any cryptocurrency nexus at all, and those accounted for $83.8 million of the $3.046 billion total. More than 97% of reported BEC loss value moved through conventional payment rails — to a named account, at a regulated bank, in an identifiable country.
That is a weakness in the attack, and it is the only part of the chain that is fully knowable before the money moves. You cannot verify from an email whether a message is genuine; every attribute of a compromised-mailbox email is authentic by definition. You can verify whether the account you are about to fund belongs to the company you contracted with. One of those questions has a checkable answer.
The 2026 AFP Payments Fraud and Control Survey, based on 465 US treasury practitioners, found 76% of organisations hit by attempted or actual payments fraud in 2025 and 74% affected specifically by BEC — a rise on both 2023 and 2024. The same survey found paper cheques cited as targeted by 58% of respondents, ahead of ACH debits at 30% and wire transfers at 25%. Financial losses were reported by 48% of organisations under $1 billion in revenue and 66% of those above it. The attack surface is the payment file, not the mail server.
The natural experiment: what happens when the destination is checked by default
There is a live, large-scale comparison available between a market where destination-account verification is standard on push payments and one where it is not. The UK has run Confirmation of Payee across its main payment schemes since 2020, with the scope expanded to effectively all payment service providers through 2024. The US has no equivalent universal scheme.
The EU mandated the same check — and let business payers out of it
Europe has now followed the UK. Under the Instant Payments Regulation, Regulation (EU) 2024/886, payment service providers in euro-area member states have been required since 9 October 2025 to offer a Verification of Payee service free of charge, returning a match, close match, no match or other result before a credit transfer is authorised. The obligation covers standard credit transfers as well as instant ones, and it applies to banks, e-money institutions and payment institutions alike.
On paper that closes the gap this article describes across the euro area. In practice, read Article 5c closely and two carve-outs matter enormously for anyone reading this from an accounts payable function:
- Non-consumer payers can waive it. A payer who is not a consumer may opt out of receiving the verification service. Corporates that find the check adds friction to a payment run are permitted to switch it off — and can opt back in later.
- Bulk payment files are treated differently. The regulation's treatment of credit transfers bundled into a package is not the same as its treatment of individual transfers, which is precisely the mode most accounts payable teams pay in.
The regulation that fixed name-checking for European consumers contains an exit door built specifically for the payers who lose the most money per incident. If your organisation pays suppliers from the euro area in scheduled batches, do not assume the statutory check is running on your payments. Ask your bank directly whether VoP is active on your account, whether anyone has waived it, and how it behaves on bulk files — the answer determines whether you have one control or none.
In 2025 UK invoice and mandate scam losses fell to £41.3 million across 2,305 cases — the lowest loss total and the lowest case total ever recorded. CEO fraud fell to £5.6 million across 197 cases, also a record low, and now accounts for under 1% of UK authorised push payment losses. Taken together, the four "malicious redirection" scam types now make up just under a quarter of UK APP losses, down from more than half in 2020, with case volumes down from 30% of the total to 11%.
UK Finance's own analysis is explicit about the mechanism. It notes that for redirection fraud specifically, Confirmation of Payee and in-journey warnings may help catch fraudulent transactions earlier in the process — and contrasts this with scam types where the victim is paying a correctly identified account, where payee verification has nothing to bite on. Meanwhile, in the same period, US BEC losses set a record.
This is correlational, not a controlled experiment. UK reimbursement rules, sustained public awareness campaigns and bank-side detection all changed over the same window, and the two datasets define fraud differently. But the pattern is consistent with the mechanism: redirection fraud fell where the destination account started being checked, and did not fall where it wasn't. UK Finance attributes the decline to industry prevention investment, of which payee verification is a named component.
There is a timing dimension too, and it is moving against payers. A credit transfer is irrevocable once settled; recovery depends entirely on freezing funds at the receiving bank before they are moved on. As euro-area instant transfers, UK Faster Payments and US instant rails become the default rather than the exception, the interval between "approved" and "unrecoverable" shrinks from days to seconds. Every control that runs after authorisation is losing ground; only controls that run before it are unaffected.
One further UK number complicates any comfort a European finance team might take from the domestic trend. International payments used in APP fraud doubled in volume in 2025, with value up 40% to £69.6 million. Domestic verification schemes stop at the border. The moment a supplier sits outside the scheme's coverage, the destination account goes back to being an unverified string of digits — which is exactly the gap that CoP and VoP leave open for cross-border suppliers.
Check the destination account before the payment leaves
MonitorPay answers the two questions a phishing email can never answer for you: is this bank account real, active and held by the name you are paying, and is the company behind it registered, active and owned by who you think. One API call returns both — IBAN and local account validation, payee name matching with confidence scoring, account ownership confirmation, and registry-sourced company data including directors, shareholders and ultimate beneficial owners. Coverage spans direct bank account verification in 49+ markets and company records drawn from 200+ government registries.
Continuous monitoring means a supplier verified at onboarding does not silently drift: you get an alert when an account or a company record changes, rather than discovering it during a payment run. To be clear about the boundary: MonitorPay does not read or scan your email, and it does not initiate, hold or settle funds. It answers one question — whether the destination is safe to pay — and logs the answer for audit.
What each control actually catches
No single layer is sufficient, and the useful question is not "which tool stops phishing" but "which failure does each layer leave behind". Mapped honestly, the gaps line up.
| Control | What it catches | What it leaves open |
|---|---|---|
| Email gateway, SPF/DKIM/DMARC | Spoofed domains, lookalike senders, bulk campaigns, known-bad infrastructure. | Mail sent legitimately from a supplier's genuinely compromised mailbox. Every check passes. |
| Anti-phishing training | Obvious credential-harvesting lures; builds a reporting culture that shortens response time. | Roughly a 2-point reduction in click rate, and no measurable effect from annual mandatory training. |
| Phishing-resistant MFA | The credential theft that creates the compromised mailbox upstream. High return on investment. | Does nothing once the attacker is inside a supplier's estate rather than yours. |
| Call-back verification | Most straightforward impersonation — if, and only if, the number comes from your master file rather than the email. | Numbers changed in the same compromise; voice cloning of a known contact; time pressure that turns a call-back into a voicemail. |
| Dual approval | Unilateral action by a single compromised or coerced employee. | Two people approving the same convincing instruction. Both saw the same email. |
| Confirmation of Payee / VoP | Name-to-account mismatch on domestic payments in covered schemes. | Suppliers outside the scheme's geography; a matching name on an account controlled by a fraudulent entity. |
| Cross-border account verification | Whether the account exists, is active, and matches the payee name in markets no domestic scheme reaches. | A correctly named account belonging to a company that is not what it claims to be. |
| Registry-sourced company verification | Entity status, incorporation date, directors, shareholders and beneficial ownership behind the payee. | Nothing at the payment layer — which is why it belongs alongside account verification, not instead of it. |
| Positive pay and ACH debit blocks | Altered or counterfeit cheques and unauthorised debits pulled from your account. | Nothing at all in this attack class. These defend against money being taken; BEC works by getting it sent. |
| Vendor master file controls | Unauthorised edits to supplier contact and bank records — the data every other control trusts. | Records that were already wrong. Data hygiene is a precondition, not a detection layer. |
| Continuous monitoring | Changes to an account or a company record after onboarding, when nobody is looking. | Requires acting on the alert. A signal nobody triages is not a control. |
The two rows worth reading together are Confirmation of Payee and registry-sourced company verification. A name match confirms that the account you are paying belongs to a party using that name. It does not confirm that the party is the supplier you contracted with, that the company is still trading, or that control of it changed hands last month. Those are company red flags a bank account match will not catch, and they are the residual risk after every other layer has done its job. If you are evaluating tooling for this layer, the trade-offs between providers are set out in our comparison of the top bank account verification providers in 2026.
When everything matches and it is still fraud
This is the scenario that makes experienced AP managers uncomfortable, because it defeats a checklist mentality entirely. Consider a payment where every conventional check returns a clean result.
The email is authentic. It came from the supplier's real domain, passed DMARC, and sits in a thread with eighteen months of genuine history.
The invoice reconciles. It matches an open purchase order, at the agreed rate, for goods actually received.
The account is real. The IBAN validates, the bank exists, the account is open and can receive credits.
The payee name matches. The account holder's registered name corresponds to the name on the invoice.
Every one of those is true, and the payment is still going to a criminal. What makes it visible is not any single check but the co-occurrence of company-level signals that no payment-layer control examines.
1. The entity receiving payment was incorporated four months ago, while the trading relationship is six years old.
2. Its registered name differs from your contracted counterparty by one word — a suffix, a "Group", a "Holdings".
3. A change of director or shareholder was filed within the last ninety days.
4. The registered address is a formation-agent or mail-forwarding address shared with dozens of other entities.
5. The nominated account sits in a country with no operational connection to where the supplier actually manufactures, staffs or bills.
Any one of these is unremarkable. Companies restructure, directors resign, businesses open accounts abroad for legitimate treasury reasons. Three or more appearing at the same moment as a payment-detail change is a different object entirely — it is a profile, and profiles are what registry data is for. Ownership signals in particular repay attention, which is why beneficial ownership verification belongs in a payments workflow and not only in a compliance file. The practical test is not "does this check pass" but "does the company behind this account look like the company I have been trading with". That question is answerable in under a second, and it is not answerable from an inbox.
Who actually absorbs the loss
This is the part most phishing guidance leaves out, and it is the part a CFO will ask about first. When a business authorises a payment to a fraudster, the money was not stolen from the account — it was sent from it. That distinction determines who carries the loss, and in most cases the answer is your organisation.
In the UK, the Payment Systems Regulator's mandatory APP reimbursement rules apply to payments made from personal, micro-business and charity accounts, up to £85,000, claimed within 13 months, on Faster Payments and CHAPS. A mid-market or enterprise buyer sits outside that scope entirely. The recovery data reflects it: of £28.0 million in invoice and mandate losses on UK business accounts in 2025, £10.6 million was returned — about 38%. On personal accounts, 71% came back. For CEO fraud on business accounts, £1.1 million of £4.8 million was returned, under a quarter.
In the US there is no equivalent reimbursement right for a business that authorised the payment. Recovery depends on how fast the incident reaches the receiving bank, which is why the FBI's kill-chain figures matter so much. And regulatory expectation is now moving in the other direction: since 20 March 2026 for large originators and 22 June 2026 for every remaining non-consumer originator regardless of volume, Nacha's amended rules require ACH originators to maintain risk-based processes to detect entries initiated under false pretenses, explicitly including social engineering and business email compromise. Detecting a fraudulently induced payment is no longer only a prudent control in the US ACH network — it is a rule.
There is a controls-documentation angle that follows from this. If your organisation is subject to SOX, payment authorisation sits squarely inside the internal control over financial reporting that management attests to and auditors test. A verification step that happens verbally, or in someone's inbox, is not evidence. A verification step that produces a timestamped result and a reason code for every payment-detail change is — and it is the same artefact that answers a Nacha examiner, an insurer, or a board asking what changed after an incident. Design the control so that it leaves a record by default rather than when someone remembers to take a screenshot.
Consumers are increasingly protected by reimbursement frameworks. Businesses largely are not, and they recover a materially smaller share of what they lose. For a corporate payer, prevention is not the cheaper option — it is close to the only option. Confirm your bank's recall policy and your insurance wording for voluntarily authorised transfers before you need them, not after.
A verification workflow that survives a good lure
The design principle is simple: assume the email is convincing, and make the payment decision depend on something the attacker does not control.
- Treat every payment-detail change as a re-verification event. Not a review, not an approval — a full re-run of onboarding checks. This applies equally to a ten-year supplier and a new one.
- Break the channel. Verify through a route that did not originate in the request: a phone number from your vendor master file, a portal login, a named contact you have spoken to before. Never a number, link or address supplied in the message itself.
- Treat a voice as evidence, not proof. Voice cloning is now cheap and the FBI records it being used to request wire payments. A call-back to a number you already held is still a strong control because you chose the number; a call you receive, or a video call where the face and voice are convincing, is not. Where the amount justifies it, confirm through a second channel or a pre-agreed challenge phrase that was never sent by email.
- Protect the master file itself. Every call-back control depends on the contact details in your vendor master being correct. If an attacker can amend a supplier record — or if a stale record has drifted for years — the "known-good" number is whatever the attacker last wrote. Lock down change permissions, log every amendment with an approver, and reconcile contact data against an authoritative source periodically.
- Verify the account, not just the format. Confirm the account exists, is active and can receive credits, and that the account holder's name matches the payee. Structural IBAN validity proves only that the digits are well-formed, and different verification methods answer different questions — see Open Banking AIS versus registry-based verification for where each one wins.
- Verify the company behind the account. Registered name and number, current status, incorporation date, directors, shareholders and beneficial ownership. Compare against the counterparty on your contract, not the name on the invoice.
- Check the geography. Does the account country make sense for where this supplier operates and invoices? A mismatch is not proof of fraud, but it is a question that deserves an answer before the money moves.
- Hold the first payment. After any details change, the first payment to a new account is the highest-risk transaction in the relationship. A short deliberate delay costs a supplier relationship almost nothing and costs a fraudster everything.
- Monitor, don't snapshot. Onboarding verification expires the moment ownership, status or account details change. Continuous monitoring converts a one-time check into a standing control.
If you suspect an email but have not paid yet
The first few minutes shape what your security team can do afterwards. Do not reply to the message and do not click anything in it. Do not forward it inline, which strips the headers your security team needs — report it through your organisation's phishing button, or forward it as an attachment. Note the exact time it arrived and who else received it. Freeze any related payment in your ERP or banking portal rather than simply declining to action it, so a colleague cannot release it in good faith while the check is running. Then verify the underlying request through an independent channel before anyone decides whether the email was genuine.
For teams running scheduled payment runs rather than one-off transfers, the same logic applies at file level: pre-flight the whole batch against account and company checks before it leaves the treasury system, and quarantine the exceptions. This is also the model that agentic AP tools need before they can be trusted to move money, since an autonomous agent has no intuition to fall back on at all.
Verifying lawfully
Company-level verification means processing personal data — director names, dates of birth, registered addresses, beneficial owners. Under UK and EU data protection law that needs a lawful basis, and legitimate interests is the usual one for fraud prevention, supported by a documented balancing assessment. Two practical points follow: keep only what the decision required rather than the full record you were returned, and set a retention period tied to the audit trail you actually need. Fraud prevention is a well-established legitimate interest; it is not a licence to retain everything indefinitely.
How to tell whether the control is working
Fraud prevention has an awkward measurement problem: success looks like nothing happening. That is not a reason to run it unmeasured, and a CFO signing off on spend will reasonably ask what improved. Four figures are worth tracking, none of which depend on an incident occurring.
| Metric | What it tells you | Healthy direction |
|---|---|---|
| Coverage | Share of payment-detail changes that went through full re-verification, not just approval. | Toward 100%. Anything below it is where the loss will happen. |
| Exception rate | Share of verifications returning a mismatch, an inactive account or an adverse company signal. | Stable and non-zero. A zero exception rate means the check is not really running. |
| Time to verify | Median hours from change request to verified outcome. | Down. This is the number that decides whether the business tolerates the control. |
| Stale supplier records | Share of the master file not verified within your review period, or with no confirmed owner. | Down. Every stale record is an unverified destination sitting in your next payment run. |
The last one is usually the most revealing and the least measured. Most organisations discover on first running it that a material share of their active supplier records have never been verified against anything, were migrated from a prior system, or point at accounts nobody can currently attribute. That is a one-off cleanup, and it is the sensible place to start rather than the workflow redesign.
If you are the supplier being impersonated
Every buyer in this article is also somebody's supplier. When your mailbox is the one compromised, your customers lose money in your name and you find out from an angry email about an invoice you never sent. Three things reduce that exposure and cost almost nothing.
- Publish a bank-details policy and never deviate from it. State plainly, on invoices and in your onboarding pack, that your bank details will never change by email and that any change will be confirmed by a named person on a call your customer initiates. This gives your customers a bright-line rule and gives you a defensible position later.
- Audit inbox rules and enforce phishing-resistant MFA across finance mailboxes. Auto-forwarding rules are the earliest reliable indicator of a compromised finance account, and they are trivial to detect once anyone looks.
- Tell customers immediately if you suspect compromise. Silence buys nothing. A same-day warning to your accounts receivable contacts is the only control that operates faster than the attacker, who is already replying in your threads.
A message you can send today
The cheapest control in this article costs one email to your supplier base. Adapt and send:
Subject: Change to how we handle payment detail updates
We are tightening how we process changes to supplier banking details, and we want you to know what to expect so that a genuine request from you is never delayed.
From now on, we will not action any change to bank details received by email, however it is worded and whoever it appears to come from. Every change will be confirmed by us calling a named contact on a number already held in our records, and verified against your company's registered details before any payment is released. The first payment to a new account may be held briefly while this completes.
If you receive a request from someone claiming to be us asking you to change our details, please treat it the same way and call your usual contact directly. If you believe any mailbox in your finance team has been compromised, please tell us the same day.
If you have already paid: the recovery window
Speed is the only variable you still control. The FBI's Recovery Asset Team runs a Financial Fraud Kill Chain that contacts recipient banks to freeze funds, and its 2025 results show what is achievable when victims report immediately.
The FBI's guidance is unambiguous: contact your financial institution immediately, request a recall of the funds along with any indemnification documents the bank requires, and file a report at ic3.gov regardless of the amount, with full transaction details. Different institutions have different policies, so knowing in advance what your bank will do is part of the control, not part of the incident. A UK-based team should also report to Action Fraud and notify the sending bank so the Best Practice Standards process can alert the receiving institution.
One case in the FBI's 2025 report illustrates why reporting matters even when your own money is gone. A March 2025 freeze on a fraudulent recipient account meant that when a second victim — a city government — wired over $6 million to the same account a month later, the receiving bank recognised it, contacted the originating bank, and the wire was recalled. The first victim's report protected the second.
Bulk, API, or the online platform
Bank account and company verification is available through whichever route fits your workflow: bulk file checks to clean an existing supplier master file in one pass, the REST API for in-workflow verification inside your ERP or payment approval process, or the online platform for one-off checks with full audit logs.
- Grade the request, not the writing. Fluency, sender domain and thread history are all authentic in a compromised-mailbox attack. The durable signals are a payment-detail change, pressure to bypass a control, a geography mismatch and an entity name that is subtly wrong.
- Detection is probabilistic and it compounds against you. Training moved click rates by about two points; over eight months more than half of a 19,500-person workforce clicked at least once. Any control with a non-zero failure rate approaches certainty across enough attempts.
- AI removed the stylistic tell permanently. Fully automated spear phishing now matches human experts at 54% click-through, at a fraction of the cost.
- The money lands in an ordinary bank account. Over 97% of reported US BEC loss value in 2025 had no cryptocurrency involvement — it moved through conventional rails to a named account you could have checked.
- Where the destination gets checked, redirection fraud falls. UK invoice and mandate and CEO fraud both hit record lows in 2025; US BEC losses hit a record high.
- The EU mandate has a corporate exit door. Verification of Payee has been compulsory across the euro area since 9 October 2025, but non-consumer payers may waive it and bulk files are treated differently. Confirm with your bank whether it is actually running on your payments.
- Businesses rarely get reimbursed. Around 38% of UK business invoice and mandate losses were returned in 2025, against 71% on personal accounts. Prevention is the only economic option for a corporate payer.
Frequently asked questions
How do you spot a phishing email?
Grade the request rather than the writing. The signals that still work are a request to change payment or login details, pressure to bypass an existing control, a destination that does not match how the organisation actually operates, and a legal entity name that differs subtly from the one on your contract. Check the reply-to address against the visible sender, and hover links before clicking. Spelling, grammar and generic salutations are no longer reliable indicators — language models produce fluent business English by default.
How can I tell if an email is fake or a scam?
Verify the claim through a channel the email did not supply. Call a number from your own records rather than from the message, log in to the organisation's site by typing the address yourself, or ask a colleague who owns the relationship. If the email asks you to act on financial details, confirm the details against a source outside the email. An email cannot authenticate itself, and a compromised genuine mailbox will pass every technical check you can run on the message.
How do I check if an email is phishing before I pay an invoice?
Run three checks in order. First, confirm the request through a known-good channel from your vendor master file. Second, verify the bank account itself — that it exists, is active, and that the account holder's name matches the payee. Third, verify the company behind it against a registry: registered name and number, current status, incorporation date, directors and beneficial owners. If the details changed, hold the first payment to the new account and treat it as a fresh onboarding.
What is the difference between phishing and business email compromise?
Phishing is the broad category of deceptive messages designed to get a recipient to click, authenticate or act. Business email compromise is the targeted subset aimed at diverting a business payment, usually by impersonating an executive or supplier — often from a genuinely compromised mailbox rather than a spoofed one. The FBI counts them separately. In 2025 phishing and spoofing generated 191,561 complaints and $215.8 million in losses, while BEC generated 24,768 complaints and $3.046 billion. BEC is far rarer and roughly 110 times more expensive per reported incident — about $123,000 against $1,100.
Does anti-phishing training actually work?
Less than most organisations assume. In a randomised controlled trial of more than 19,500 employees across ten campaigns and eight months, embedded phishing training reduced the likelihood of clicking by about two percentage points, and there was no significant relationship between recent completion of mandatory annual training and falling for a lure. Most users spent under a minute on the training material. Training is still worth running for reporting culture and baseline awareness, but it should not be treated as a payment control.
Can AI write phishing emails that pass as legitimate?
Yes. In a controlled human-subjects study, fully automated AI spear phishing achieved a 54% click-through rate — identical to emails written by human social-engineering experts, and roughly four and a half times the 12% rate of generic phishing. The AI also performed its own reconnaissance, with around 88% of generated target profiles judged useful and accurate. The practical consequence is that stylistic tells no longer separate a genuine business email from a malicious one.
What should I do if a supplier emails asking to change their bank details?
Treat it as the highest-risk request in accounts payable, because it is. Do not reply to the email. Call a contact using a number from your vendor master file, not from the message or its signature. Verify that the new account is active and that the account holder name matches the supplier. Verify that the company behind the account matches your contracted counterparty on registration number, status and ownership. Require dual approval for the change, hold the first payment, and log the whole verification trail.
Does a bank account name match mean the supplier is legitimate?
No. A name match confirms that the account belongs to a party using that name. It does not confirm that the party is the supplier you contracted with, that the company is still trading, that ownership has not recently changed, or that the entity was not incorporated last month with a name one word different from your real supplier. Account verification and company verification answer different questions, and both are needed before a payment is released.
What is email fraud detection and how is it different from email security?
Email security filters malicious messages before delivery, using reputation, authentication and content analysis. Email fraud detection is broader: it also covers the financial decision the message is trying to trigger, including payee verification, bank account validation and anomaly checks on the payment itself. The distinction matters because email security cannot flag a legitimate message from a compromised supplier mailbox, whereas verifying the destination account catches the resulting payment regardless of how convincing the email was.
What should I do if we have already paid a phishing invoice?
Act within hours. Contact your bank immediately, request a recall of the funds and ask what indemnification documents they need. File a report at ic3.gov with full transaction details regardless of the amount — in the UK, report to Action Fraud and notify your bank so the receiving institution can be alerted. The FBI's Recovery Asset Team froze $679 million of $1.164 billion in attempted theft in 2025, a 58% success rate, but that depends almost entirely on how quickly the incident is reported. Preserve the email headers and do not delete anything.