If you paid an invoice and then learned the bank details were false, contact the sending bank immediately. Ask whether it can stop or recall the payment and contact the receiving institution. Verify the real supplier through a previously trusted channel, preserve the original email, and pause further payments using the disputed details.
Stop the next payment while the first is investigated
A familiar invoice can carry unfamiliar payment instructions. The fraud may involve a lookalike email address, an altered attachment, or a genuine mailbox used without its owner's permission. Do not wait to establish which one happened before alerting the bank.
The FBI's business email compromise guidance recommends immediate contact with the sending financial institution and asking it to contact the recipient institution. It also recommends independently verifying payment requests and changes to account details.
- Call the sending bank using its verified number. Give the transaction amount, currency, time, reference, and receiving details.
- Pause scheduled payments and vendor-record changes involving the disputed destination. Confirm the scope with the person authorized to manage payments.
- Contact the real supplier, solicitor, contractor, or other payee using a number you trusted before the suspicious message.
- Ask the account or IT administrator to preserve the relevant emails and investigate possible unauthorized mailbox access.
- Assign one person to maintain the incident timeline and track the bank's requests.
Do not verify inside the disputed conversation: replying to the same email or calling its new signature number can return you to whoever supplied the false details.
For a home purchase or other time-sensitive transaction, notify the genuine professional handling it through verified contact details. Explain that payment instructions may have been altered. Do not send a replacement payment merely because another urgent email appears to correct the first one.
Keep the legitimate invoice separate from the false instructions
Record what you were genuinely trying to pay for. Include the contract or purchase order, invoice number, agreed amount, and expected recipient. Then identify the message or document that changed the destination. This prevents the investigation from treating the underlying purchase and the fraudulent instruction as the same issue.
If there were multiple versions of an invoice, preserve each version. Note when and how it arrived. Do not rename a modified version “original” simply because it was the one you paid. A useful file name includes a date and a neutral description, such as “invoice received by email” or “earlier invoice from supplier portal.”
If the supplier says it never changed its bank details, record who confirmed that, the date, and the trusted number used. Ask for written confirmation through a separately verified channel if appropriate. Avoid turning the first phone call into an argument about who is responsible for the loss.
The fraud pattern is often called business email compromise, or BEC. The term does not prove whose account was accessed. A convincing email may be impersonation without a mailbox intrusion. A genuine sender address may also be part of an actual account compromise.
Give the bank a transaction record it can identify
Use the receipt from the sending bank as the starting point. Record the account holder, payment method, amount, currency, date and time, reference, and beneficiary details as displayed. Keep a copy of any bank confirmation or warning you saw while arranging the transfer.
State who actually initiated and approved the payment. If you made the transfer in reliance on a fraudulent invoice, say so. If someone entered the account without authority, describe that separately. Do not change the account of events to fit an assumed reimbursement category.
Ask the bank what it has done, what it needs next, and how you should supply the supporting documents securely. Record the case number and any time limit the bank gives. A request to contact the receiving bank is not confirmation that funds remain there or have been frozen.
The bank-report checklist after a scam payment provides a fuller evidence format. For a business account, confirm which business-specific process and contractual terms apply. Consumer payment protections should not be assumed to cover a company transfer.
| Record | Why it matters | How to label it |
|---|---|---|
| Genuine invoice or purchase order | Establishes the intended transaction | Expected supplier, invoice number, agreed amount |
| Changed payment instructions | Identifies the deception and destination change | Received time, sender address, account details supplied |
| Payment receipt | Connects the instruction to a real transfer | Bank reference, amount, currency, transaction status |
| Independent supplier confirmation | Records how the change was checked | Contact method, person reached, time, statement made |
| Bank and incident references | Connects later evidence to the correct case | Issuing organization and follow-up requested |
Preserve email evidence without spreading the problem
A screenshot captures what was visible. The original email may also preserve routing details and attachments useful to an administrator. Retain the message in its original form where possible and ask IT how to export it safely. Forwarding a message normally may not preserve all the same information.
Keep the complete sender address, reply-to address, subject, timestamps, and relevant attachment names. A display name alone is not enough. Copy exact addresses instead of retyping from memory, and clearly distinguish them from the genuine supplier's independently verified details.
Do not open a suspicious attachment again just to obtain a better screenshot. Do not send it around the business with instructions to “check this.” Arrange a safe handoff to the person handling the investigation. Evidence preservation should not create another route for infection or credential theft.
Restrict the evidence folder to people who need it. Invoices may include customer details, bank information, addresses, or confidential contract terms. Keep originals intact and make separate redacted copies when an external recipient does not need the full document.
Investigate access on both sides without assuming fault
The buyer's account, the supplier's account, a third party, or no genuine mailbox at all may be involved. The immediate job is to determine which communication channels can be trusted. An accusation based only on the visible sender name can distract from preserving the records that answer that question.
For Microsoft 365, Microsoft's compromised-account response covers blocking unauthorized access, revoking sessions, and reviewing authentication methods, app permissions, forwarding, inbox rules, and audit evidence. An administrator should coordinate containment and evidence preservation using the controls appropriate to the affected service.
Changing the password alone does not establish that all access paths have been removed. Ask the administrator what was checked and what remains uncertain. Keep security investigation notes separate from claims about who bears financial responsibility.
If the mailbox was used to reach other customers or suppliers, work with the authorized incident lead to identify the affected messages and recipients. Warning them through the same potentially compromised account may not be reliable. Use a verified communication route and factual wording that does not overstate the scope.
For a wider incident, use the business email administrator containment guidance. Finance and IT need a shared timeline, even when their immediate tasks differ. The time of a vendor-record change may be as important as the time an unfamiliar email was received.
Do not pay a second invoice until the destination is verified
A genuine supplier may still be waiting for payment. The commercial problem can be urgent, but it does not remove the need to verify new instructions. Agree on a trusted contact route and a documented process for any further payment.
Ask the person authorized to approve expenditure to review the situation. Keep the original disputed transfer separate from any proposed replacement. Identify whether the new request is for the same invoice, an additional service, or a different obligation. Avoid recording both as ordinary payments with no reference to the fraud.
Where liability, contract performance, insurance, or litigation may be disputed, seek qualified local advice. Notify an insurer through the policy's verified claims route if relevant, and ask about applicable notice requirements. Do not assume coverage or a particular outcome. This is general incident-response information, not legal advice.
A bank investigation, a police report, and the contractual discussion with the supplier may progress at different speeds. Keeping them distinct avoids treating a bank reference as resolution of the debt or a supplier's assurance as proof that a transfer can be recovered.
Reconstruct the approval trail
Record how the altered details entered the payment process. Was the bank account changed in a vendor record? Did an employee copy it from a PDF? Was a phone check made, and which number was used? Did a second approver see the original invoice or only a summary?
Use neutral, specific entries. “The account was updated after the email received at 09:20” is more useful than “finance fell for it.” The purpose is to identify which verification step was missing or bypassed and which other payments might share the same exposure.
Compare the last known genuine payment with the disputed one. If several invoices used the new account, identify them individually. If the same supposed contact handled multiple suppliers, explain that connection without assuming every transaction was fraudulent.
One owner, separate responsibilities: finance tracks payments, IT checks account access, and the incident lead keeps the facts consistent across the bank, supplier, insurer, and investigators.
Prepare the incident for reporting and follow-up
For U.S. internet-enabled payment fraud, the FBI's IC3 reporting service is an official route. Use the relevant police or fraud-reporting service in your country. Retain the submitted information and confirmation reference so later evidence can be connected to the original report.
You can create a Scam Incident Record for the diverted invoice payment. Organize the genuine invoice, changed instructions, receipt, verification call, and follow-up messages in order. Review every name, account detail, date, and amount before sharing a report.
Hacked.com does not automatically submit your record to the bank or authorities, and the record cannot guarantee recovery. You review and send the appropriate information yourself. Keep passwords, authentication codes, and unrelated client documents out of the submission.
Make future changes verifiable
A payment process is only as reliable as the channel used to authorize a change. Two people approving the same unverified email do not provide independent verification. The useful control is confirmation through a channel established before the disputed request.
The incident record should explain which details were trusted, when they changed, and how the change was checked. That explanation helps the business repair the process without relying on everyone to recognize the next convincing message by appearance.
Financial recovery may remain uncertain. A durable improvement is that the next change of bank details can no longer travel from an email directly into a payment without an independently documented check.
