Security

Your Supplier Changed Their Bank Details. Check Before You Pay.

SKIMBOX Team

An email from a real supplier says they have changed banks. The invoice looks right, the tone is right, and the money goes to a criminal. Here is how payment redirection fraud works, the one control that stops most of it, and what to do in the first hour if you have already paid.

Your Supplier Changed Their Bank Details. Check Before You Pay.

The email comes from a supplier you have paid many times. It arrives in the same thread as the last invoice, written in the same tone, signed by the same person. It says they have changed banks and gives new account details for this month's payment. Everything looks right.

It is not their email. Or it is their real email account, but somebody else is typing. And the money you send will be gone within hours.

This is payment redirection fraud, also called business email compromise, mandate fraud or payment diversion fraud. It does not look like hacking. It looks like normal business, which is exactly why it works. The good news is that one simple, cheap habit stops most of it.

This guide explains how the fraud works, the warning signs, the controls government and police bodies recommend, how to protect your customers from fraud in your name, and what to do in the first hour if money has already gone.

What is payment redirection fraud?

Payment redirection fraud is when a criminal persuades a business to send a genuine payment to the wrong bank account, usually by impersonating a supplier who has changed banks or a senior manager who needs an urgent transfer.

The FBI's Internet Crime Complaint Center defines business email compromise as a scam targeting businesses and individuals who work with suppliers or regularly make wire transfers, carried out by compromising email accounts and other forms of communication, such as phone numbers and virtual meeting applications, through social engineering or computer intrusion [1].

The UK's national fraud reporting service describes mandate fraud, also known as payment diversion fraud and business email compromise, as tending to affect businesses where electronic financial transactions take place, typically through a request for payment or a notice that bank account details have changed [2].

There are three common versions:

The supplier version. An email appearing to come from a supplier says their bank details have changed. Your next payment goes to the fraudster.

The boss version. An email appearing to come from the owner or a senior manager asks for an urgent, confidential transfer. Europol calls this CEO fraud: an employee authorised to make payments is tricked into paying a fake invoice or making an unauthorised transfer [3].

The payroll version. An email appearing to come from an employee asks for their salary to be paid into a new account.

The mechanics differ slightly. The defence is the same for all three.

How big is the problem?

The FBI recorded 24,768 business email compromise complaints in 2025, with reported losses of about 3.05 billion US dollars, making it the second most costly type of cyber-enabled fraud in its report, after investment fraud.

The exact figure reported to the FBI's Internet Crime Complaint Center was 3,046,598,558 US dollars. The equivalent figure for 2024 was 21,442 complaints and about 2.77 billion US dollars [4].

An FBI public service announcement in 2024 put exposed losses worldwide between October 2013 and December 2023 at about 55.5 billion US dollars across more than 305,000 incidents [5].

These are US figures, reported to a US agency. We did not find an official UAE figure for losses to this fraud, so we cannot tell you how common it is here in numbers.

But it is not a foreign problem. In 2020, Dubai Police announced the arrest of a gang, in an operation called Fox Hunt 2, whose methods included hacking corporate emails to deceive clients into transferring money to the gang's bank accounts [6]. Abu Dhabi Police's Aman service lists company email fraud among its current scam warnings, describing a fraudster sending an email that appears to come from a company manager asking for money to be transferred to a specific account [7]. And the FBI's 2024 announcement named the UAE among the countries where international banks were used as intermediate stops for stolen funds [5].

How the fraud actually works

The most effective versions do not rely on a fake email arriving out of nowhere; they rely on the fraudster reading real conversations and striking at exactly the right moment.

A typical sequence:

1. Getting in. The fraudster gains access to a mailbox, at the supplier or at your business, usually through a phishing email that collects a password. The UAE Cyber Security Council said in April 2026 that more than 75 per cent of cyber breaches begin with phishing emails or fraudulent messages [8]. Alternatively, they register a domain that looks almost identical to the real one.

2. Watching. They read the email quietly, sometimes for weeks. They learn who pays whom, how invoices are sent, what the people sound like and when payments are due. Some set up hidden forwarding rules so they keep receiving copies even after a password is changed.

3. Striking. When a real invoice is due, they send a message, often in the same thread, saying the bank details have changed. Because it concerns a real invoice, arrives at the right time and sounds like the right person, nothing feels wrong.

4. Moving the money. Once the payment lands, it is typically moved on quickly, often through several accounts and sometimes several countries.

The newer twist is that the fraud no longer has to be email. The FBI's 2025 report notes that businesses reported losses of over 30 million US dollars to business email compromise scams involving artificial intelligence, and that voice cloning can be used to request wire payments [4]. A phone call in a familiar voice is no longer proof of anything if you did not dial the number yourself.

A worked example

Here is how a typical case unfolds, step by step, and the single point at which it could have been stopped. The business and people are illustrative; the pattern is the one official warnings describe.

A Dubai trading company has bought packaging from the same supplier for three years. Invoices arrive monthly by email from the supplier's accounts manager, and the company pays by bank transfer at the end of each month.

In March, somebody at the supplier clicks a convincing link and enters their email password. Nobody notices. The fraudster now has quiet access to the accounts manager's mailbox and spends several weeks reading it: who the customers are, how invoices are worded, when payments are due, how the accounts manager signs off.

At the end of April, the genuine invoice goes out as usual. Two days later, a follow-up arrives in the same thread, from the same address, in the same style: the supplier has moved banks following an audit, please update the details before paying this month's invoice. A new IBAN is attached on a letterhead copied from a real one.

At the trading company, the accounts clerk sees nothing wrong. It is the right person, the right thread, the right amount, the right week. The clerk updates the details and the payment goes out.

The supplier chases payment three weeks later. By then the money has long gone.

Where it could have been stopped: at one point only, the moment the bank details changed. A call to the accounts manager on the number already held in the company's records would have taken two minutes and ended the fraud, because the real accounts manager knew nothing about a new bank.

Every other part of the story was out of the trading company's control. The supplier's mailbox was compromised. The email was genuinely from their address. The timing was perfect. That is the point: you cannot rely on spotting a fake, because the best ones are not fake in any way you can see. You can only rely on the callback.

The warning signs

Official warnings repeatedly name the same four signs: new bank details, urgency, secrecy, and a request to skip the normal process.

Europol lists pressure and a sense of urgency, requests for absolute confidentiality, and unusual requests that contradict internal procedures [3]. It describes typical language such as "confidentiality", "the company trusts you" and "I am currently unavailable" [3].

Abu Dhabi Police's Aman service says scams share urgency, a request for sensitive data and an offer that seems illogically attractive [7].

The UK fraud reporting service highlights fraudulent emails providing altered bank account details to redirect payments intended for legitimate transactions [9].

The combination that should always trigger a check:

Any change to bank details, however ordinary the explanation.

Any payment request marked urgent or confidential, especially from somebody senior.

Any request to skip or shorten the usual approval, for whatever reason.

Any message from a sender address you have not read in full, particularly on a phone, where the full address is often hidden. The FBI advises verifying the email address used to send messages, especially on mobile devices, and watching for links with misspellings of the real domain [5].

None of these proves fraud. Each is a reason to pick up the phone before any money moves.

The one control that stops most of it

Call the supplier back on a phone number you already had before the request arrived, speak to somebody you know, and confirm the change before paying. The FBI, CISA, the UK NCSC and the UK fraud reporting service all recommend this in some form.

The FBI advises using secondary channels or two-factor authentication to verify requests for changes in account information [10]. The UK fraud reporting service says to contact the supplier directly using their official and verifiable contact details to confirm any request to move money into a new account [2]. The UK National Cyber Security Centre recommends verifying all important email requests through a second type of communication, such as a phone call [11].

The US Cybersecurity and Infrastructure Security Agency adds the detail that makes it work: the phone number should not come from the email itself, but from a known contact list for that supplier. It suggests keeping that list in non-electronic form [12].

Why the detail matters. If the email is fraudulent, then everything in it is controlled by the fraudster: the reply address, the phone number in the signature, the number on the new invoice. Call any of those and the fraudster answers and confirms. Verification only works through a channel the fraudster cannot reach, which means contact details you held before the request arrived.

A printed list of supplier contacts, with the names and numbers of the people authorised to confirm payment changes, is the simplest tool in this whole article. An attacker in your email cannot edit a piece of paper.

Turning the habit into a process

A callback that depends on one careful person remembering is a habit; a callback built into who can change bank details, and how, is a control.

Limit who can change bank details. The UK fraud reporting service recommends that only designated employees should be able to make changes to payment arrangements [2].

Use two people. It also recommends a verification process involving multiple individuals before executing any fund transfer or sensitive transaction [9]. In practice: one person records the change with evidence of the callback, a second person approves it, and the system logs both, along with the old and new details.

Use a test payment for large first-time transfers. The UK fraud reporting service suggests sending a small amount first and confirming it has been received before sending the full amount [2]. This does not replace the callback, since a fraudster will confirm receipt too if you call the wrong number, but with a callback to a known contact it adds a second check.

Apply the rule to everybody, including the owner. The CEO version of the fraud relies on staff feeling unable to question a senior request. Europol's advice to employees is to apply payment security procedures strictly, not skip any steps and not give in to pressure [3]. That only works if the owner has said, in advance and in writing, that nobody is exempt. A genuine urgent payment survives a two-minute phone call. A fraudulent one does not, which is exactly why fraudsters ask for speed and secrecy.

Use your software's controls. Many accounting and procurement systems can restrict who edits supplier bank details, require a second approval, keep a log of changes, and flag payments to details that changed recently. Those controls only work if they are switched on and nobody shares logins. Our guide on procurement software covers building this into a supplier approval workflow.

Treat new suppliers the same way. Onboarding is a common entry point, because nothing looks unusual yet. Collect bank details through the same verified process as changes, confirm them by phone with a contact you have verified independently, and record who confirmed them and when.

When finance is one person

A two-person rule still works in a small business; the second person is usually the owner, and the bank can enforce it for you.

Many small businesses have a single bookkeeper or accountant, and the advice to "use two people" can feel impossible. It is not, because the second person does not need to be in finance. They need to be somebody other than the person entering the change.

The owner as approver. The simplest arrangement is that the bookkeeper records any bank detail change, with a note of the callback, and the owner approves it before the next payment run. It takes a minute and it means one person being fooled is not enough.

Use your bank's controls. Many business banking platforms allow a payment or a new beneficiary to require approval by a second user before it is released. If your bank offers it, switch it on. It enforces the two-person rule even when nobody remembers to.

Separate adding a beneficiary from paying one. Where possible, set things up so that adding or editing a beneficiary and releasing a payment to it are separate steps, ideally done by different people or on different days. Fraud depends on speed, and a pause between the change and the payment is a cheap defence.

If you genuinely work alone, the rule becomes a pause instead of a second person: never pay changed bank details on the same day you receive them, and always call first. A night's delay and a phone call are enough to stop most of these frauds.

Put the rule in your contracts

Agree in writing, with each regular supplier, how bank detail changes will be communicated and verified.

At minimum, the agreement should say that bank details will never be changed by email alone, how a change will be communicated, and how it will be verified, for example by a callback to a named contact. Some businesses also require a change to arrive on signed letterhead in addition to the call.

This does three useful things. Both sides know the rule. A request that ignores it is immediately suspicious. And if a dispute ever arises about who should bear a loss, there is a written process to point to.

On liability generally: when a fraud starts in one party's compromised mailbox and the loss falls on the other, the question of who pays can become a dispute. We cannot give a general answer, because it depends on the facts and the contracts, and it is a question for a lawyer. The practical protection is agreeing the process before anything goes wrong.

Protecting your customers from fraud in your name

Fraudsters who get into your email will target your customers too, by sending them fake invoices with your bank details changed. You can make that much harder.

Tell customers, in advance and repeatedly, that your bank details will not change by email. The UK NCSC suggests telling customers that your bank details will not change at any point [11]. Put it on every invoice and in your email footer. Then, if a fraudster ever writes to your customers pretending to be you, they already know to phone you first.

Make your domain harder to impersonate. The NCSC recommends the email authentication controls known as SPF, DKIM and DMARC to make it harder for email from your domains to be spoofed [11]. Our guide on email authentication explains what each does and how to set them up.

Secure the mailboxes themselves. Turn on multi-factor authentication for every mailbox, starting with finance and management. The UK fraud reporting service recommends two-factor authentication on email accounts and financial systems [9], and the UAE Cyber Security Council has advised enabling multi-factor authentication when warning about phishing [8].

Check for forwarding rules. Periodically review mailboxes, especially finance mailboxes, for forwarding rules and filters nobody created. Attackers use them to keep reading after a password is changed.

Reduce what fraudsters can learn. The UK fraud reporting service notes that criminals use social media to research staff and decision-makers [9]. Knowing who approves payments and who is travelling this week helps a fraudster time and word a request. That does not mean hiding your team. It means thinking about what your public profiles reveal about how payments work.

Instant payments and the speed problem

Instant payments are convenient for business and unforgiving of mistakes, because there is very little time to catch a wrong payment before it lands.

Aani, the UAE's instant payments platform, was launched in 2023 by Al Etihad Payments, a subsidiary of the Central Bank of the UAE, allowing payments to be processed instantly around the clock [13]. The operator states that payments take less than ten seconds, with a maximum of AED 50,000 per transaction, and that Aani is for domestic transfers [14].

The operator's own guidance reminds users to make sure they are initiating payments to the right beneficiaries, and to report immediately to their bank if they believe a payment was made without authorisation [15].

Two things we could not confirm, and so will not claim: we found no official source saying Aani shows the recipient's name before you confirm a payment, and no official source describing whether an Aani payment can be recalled. Some countries run account-name checks on payments; the UK, for example, has a service called Confirmation of Payee [16]. Do not assume an equivalent protects you here. Ask your bank what checks it applies.

The practical conclusion is simple. The faster the payment, the more the verification has to happen before you press send, because there may be no opportunity afterwards.

If you have already paid: the first hour

Call your bank's fraud line immediately and ask it to stop or recall the payment; everything else comes second. The FBI states that time is of the essence and advises contacting your financial institution immediately to request a recall of the funds [4]. The UK NCSC advises contacting your bank directly using its official website or phone number [17].

In order:

1. Call your bank. Use the number on its official website or your card, not any number in the fraudulent email. Explain that you have been the victim of payment fraud, give the payment details, and ask for the payment to be stopped or recalled. Ask what else they need from you.

2. Report to the police. The UAE government portal lists the Ministry of Interior's eCrimes platform, the Dubai Police eCrime service, the Abu Dhabi Police Aman service, and the Federal Public Prosecution's My Safe Society app, along with local police stations and 999 [18]. Dubai Police's eCrime service lists the business sector among its users, is free, and has a 901 call centre, for incidents within Dubai [19]. Abu Dhabi's Aman service lists 8002626 and SMS 2828 [7]. The Central Bank of the UAE also advises reporting fraud to your local law enforcement authority [20].

3. Preserve the evidence. Keep the emails, including full headers if your IT support can export them, the invoices and the payment records. Do not edit or delete anything.

4. Check your own mailbox. If the fraud came through your email or used information only your email held, assume your mailbox may be compromised. Change the password, turn on multi-factor authentication, sign out all sessions and check for forwarding rules. Our guide on what to do if you have been hacked covers this in more detail.

5. Warn the real supplier by phone. Their email may be compromised, in which case other customers are at risk too.

6. Notify your insurer, if you have a policy that might cover it.

How much difference speed makes: the FBI reports that in 2025, through its fast-track process for US-reported cases, it froze about 679 million US dollars of 1.16 billion dollars in attempted theft, a 58 per cent success rate [4]. That is a US process and not a UAE recovery rate, but it shows that fast action can work. The money is moved on quickly, and every hour reduces the chance.

Will you get the money back?

Sometimes, if you act very quickly, but you should not assume it.

We did not find an official UAE source describing a recall process for domestic bank transfers or instant payments, or setting out recovery rates. SWIFT offers banks a stop and recall service for international payments still in flight [21], which is one reason speed matters for international transfers too.

On refunds: do not assume your bank will reimburse you. A payment you authorised, even one you were tricked into making, may be treated differently from a payment somebody made without your permission. Ask your bank whether any reimbursement rules cover business accounts, and do not assume they do.

Beware the second fraud. People who have just lost money are targeted again, by callers claiming they can recover it for a fee or in exchange for details. The UK fraud reporting service warns to hang up on anybody who claims they can get your money back [2]. Deal only with your bank and the police, using contact details you find yourself.

After an incident: fix the route in

Once the immediate response is done, find out exactly how the fraud got in and close that route.

Was a mailbox compromised, and whose? Was a lookalike domain used? Was the callback skipped, or made to a number from the email? Was the second approval rubber-stamped?

Each answer points to a specific control to tighten. Then brief everybody who handles payments on what happened, without naming or blaming the person who made the payment. People who fear punishment delay reporting, and delay is what turns a recoverable loss into a permanent one.

Europol advises contacting the police about fraud attempts even when no money was lost [3]. Reporting near misses helps authorities build a picture and warn others.

Training the people who pay

Train everybody who can pay, approve payments or change payment details, and train them on your process, not just on spotting suspicious emails.

That means finance and accounts payable, payroll, executive assistants, and senior managers. The UK NCSC recommends making sure staff are familiar with the normal ways of working for key tasks, such as how payments are made [11]. When everybody knows the normal process, anything different stands out.

The single sentence worth everybody remembering: never act on changed bank details, or an urgent payment request, without first calling a number you already had.

Our guide on phishing awareness training covers building this into a wider programme, and our guide on cybersecurity for small businesses covers the surrounding baseline.

What it costs to put controls in place

A review of your payment verification process, covering who can change bank details, how changes are verified and how your systems enforce it, starts from around AED 2,500 with us. Setting up email authentication with SPF, DKIM and DMARC starts from around AED 1,500. An awareness programme for a small team starts from around AED 3,000 a year. No official body publishes rates for this work, so these are our own figures. Final pricing depends on scope.

Or start this week, for nothing:

  1. Write down the callback rule and give it to everybody who can pay or change payment details.
  2. Require a second approver for any bank detail change.
  3. Print a contact list for your main suppliers, with the names of the people who can confirm payment changes.
  4. Add a line to your invoices telling customers your bank details will not change by email.
  5. Turn on multi-factor authentication for every finance and management mailbox.

That is an afternoon of work, and it closes the route through which some of the most expensive fraud in the world is committed.

References

  1. FBI Internet Crime Complaint Center, 2025 Internet Crime Report, Appendix B
  2. UK Report Fraud, mandate fraud
  3. Europol, CEO/BEC fraud
  4. FBI Internet Crime Complaint Center, 2025 Internet Crime Report
  5. FBI Internet Crime Complaint Center, Business Email Compromise: The $55 Billion Scam
  6. Dubai Government Media Office, Dubai Police operation Fox Hunt 2
  7. Abu Dhabi Police, Aman service, latest scams
  8. WAM, UAE Cyber Security Council: 75% of cyberattacks start with phishing
  9. UK Report Fraud, payment diversion fraud
  10. FBI Internet Crime Complaint Center, business email compromise
  11. UK National Cyber Security Centre, phishing attacks: defending your organisation
  12. CISA, business email compromise continues to swindle and defraud US businesses
  13. Central Bank of the UAE, Al Etihad Payments launches Aani
  14. Al Etihad Payments, about Aani
  15. Al Etihad Payments, Aani help
  16. Pay.UK, Confirmation of Payee
  17. UK National Cyber Security Centre, business payment fraud
  18. The Official Portal of the UAE Government, cyber safety and digital security
  19. Dubai Police, eCrime service
  20. Central Bank of the UAE, fraudulent reporting
  21. Swift, Swift GPI
  22. SKIMBOX, procurement software in the UAE
  23. SKIMBOX, email deliverability, SPF, DKIM and DMARC
  24. SKIMBOX, security awareness training and phishing

This article summarises published guidance from government and law enforcement bodies and is not legal or financial advice. Loss figures are from US reporting and are not UAE statistics. Ask your bank what verification and recall options apply to your account.

Frequently asked questions

  • What is payment redirection fraud?

    A fraud in which a criminal persuades a business to send a genuine payment to the wrong bank account, usually by pretending to be a supplier who has changed banks or a senior manager who needs an urgent transfer. It is also called business email compromise, mandate fraud or payment diversion fraud. The UK's national fraud reporting service describes it as affecting businesses where electronic financial transactions take place, often through a request to change bank account details.

  • How big a problem is it?

    Large. The FBI's Internet Crime Complaint Center recorded 24,768 business email compromise complaints in 2025 with reported losses of about 3.05 billion US dollars, making it the second most costly type of cyber-enabled fraud in that report, after investment fraud. An FBI alert covering October 2013 to December 2023 put total exposed losses worldwide at about 55.5 billion US dollars. These are US figures; we did not find official UAE loss statistics for this fraud.

  • Does this happen in the UAE?

    Yes. In 2020 Dubai Police announced the arrest of a gang, in an operation called Fox Hunt 2, whose methods included hacking corporate emails to deceive clients into transferring money to the gang's accounts. Abu Dhabi Police's Aman service lists company email fraud among its current scam warnings. An FBI alert also named the UAE among the countries where banks were used as intermediate stops for stolen funds.

  • How do the fraudsters know when to strike?

    Often because they have been reading the emails. A common pattern is that an attacker gets into a mailbox at the supplier or the customer, watches the conversation quietly, and waits until an invoice is due. Then they send a message in the same thread, in the same tone, saying the bank details have changed. Because it arrives at exactly the right time about a real invoice, it does not feel suspicious.

  • What are the warning signs?

    New bank details, urgency, secrecy and a request to skip the normal process. Europol lists pressure and a sense of urgency, requests for absolute confidentiality, and unusual requests that contradict internal procedures. Abu Dhabi Police's Aman service says scams share urgency, a request for sensitive data and an offer that seems too good. Any one of these alongside a payment request deserves a phone call before any money moves.

  • What is the single most effective control?

    Call the supplier back on a phone number you already had before the request arrived, and confirm the change with somebody you know. The FBI, the UK NCSC and the UK fraud reporting service all recommend verifying changes through a second channel. The US Cybersecurity and Infrastructure Security Agency adds that the number must come from a known contact list, not from the email, and suggests keeping that list in non-electronic form so an attacker cannot alter it.

  • Why not just reply to the email to check?

    Because if the email account is compromised or the address is a lookalike, your reply goes straight to the fraudster, who will happily confirm the new details. The same applies to a phone number printed in the email, on the new invoice, or in the signature, all of which the fraudster controls. Verification only works through a channel the fraudster cannot reach, which means contact details you held before the request arrived.

  • Who should be allowed to change a supplier's bank details?

    Only a small number of named people. The UK fraud reporting service recommends that only designated employees can change payment arrangements, and that a process involving multiple individuals is used before executing transfers. In practice that means one person records the change with evidence of the callback, a second person approves it, and the system keeps a record of both, along with the old and new details.

  • What is a test payment and when should we use one?

    A small amount sent to a new account first, with the recipient confirming by phone that it arrived before the full amount follows. The UK fraud reporting service recommends it when sending large sums. It is not a substitute for the callback, because a fraudster can confirm receipt too if you call the wrong number, but combined with a callback to a known contact it adds a useful second check for large first payments.

  • Can this happen with a request from our own boss?

    Yes, and it is one of the most common forms. Europol describes CEO fraud as an employee authorised to make payments being tricked into paying a fake invoice or making an unauthorised transfer, usually with a request not to follow normal authorisation procedures and language about confidentiality and trust. The defence is a rule that nobody is exempt from the payment process, including the owner, so staff never have to choose between obeying and checking.

  • What should staff do if the boss really is in a hurry?

    Follow the process anyway, and make sure the boss has said in advance that this is what they want. Europol's advice to employees is to apply payment security procedures strictly, not skip any steps and not give in to pressure. A genuine urgent payment survives a two-minute phone call. A fraudulent one does not, which is exactly why fraudsters ask for secrecy and speed. The owner should say this in writing in advance, so nobody ever has to choose between obeying and checking.

  • Can fraudsters really fake a voice or video call?

    The FBI's 2025 report notes that businesses reported losses of over 30 million US dollars to business email compromise scams involving artificial intelligence, and that voice cloning can be used to request wire payments. That is why the callback must go to a number you already hold, which you dial yourself. A call you receive from an unknown number, even in a familiar voice, is not verification.

  • How do we protect our customers from fraud in our name?

    Tell them in advance, clearly and repeatedly, that your bank details will not change by email. The UK National Cyber Security Centre suggests telling customers that your bank details will not change at any point. Put it on invoices and in your email footer. Then, if a fraudster ever writes to your customers pretending to be you, they already know to phone you before paying.

  • What can we do about our own email security?

    Three things. Turn on multi-factor authentication for every mailbox, especially finance and management. Set up the email authentication records known as SPF, DKIM and DMARC, which the UK NCSC recommends to make it harder for criminals to send email that appears to come from your domain. And check mailboxes periodically for forwarding rules nobody set up, which attackers use to keep reading after a password changes.

  • What is a lookalike domain?

    An email address that looks like the real one at a glance but differs by a letter or two, such as a swapped character or an extra word. The FBI advises verifying the email address used to send messages, especially on a phone where the full address is often hidden, and being alert to links with misspellings of the real domain. Train finance staff to expand and read the full sender address on any payment request.

  • Do instant payments like Aani make this worse?

    They make speed work in both directions. Aani, the UAE instant payments platform launched by Al Etihad Payments in 2023, processes payments in under ten seconds, with a per-transaction limit of AED 50,000 according to the operator. The operator reminds users to make sure they are paying the right beneficiaries and to report unauthorised payments immediately. Fast payments are convenient, and they also leave very little time to catch a mistake.

  • Can a payment be stopped or recalled once it has been sent?

    Sometimes, if you act very fast, but you cannot count on it. The FBI says time is of the essence and advises contacting your bank immediately to request a recall. SWIFT offers banks a service to stop payments still in flight. We did not find an official UAE source describing a recall process for domestic transfers or Aani payments, so ask your bank directly and assume that every minute of delay reduces the chance.

  • What should we do in the first hour if we have already paid?

    Call your bank's fraud line immediately, using the number on its official website or card, and ask it to stop or recall the payment. Then report the fraud to the police. Preserve the emails, invoices and payment records without editing them. Check whether your own mailbox was compromised. Warn the genuine supplier by phone. The FBI, the UK NCSC and the Aani operator all stress speed, because the money is moved on quickly.

  • Where do we report this in the UAE?

    The UAE government portal lists the Ministry of Interior's eCrimes platform, the Dubai Police eCrime service, the Abu Dhabi Police Aman service and the Federal Public Prosecution's My Safe Society app, as well as local police stations and 999. Dubai Police's eCrime service lists businesses among its users and a 901 call centre. Abu Dhabi's Aman service lists 8002626 and SMS 2828. The Central Bank also advises reporting fraud to local police.

  • Will our bank refund the money?

    Do not assume it will. A payment you authorised, even one you were tricked into making, may be treated differently from a payment made without your permission. Ask your bank whether any reimbursement rules cover business accounts, and do not assume they do. Recovery depends mainly on how quickly the receiving bank can freeze the funds, which is why the first call matters so much.

  • What is a recovery scam?

    A second fraud aimed at people who have just lost money. Somebody contacts you claiming they can get the money back, for a fee or in exchange for your details. The UK fraud reporting service specifically warns to hang up on anybody who claims they can recover your money. Deal only with your bank and the police, using contact details you find yourself rather than any that are offered to you.

  • Who is liable, us or the supplier?

    It depends on the facts and on your contracts, and it can become a dispute. If the fraud started in the supplier's compromised mailbox, they may argue you should have checked; you may argue they should have secured their email. We cannot give a general answer, and it is a question for a lawyer. The practical protection is agreeing in writing, in advance, how bank detail changes will be communicated and verified.

  • What should our supplier contracts say?

    At minimum, that bank details will never be changed by email alone, how a change will be communicated, and how you will verify it, such as a callback to a named contact. Some businesses also require changes to arrive on signed letterhead in addition to the callback. Having the process in the contract means both sides know the rule, and a request that ignores it is immediately suspicious.

  • How should we collect bank details from a new supplier?

    Through the same verified process as changes. Collect the details as part of onboarding, confirm them by phone with a contact you have met or verified independently, and record who confirmed them and when. New supplier onboarding is a common entry point for fraud because nothing looks unusual yet. Our guide on procurement software covers building this into a supplier approval workflow. Use the same two-person approval for a new supplier as for a change.

  • Who in the business should be trained?

    Everybody who can pay, approve payments or change payment details: finance, accounts payable, payroll, executive assistants and senior managers. Staff should know the normal way payments are made, so anything different stands out. The UK NCSC recommends making sure staff are familiar with normal ways of working for key tasks such as payments. Our guide on phishing awareness training covers building this into a wider programme.

  • Should we punish staff who fall for it?

    No. People who fear punishment delay reporting, and delay is what turns a recoverable loss into a permanent one. The fraud is designed by professionals to be convincing. Make it clear that reporting a mistake quickly is what you want, and treat the incident as a process failure to fix rather than a personal failure to punish. The goal is a process in which a single person's mistake cannot move money on its own.

  • Does accounting software help prevent this?

    It can, if it is set up to. Good systems let you restrict who can edit supplier bank details, require a second approval for changes, keep a log of old and new values, and flag payments to details that changed recently. Those controls only work if they are switched on and nobody shares logins. Check what your current system already offers before buying anything new.

  • Is a changed bank account always fraud?

    No. Businesses do genuinely change banks, merge accounts or open new ones. That is precisely why the fraud works: the request is plausible. The point of the callback is not to refuse changes, but to confirm them with somebody you know through a channel the fraudster cannot control. A genuine supplier will understand, and many will be relieved that you checked. Treat the call as routine, not as an accusation, and it rarely causes friction.

  • What if the supplier gets annoyed by the callback?

    Explain that you verify every bank detail change by phone for everybody's protection, including theirs, since a fraudster intercepting their invoices would cost them money too. Most businesses that have been targeted, or know somebody who has, welcome the check. A supplier who resists a two-minute verification call about a change to where your money goes is itself a reason to slow down. Putting the rule in your contract means the conversation never needs to happen at all.

  • Does this affect payroll too?

    Yes. A variation of the same fraud targets payroll, with an email appearing to come from an employee asking to change the account their salary is paid into. The defence is the same: verify any change in person or through a channel you already hold, never through the email that requested it. Apply the same two-person rule to payroll changes as to supplier changes. An employee who genuinely changes banks will not mind confirming it in person.

  • What should we do after an incident?

    Once the immediate response is done, find out how the fraud got in and fix that route. Was a mailbox compromised, was a lookalike domain used, was the callback skipped or done to the wrong number? Tighten the specific control that failed and brief everybody who handles payments. Europol advises contacting the police about fraud attempts even when no money was lost, which helps build the picture for everybody.

  • Is insurance available for this?

    Some cyber and crime insurance policies cover losses from social engineering or funds transfer fraud, often with specific conditions such as requiring a callback procedure. Cover varies widely, so read the policy wording or ask your broker exactly what is covered and what conditions apply. Do not assume a general cyber policy includes it, and check before a loss rather than after. If a policy requires a callback procedure, make sure yours is written down and followed, because that condition may decide whether a claim is paid.

  • What does it cost to put these controls in place?

    A review of your payment verification process, covering who can change bank details, how changes are verified, and how your systems enforce it, starts from around AED 2,500 with us. Setting up email authentication with SPF, DKIM and DMARC starts from around AED 1,500. An awareness programme for a small team starts from around AED 3,000 a year. Final pricing depends on scope, and these are our own figures.

  • How do we use a two-person rule if only one person handles finance?

    Make the owner or another manager the second approver, since the second person does not need to be in finance, only somebody other than the person entering the change. Many business banking platforms can also require a second user to approve new beneficiaries or payments, which enforces the rule automatically. If you work entirely alone, use a pause instead: never pay changed details on the day you receive them, and always call first.

  • What should we do this week?

    Write down the callback rule and give it to everybody who can pay or change payment details: any new or changed bank details are verified by phone to a number already on file, and a second person approves. Then print a contact list for your main suppliers and add a line to your invoices telling customers your bank details will not change by email. That is an afternoon of work.

  • Is there one sentence staff should remember?

    Never act on changed bank details, or an urgent payment request, without first calling a number you already had. Everything else in this guide supports that one habit. It costs a two-minute phone call, it works against email compromise, lookalike domains and cloned voices alike, and it is the control the FBI, CISA and the UK authorities all recommend in some form. Put it on the wall next to whoever makes payments, and repeat it whenever anybody new joins the team.

SKIMBOX Team

Tech Consultancy

Get fresh writing in your inbox

One email a fortnight. No filler.

By subscribing, you agree to our privacy policy.

Want us to build something?

We work with teams across MENA, UK, USA, and India to build products, run programs, and grow.

Get in touch

Continue reading