business
Vendor bank-detail change fraud
A supplier emails new payment details a week before a large invoice is due. The email looks perfect. The account is six days old.
How it works
- 01An attacker compromises or spoofs a supplier's mailbox, often via a lookalike domain one character off the real one.
- 02They wait — sometimes weeks — reading the thread until a genuine invoice is in flight.
- 03They reply in-thread with updated bank details and a plausible reason (audit, new treasury provider).
- 04Finance pays the real invoice to the wrong account. Recovery windows are measured in hours.
How to spot it
- Any change to payment details, ever, is a stop-and-verify event — no exceptions for urgency.
- Check the reply-to domain character by character, not the display name.
- Call the supplier on the number you already had, never one in the email.
- Beneficiary name mismatch against the account name is the strongest single signal.
How the fleet stops it
Plutus
Plutus watches invoice and payment flows for changed beneficiaries, brand-new accounts, and name mismatches, while Psycher checks the message itself for spoofed domains and social-engineering patterns. A suspect payment is held for your approval — the fleet never moves money.