Skip to main content
AAktoh Cyber
← Threat library

business

Vendor bank-detail change fraud

A supplier emails new payment details a week before a large invoice is due. The email looks perfect. The account is six days old.

How it works

  1. 01An attacker compromises or spoofs a supplier's mailbox, often via a lookalike domain one character off the real one.
  2. 02They wait — sometimes weeks — reading the thread until a genuine invoice is in flight.
  3. 03They reply in-thread with updated bank details and a plausible reason (audit, new treasury provider).
  4. 04Finance pays the real invoice to the wrong account. Recovery windows are measured in hours.

How to spot it

  • Any change to payment details, ever, is a stop-and-verify event — no exceptions for urgency.
  • Check the reply-to domain character by character, not the display name.
  • Call the supplier on the number you already had, never one in the email.
  • Beneficiary name mismatch against the account name is the strongest single signal.

How the fleet stops it

Plutus

Plutus watches invoice and payment flows for changed beneficiaries, brand-new accounts, and name mismatches, while Psycher checks the message itself for spoofed domains and social-engineering patterns. A suspect payment is held for your approval — the fleet never moves money.