Vendor Bank Change Scam: Verify Before You Pay
A practical callback and approval workflow for retail owners and managers facing new vendor bank details, altered invoices, or urgent payment changes.
A vendor bank change scam works by slipping new payment instructions into a relationship your store already trusts. Treat every bank-detail change as a new request: pause the payment, call a known vendor contact using a number already on file, document who confirmed it, and require a second approval before money moves.
Why a familiar invoice can be the dangerous one
This problem lands with owners and managers because the message usually looks routine. The supplier name is familiar. The amount may match a real order. The email can even appear inside an existing conversation. The only new detail is where the money should go.
Email continuity is not proof of identity. A criminal may use a look-alike address, spoof a display name, or gain access to a real mailbox. Once the payment leaves, the store still owes the legitimate supplier if the supplier never received it. The operational question is not whether an email looks polished. It is whether a payment change survived a verification process outside that email.
The FBI’s current business email compromise guidance, accessed September 24, 2026, tells businesses to verify changes in account numbers or payment procedures with the person making the request. It also warns against using contact information supplied inside the suspicious message. That guidance should become a store rule, not a judgment call reserved for unusually large invoices.
The vendor bank change scam rule: stop the payment
Any request to change an account number, routing number, payment portal, mailing address for checks, or usual payment method should move the invoice into a temporary hold. The person processing the invoice should not reply “confirmed” in the same email chain. A reply only proves that someone controls the channel being questioned.
Use a vendor phone number that was recorded before the change request. Good sources include the approved vendor record, an earlier signed agreement, or a number independently found on the vendor’s official site. Do not call a number printed only on the new invoice or included in the change email.
Ask the known contact to confirm the requested change and the last four digits of the new account. Avoid reading the full new account number first and asking for agreement; that turns the call into a yes-or-no exercise. If the contact cannot verify the change, keep the hold in place and escalate through the vendor’s established office.
Keep a short verification record
A callback that leaves no record becomes folklore by the next invoice. Add a change log to the vendor file with enough detail for another manager to understand what happened:
- Vendor name and vendor ID
- Date and time the change request arrived
- Old payment method and last four digits, when available
- New payment method and last four digits
- Name and role of the person who requested the change
- Trusted phone number used for the callback
- Name of the person who confirmed the change
- Employee who performed the callback
- Second approver and approval time
- Effective date for the new instructions
Do not attach passwords, security codes, or unnecessary bank information. The log exists to prove the control was followed, not to create another file full of sensitive data.
The FTC’s Cybersecurity for Small Business guidance, accessed September 24, 2026, recommends verification policies and gives a concrete example: employees should call to confirm wire-transfer requests received by email. A retailer can apply the same control to ACH instructions, mailed-check changes, and new payment portals.
Separate the request, approval, and release
A small store may not have an accounts-payable department, but it can still separate three actions. One person receives or enters the requested change. A second person reviews the callback record and invoice. The payment is released only after both steps are complete.
If only one owner can move money, add time instead of another person. Verify the change, save the record, and release the payment later from a fresh session after reviewing the purchase order, receipt, and invoice together. The delay breaks the urgency that scammers depend on and gives the vendor time to notice a compromised account.
Set the rule for all changes rather than only payments above a threshold. A criminal can send a smaller first invoice to test the process. You can still require extra approval for high-dollar transfers, but the callback should apply to every change in destination.
Managers also need authority to pause an invoice without being blamed for a late payment. Write the exception into the procedure: a payment held for bank-detail verification is not considered overdue internally while verification is pending. The owner decides how to communicate the delay to the vendor.
Match the invoice to what the store authorized
A real invoice can carry fraudulent payment instructions, so matching the amount alone is not enough. Compare the invoice with the approved purchase order and the merchandise actually received. Confirm the vendor, purchase-order number, quantities, prices, credits, payment terms, and payment destination as separate fields.
The earlier guide to the retail purchase order process explains why the order, receipt, and invoice should remain distinct records. Add bank-detail verification as a fourth checkpoint whenever the destination changes. Do not rewrite the original purchase order to make the new invoice appear consistent.
Duplicate invoices deserve their own exception. Search the invoice number, amount, date, and vendor before releasing payment. A changed invoice number does not make the charge new if it refers to the same shipment. When an invoice is corrected, preserve both versions and note why the replacement was accepted.
Train the person who can move money
A policy fails when staff think an owner’s urgent email can override it. Tell employees in advance that nobody, including the owner, may waive callback verification through email or text. An urgent request from a senior person is a reason to slow down, not a substitute for approval.
Run a ten-minute practice with one fake change request. The employee should identify the hold, find the trusted contact, describe the callback questions, record the result, and route the change for approval. Practice the ordinary-looking version, not an email filled with spelling errors. The test should feel like a normal Thursday invoice.
Give employees one sentence they can send without starting an argument: “Our payment policy requires us to verify any change through the vendor contact already on file before we release funds.” A legitimate supplier may be inconvenienced, but the rule protects both sides.
What to do when a suspicious payment was sent
Call the bank or payment provider immediately using a trusted number and ask what recovery or recall options are available. Speed matters, but recovery is not guaranteed. Do not wait for the vendor to finish an internal investigation before contacting the financial institution.
Preserve the original message, invoice, headers if available, callback notes, payment confirmation, account details, and timeline. Do not keep forwarding the suspicious email through the business, because that can spread malicious links or attachments. Secure any mailbox that may have been compromised, change affected credentials, and enable multi-factor authentication where available.
The FBI guidance directs victims to report business email compromise to the Internet Crime Complaint Center. Follow the reporting steps your bank, insurer, counsel, or law-enforcement contact gives you. Avoid promising employees that the money will be recovered or deciding responsibility before the records are reviewed.
Use systems for records, not identity proof
A POS or inventory system can connect a purchase order, receipt, supplier invoice, and stock history. It cannot prove that an emailed bank change came from the vendor. Keep the identity check outside the potentially compromised channel, then record the approved result in the vendor file.
VoVi keeps a ledger-backed inventory history with every stock change logged, flags low stock, and on Pro drafts purchase orders from what fell below its minimum. Those records can support invoice review, but the callback and payment approval still belong in the store’s financial controls. Software history is evidence of what staff entered, not proof that a bank account belongs to the supplier.
Review the process once a quarter. Pick one recent vendor change and trace the request, callback, approval, invoice match, and first payment. If any step lives only in somebody’s memory, fix the record before the next request arrives.
A payment-control policy earns its keep on the first ordinary-looking email that does not get through. Put the trusted contact on file now, give staff permission to pause, and make every change wait for a callback and a second set of eyes.
What else do people ask?
How should a retailer verify new vendor bank details?
Pause the payment and call a known vendor contact using a phone number that was on file before the request. Record who confirmed the change, then require a second approval.
Is replying to the vendor’s email enough verification?
No. The mailbox or email thread may be compromised. Verify through a separate, trusted channel and do not use a phone number supplied only in the change request.
Should small invoice changes require the same callback?
Yes. Apply the callback to every change in payment destination. Dollar thresholds can trigger extra approval, but a smaller payment can still test whether the store follows its controls.
What should a store do after sending a suspicious payment?
Contact the bank or payment provider immediately, preserve the messages and payment records, secure any affected accounts, and follow official reporting guidance. Recovery is not guaranteed.