ScamsImpersonationAnatomy of a scam: the "our bank details have changed" email, dissected line by line
High

Anatomy of a scam: the "our bank details have changed" email, dissected line by line

An email from a supplier you know says their bank account has changed — please send this month's payment to the new details. It is business email compromise, which the FBI ties to more than $55 billion in reported losses between 2013 and 2023. We take one apart line by line, and show the single rule that stops every version.

Sources checked:FBI IC3

This is the next in our series taking a single scam apart line by line. Our subject this time isn’t a flashy text on your lock screen — it’s a quiet, professional email to a company’s accounts team. It is business email compromise (BEC), and it is one of the most expensive scams in the world: the FBI’s Internet Crime Complaint Center (IC3) ties it to more than $55 billion in reported losses between 2013 and 2023. The whole con can fit in a five-line email that looks exactly like business as usual — which is precisely why it works.

Here’s a representative example. The company and supplier are invented; the structure mirrors what the FBI describes in real BEC cases.

From: Anna Reyes <a.reyes@northbridge-supply[.]com> Subject: RE: Invoice #4471 — March delivery

Hi, following up on invoice #4471. Quick note: our bank account has changed, so please send this month’s payment to the new account below rather than the usual one. Can you process it today before close? Trying to keep this tidy before quarter-end — happy to confirm anything you need by email.

Five short lines. Every one is doing a job. Let’s mark them.

The familiar sender — a real name, maybe a real account

The email appears to come from someone you know, at an address you recognize. That’s not a coincidence; it’s the foundation of the whole scam. The FBI explains that BEC is “frequently carried out when a subject compromises legitimate business email accounts through social engineering or computer intrusion,” then uses that access to “impersonate email communications between compromised businesses and third parties, such as vendors or customers.”

So the sender line can be genuinely real — a supplier’s actual mailbox, broken into and watched for weeks — or a look-alike domain a character or two off. Either way, the thing you’d normally use to confirm identity is the thing that’s been turned against you.

”RE: Invoice #4471” — they’ve read the thread

The reply references a real invoice and a real delivery, because the attacker has been reading the mailbox. They wait inside an existing conversation and pick the natural moment a payment is due. That context is what disarms you: this isn’t an out-of-the-blue request, it’s the next logical message in a thread you’ve been part of.

”our bank account has changed” — the entire payload

Strip everything else away and this is the scam: a request to send money you already owe to a different account. The FBI’s description is almost word for word — “a business with a long standing relationship with a supplier is requested to wire funds for invoice payment to an alternate, fraudulent account.” Sometimes it’s bigger than one invoice: the Bureau notes perpetrators who “changed the remittance location to redirect all incoming invoice payments.”

Nothing here is technically hostile. There’s no link to click, no attachment to open. The “attack” is a single sentence asking for an administrative change — which is exactly why filters don’t catch it.

”process it today before close” — urgency, timed on purpose

The deadline isn’t impatience; it’s engineering. The FBI notes victims are “pressured by the fraudster to act quickly or secretly,” with requests “often occurring at the end of the business day or work week” to coincide with banks closing — so the money is gone before anyone can second-guess it. “Before close,” “before quarter-end,” “the director needs this done today” all do the same work: shrink the window in which you might pick up the phone.

A close cousin appears in the deepfake video-call payment scam: the FBI has documented attackers who “compromise an employer’s email, such as the CEO, and send spoofed emails to employees instructing them to initiate transfers of funds, claiming the CEO is occupied in a virtual meeting and unable to initiate a transfer” themselves. Same lever, different costume.

”happy to confirm anything you need by email” — keeping you on one channel

This is the quiet masterstroke. By offering to “confirm by email,” the sender keeps the whole exchange on the channel they control. Any confirmation you ask for there will come back reassuringly — because you’re asking the scammer. The FBI’s guidance points the other way: be “alert to hyperlinks that may contain misspellings of the actual domain name,” and “use secondary channels or two-factor authentication to verify requests for changes in account information.”

That’s the exit, and it’s the same every time: a change to where money goes is confirmed on a different channel, never the one the request arrived on.

How to spot it

The tells are in the box below, but the machine underneath is constant: a trusted identity + a real, in-progress payment + a new destination + a reason to hurry. Swap the supplier for a “CEO”, the invoice for a payroll update, or the wire for a gift-card run, and it’s the same engine. Learn the engine and you stop needing to recognize each new paint job.

What to do instead

You don’t need any product to beat this — the free move comes first (see the defense box). The habit is Two-Channel Verification: when a request asks you to send money or change where it goes, confirm it on a second, independent channel — a phone call to a number you already had for that person, never one from the email. Make it a standing rule for your finance team so it doesn’t depend on anyone’s judgment in a busy moment. If money has already moved, act fast and see Freeze & Report. For the voice-and-video version of the same trick, read the deepfake payment scam; for more, see our defense moves and the 60-second quiz.

Warning signs
  • An email asks you to send a payment, or to change a supplier's or employee's bank details, to a new account.
  • It comes from a real, familiar address (compromised or a look-alike) and references a genuine invoice or ongoing deal.
  • It leans on urgency or secrecy — pay today, before close of business, keep it between us — and steers money to a new destination.
Defense move — Two-Channel Verification
  • Confirm any new or changed payment details by calling a number you already have for the company — never one from the email.
  • Treat a real, familiar sender address as no proof on its own: business email accounts get compromised and threads hijacked.
  • Make it a fixed rule: any change to where money goes gets an out-of-band call before payment, with no exception for urgency.
  • Watch for look-alike domains with subtle misspellings, and check the reply-to address really belongs to who it claims.
Editor's note

What unsettles me about BEC is how normal it looks. There’s no broken English, no prince, no scary link — just a polite email from a name you know, about an invoice that's real, asking for a small administrative change. It preys on competence: the more efficiently your finance team pays its bills, the more smoothly the redirected payment goes through. I’ve come to treat one specific event — a change to where money is sent — as a hard stop that always triggers a phone call, no matter how routine or how rushed it feels. That single reflex is what turns a six-figure mistake back into a thirty-second non-event.

Frequently asked

The email was part of a real thread from our supplier's actual address. How can it be fake?

This is exactly what a serious BEC attack looks like. The FBI describes criminals who "compromise legitimate business email accounts" and then "impersonate email communications between compromised businesses and third parties, such as vendors or customers, to request pending or future payments be redirected to fraudulent bank accounts." A genuine address and a real thread prove nothing once the account is in the attacker's hands — which is why the only reliable check is a call on a second channel you control.

How is this different from a normal phishing email with a bad link?

Most BEC has no link and no malware to catch — it is pure social engineering using a trusted identity to redirect a payment you were already going to make. There is nothing for a spam filter or antivirus to flag, because the email is just words asking for a routine business action. That is what makes it slip through, and why the defense has to be a human verification step rather than a technical filter.

We already wired the money to the new account. What now?

Act immediately — time is the biggest factor in recovery. Contact your bank or card issuer at once and ask them to recall the transfer, then report it to the FBI's IC3 at ic3.gov with the email, the account details, and the timeline. The faster you move, the better the chance the funds can be frozen before they are pulled out the other end.

RY
Ryon — Founder & Editor
Consumer-safety advocate · Scamblare

Scamblare researches scams every day so you don't have to. Every article is checked, claim by claim, against primary sources like the FTC and FBI IC3 under our published editorial standard. How we fact-check ›