Real-world pattern · Invoice safety
The invoice looked familiar. The new bank account was the trap.
A documented business-email-compromise pattern: a convincing invoice or email changes bank details just before a payment is sent.
What happened
The FBI describes business email compromise schemes in which criminals compromise or spoof a business email account, then send payment instructions that appear to come from a known vendor or colleague. A common version asks the recipient to change an existing invoice, bank deposit, or contact detail before sending a wire transfer.
The payment decision point
A changed account number is not a routine administrative update until it is confirmed through a contact method you already trust. Do not reply to the suspicious email or call a number in the invoice to verify the change.
Signals to pause on
- A last-minute request to change wire instructions or bank-account details.
- A sender address, reply-to address, or wording that differs slightly from a known vendor.
- Pressure to send the payment before a deadline or keep the change confidential.
- An invoice asks you to verify payment details only through the same email thread.
What to do now
- Upload the invoice screenshot or paste the payment email into SignalCheck.
- Call the vendor or colleague using a saved number or independently verified contact route.
- Require a second approval for a new payee or changed bank details before releasing funds.
- If a transfer was sent, contact the originating bank immediately and preserve the invoice, emails, and payment details.
Have a similar request in front of you?
Check the link, message, or screenshot before sending money or personal information.
Check the evidence