← Real-world patterns

Real-world pattern · Invoice safety

The invoice looked familiar. The new bank account was the trap.

A documented business-email-compromise pattern: a convincing invoice or email changes bank details just before a payment is sent.

What happened

The FBI describes business email compromise schemes in which criminals compromise or spoof a business email account, then send payment instructions that appear to come from a known vendor or colleague. A common version asks the recipient to change an existing invoice, bank deposit, or contact detail before sending a wire transfer.

The payment decision point

A changed account number is not a routine administrative update until it is confirmed through a contact method you already trust. Do not reply to the suspicious email or call a number in the invoice to verify the change.

Signals to pause on

  • A last-minute request to change wire instructions or bank-account details.
  • A sender address, reply-to address, or wording that differs slightly from a known vendor.
  • Pressure to send the payment before a deadline or keep the change confidential.
  • An invoice asks you to verify payment details only through the same email thread.

What to do now

  1. Upload the invoice screenshot or paste the payment email into SignalCheck.
  2. Call the vendor or colleague using a saved number or independently verified contact route.
  3. Require a second approval for a new payee or changed bank details before releasing funds.
  4. If a transfer was sent, contact the originating bank immediately and preserve the invoice, emails, and payment details.

Have a similar request in front of you?

Check the link, message, or screenshot before sending money or personal information.

Check the evidence