BankChangeGuard
← All posts

7 Red Flags in a Vendor Bank-Change Request

Most vendor-payment fraud does not look like fraud. It looks like a normal email from a vendor you know, asking to update their bank details. Looking routine is the attacker's whole game. Here are seven signals that a bank-change request deserves a second look, and the one move that neutralizes all of them. This is informational, not legal or financial advice.

1. The request comes by email only

A bank change that arrives purely by email, with no prior phone conversation, is the most common pattern there is. Email is the easiest channel to spoof, or to send from a mailbox that has been quietly compromised.

2. There is urgency or pressure

"We need this before the next run," "the payment is already late," "please rush this." Urgency exists to push you past your normal checks. A real vendor rarely minds a one-day verification.

3. The address or domain is slightly off

A look-alike domain (vendorname-billing.com instead of vendorname.com), a reply-to that differs from the from address, or a free email account for a business that has always used its own domain. Small mismatches are a big tell.

4. The new account does not fit the vendor

A long-time vendor suddenly routing to a personal-style account, an out-of-state bank, or a prepaid or fintech account that does not match their size or location. That is worth a question.

5. A dormant thread revives, and it is about money

A quiet email thread that comes back to life specifically to change payment details. Attackers often sit in a mailbox and wait for, or start, exactly this kind of conversation.

6. They discourage you from calling

Any pushback on verifying by phone ("I am traveling, just email me," "no need to call, the details are below") is a red flag on its own. A real vendor welcomes the check.

7. The change lands right before a large payment

Timing that lines up with a big invoice or a scheduled payment run is not a coincidence you want to ignore. The bigger the payment, the more the change deserves scrutiny.

The one move that catches all seven

You do not have to memorize this list. One habit neutralizes every item on it: when a vendor asks to change bank details, call a phone number you already had on file (from a past invoice or a signed contract, never the number in the request), confirm the change is genuine, and record who you spoke to and when. That out-of-band callback turns all seven red flags into a five-minute confirmation. The step-by-step version is in the vendor bank-change verification SOP.

Make the record automatic

The callback is the control; the record is what you can actually show later if a payment is ever questioned. That second part is what I built BankChangeGuard to handle for QuickBooks Online firms: you log the change, it emails a one-time code to the contact you already had on file, and you get a tamper-evident PDF for the client file. It does not move money, approve payments, or make anyone "Nacha-compliant," it just makes the verification trail automatic instead of a memo nobody can defend. It is free to connect QuickBooks and try.