Soft2Securescam registry · since 2014

Supplier "updated bank details" (invoice redirect)

For businesses: an email from a known supplier — or from a look-alike address — announcing new bank details for the next payment. The next invoice is paid to the criminals. FBI IC3 tracks this as business email compromise, the costliest category it records.

Impersonates
a supplier or executive of your own company
Arrives by
email
First seen
not dated
Specimens
0
Updated
2026-09-02

Right now what this family looks like

How to recognise it

  1. Bank-detail changes by email, often just before a large payment
  2. A look-alike domain, one letter off
  3. Pressure to skip the usual verification

What to do

  1. Verify any bank change by phone on a number you already had, never from the email
  2. Check the sender domain character by character
Already called, clicked or paid? what to do in the next hour
  1. Call your bank immediately and ask for a recall; speed matters in the first hours
  2. Report to IC3 with the payment details

How it changed

nothing to compare yet · no specimen on record
Got a version? A new subject line, sender, number or domain becomes the next point on this line. Redacted before publication. Send it →
02 Sept2026
Registry

Family created

Opened at launch; no dated specimen on record yet — send yours.

Same trick, other brands

Indicators

  • None on record yet. Indicators change weekly; an empty list never means an email is safe.

In other streams

  • Nothing yet.

Registry data

Machine-readable
/scams/bec-supplier-bank-change.json
Timeline feed
/scams/bec-supplier-bank-change/feed.xml
Sources
1 · 1 change logged
Licence
CC BY 4.0 · attribution required
Created / updated
2026-09-02 / 2026-09-02