Supplier "updated bank details" (invoice redirect)
For businesses: an email from a known supplier — or from a look-alike address — announcing new bank details for the next payment. The next invoice is paid to the criminals. FBI IC3 tracks this as business email compromise, the costliest category it records.
- Impersonates
- a supplier or executive of your own company
- Arrives by
- First seen
- not dated
- Specimens
- 0
- Updated
- 2026-09-02
Right now what this family looks like
How to recognise it
- Bank-detail changes by email, often just before a large payment
- A look-alike domain, one letter off
- Pressure to skip the usual verification
What to do
- Verify any bank change by phone on a number you already had, never from the email
- Check the sender domain character by character
Already called, clicked or paid? what to do in the next hour
- Call your bank immediately and ask for a recall; speed matters in the first hours
- Report to IC3 with the payment details
Report:FBI IC3Send us your version
How it changed
nothing to compare yet · no specimen on recordGot a version? A new subject line, sender, number or domain becomes the next point on this line. Redacted before publication. Send it →
02 Sept2026
Registry
Family created
Opened at launch; no dated specimen on record yet — send yours.
Same trick, other brands
- DocuSign "document to review and sign" phishingactive · 2026-09
Indicators
- None on record yet. Indicators change weekly; an empty list never means an email is safe.
In other streams
- Nothing yet.
Registry data
- Machine-readable
/scams/bec-supplier-bank-change.json- Timeline feed
/scams/bec-supplier-bank-change/feed.xml- Sources
- 1 · 1 change logged
- Licence
- CC BY 4.0 · attribution required
- Created / updated
- 2026-09-02 / 2026-09-02