A direct answer from a Kansas City IT team

Should we trust emailed vendor bank changes?

Payment-detail changes are a common business email compromise tactic. Verify them outside email before sending money.

Never change ACH or wire instructions based only on email. Call a known contact using a previously verified number and require documented approval.

Why the email may look perfect

The attacker may have compromised the vendor’s mailbox or yours. They can study previous conversations, copy signatures, reply inside a real thread, and wait until an actual invoice is due.

Build a payment-change procedure

  1. Call a known vendor contact at a number already on file.
  2. Require approval from a second employee.
  3. Document the verification and the number called.
  4. For large changes, send a small test payment or use your bank’s verification controls.
  5. Treat pressure to bypass the process as a warning, not a reason to hurry.

If money was sent

Call your bank’s fraud department immediately and request a recall. Then preserve the email, notify both organizations’ IT teams, and report the incident. Minutes can matter.

This page provides general security guidance, not a guarantee that any individual message is safe. When money, passwords, remote access, or sensitive records are involved, verify through a separate trusted channel.