Cybersecurity / Foxbyte Insights

A payment-change email arrives: what should your team do?

Foxbyte InsightsPublished Updated

Cybersecurity connects access, protection and recovery with business ownership.

Treat an unexpected payment-detail change as a separate verification task. A familiar display name, convincing thread or successful email-authentication result does not establish that the instruction is authorised.

Pause the payment change

Suppose a message says a supplier has changed its bank account and asks you to pay urgently. Do not use the message itself as the authority for updating the supplier record. Keep the request pending while the organisation’s approved verification and financial approval process runs.

The same principle applies when a senior colleague appears to request an unusual transfer. Urgency, secrecy or pressure to bypass normal steps should make the independent check more important, not less.

Verify through a known route

Evidence offeredWhy a separate check is needed
Familiar display nameThe visible name alone does not establish the sender’s authority.
Existing email threadAn account or conversation may be compromised or imitated.
New phone number in the messageIt may be controlled by the person making the suspicious request.
Attached bank letterA document can still require independent validation.
Email filter allowed itTechnical filtering is not financial approval.

Use a contact route already established in your organisation’s records, following the approved verification procedure. Do not rely on contact details supplied only in the change request.

Separate verification from approval

Record who confirmed the change, how it was verified and who has authority to approve the master-data update. A person who receives a message may not be authorised to alter payment details. The payment decision can require another review under the organisation’s policy.

For automated invoice processing, keep extracted bank details separate from the approved supplier record. A workflow can flag a difference and prepare review information; it should not treat a document field as permission to overwrite payment instructions.

Report without spreading the risk

Use the organisation’s agreed suspicious-message reporting route. Include the relevant message or reference through that approved mechanism rather than forwarding it widely with unnecessary attachments. If someone already acted, report the timing and actions promptly to the authorised finance and security contacts.

An active loss or compromise needs the organisation’s incident and financial escalation procedures and appropriate provider assistance. A public article cannot determine what occurred or replace those time-sensitive decisions.

Practise the decision with a fictional example

  • A supplier changes its payment details shortly before an invoice is due.
  • The usual contact is unavailable and the message gives a new number.
  • A manager asks the team to bypass the check because of urgency.
  • The finance system contains a different approved account.

Ask the team who can hold the request, which known contact route to use and where the decision is recorded. The aim is a repeatable process that staff can follow without being punished for a sensible pause.

Sources and further reading

Put the decision into practice

Review the email and account controls alongside the business verification process.

Explore Microsoft 365 & Email Security Discuss the requirement by email
Talk to Us

Talk to Us

AI-assisted · Human help available

How can we help?

I’m Foxbyte’s AI assistant. Ask about a service, or talk to a person.

Scroll to Top