Payments

Invoice fraud and change-of-bank-details checklist for UK SMEs (2026)

A calm, practical checklist for UK owner-managers: how “new bank details” scams work, what to verify before you pay, and what software cannot replace.

Someone emails your accounts person. The message looks like a regular supplier. It says the bank details have changed and asks you to pay the next invoice to a new sort code and account number. The tone is polite. The deadline feels real. One rushed BACS payment later, the money is gone.

This guide is for UK owner-managers with roughly 2 to 50 staff who are not IT people. It explains how invoice redirection (also called change-of-bank-details fraud) usually works, what to check before you pay, and a one-page checklist for finance and owners. It is calm process advice, not fear theatre and not a promise that software alone will save you.

How change-of-bank-details scams usually work

Attackers rarely need fancy hacking for this. They need you to trust an email or PDF more than a known phone number.

  • Phishing or mailbox takeover: someone gets into a supplier’s email, or yours, and watches for invoice threads.
  • Lookalike domains: [email protected] instead of the real spelling; easy to miss at speed.
  • Forwarding rules: a quiet rule hides the real supplier replies so only the fraud thread reaches you.
  • Urgent pressure: “stock held”, “late fees”, “director travelling, pay now”.
  • PDF or WhatsApp follow-up: a clean-looking invoice attachment or a chat that repeats the new details.

The payment often goes to a mule account. Banks can sometimes help if you act within hours. Recovery is uncertain. Prevention is cheaper than chasing a recall.

If the incident started with a phishing click on your side, contain sessions and mailbox rules first. See OwnerSec’s first-hour phishing guide. MFA on Microsoft 365 helps stop mailbox takeover. It does not verify a supplier’s new sort code.

What this scam is not

  • Not always ransomware. Files may look fine while money leaves the account.
  • Not always a stranger. Compromised supplier mailboxes send from the “right” address.
  • Not solved by antivirus alone. Endpoint tools do not approve BACS.
  • Not proof that your bookkeeper is careless. Good people miss lookalike domains under time pressure.

What to check before you pay (every time details change)

Treat any new bank details as unverified until a human confirms them on a channel you already trust.

1. Stop and flag

  • Do not update the supplier record from the email alone.
  • Do not reply in the same thread to “confirm” the change.
  • Mark the item as “bank details change - verify” in your accounts tool or shared inbox.

2. Call back on a known number

  • Use the phone number already on last year’s contract, your CRM, or a previous paid invoice.
  • Do not use the number printed only on the suspect email or PDF.
  • Ask for a named contact in accounts. Confirm the sort code, account number, and account name out loud.
  • If nobody answers, wait. Delayed payment beats a wrong payment.

3. Match what you already know

  • Compare the new details to the last successful payment in your bank or accounting export.
  • Check the email domain character by character (extra letters, .co vs .co.uk, hyphens).
  • Open the supplier’s website from a bookmark or search, not from a link in the email.
  • If the request arrives from a personal Gmail while you usually deal with a company domain, treat that as a red flag. Shared inboxes make this worse; see OwnerSec’s shared-login guide.

4. Dual control for larger payments

  • Set a rule: any bank-detail change, and any payment above an amount you choose, needs a second person.
  • Owner or finance lead signs off after the call-back, not before.
  • Keep a short written note: who called, when, what was confirmed.

5. Only then update and pay

  • Update the supplier bank record in Xero, FreeAgent, Sage, or your bank payee list after verification.
  • Send a small test payment first if the supplier agrees and the amount is material.
  • Tell the supplier which details you will use going forward so both sides have a paper trail.

One-page checklist for finance and owners

Copy this into a Teams note, shared drive PDF, or laminated card by the payment desk.

Before any new bank details are accepted

  • Email or PDF alone is never enough
  • Call back on a number already on file (not from the new message)
  • Confirm sort code, account number, and account name with a named person
  • Second person reviews changes above your threshold
  • Write who verified, date, and time
  • Update the accounting system only after verification

Every week for owners

  • Spot-check one recent supplier payment against the last known good details
  • Ask finance: any bank-detail change requests this week?
  • Confirm leavers no longer approve payments or hold the company banking login
  • Confirm MFA is on for accounts and owner mailboxes (see MFA guide)

If you think you already paid the wrong account

  • Contact your bank immediately and ask about recall / APP fraud processes
  • Tell the real supplier so they stop chasing a payment you already sent elsewhere
  • Preserve the emails and invoice PDFs; do not delete the thread
  • Reset passwords and check mailbox forwarding rules if your own email may be involved
  • Follow the phishing first-hour steps if a click or suspicious login started this
  • Tell your insurer if you have cyber or crime cover; follow their notification rules

What software helps (and what it does not)

Be honest with the team. Tools reduce some risks. Process stops the payment mistake.

Helpful

  • MFA on Microsoft 365 / Google Workspace so attackers struggle to sit in the mailbox and alter invoices.
  • A company password manager so finance does not share one banking or accounting login on sticky notes or WhatsApp.
  • Unique passwords and no shared founder inbox for supplier email (shared mailboxes without a shared password).
  • Accounting payee records that only a few people can edit, with an audit trail if your product offers one.
  • Email warning banners for external senders (helpful reminder, not a guarantee).

Not enough on their own

  • Antivirus or endpoint suites do not verify bank details.
  • Spam filters miss lookalike domains and compromised real accounts.
  • File-recovery tools do not recover a BACS payment sent to the wrong account. They are irrelevant to this checklist, so OwnerSec skips a product CTA here.
  • Cyber insurance may help after the fact. It does not replace call-back discipline.

If you are still on shared Gmail or a shared Outlook password for “accounts@”, fix that before you buy another tool. Pair mailbox hygiene with MFA and a password manager. See also how to stop staff reusing passwords and 1Password vs Bitwarden.

A simple payment rule you can adopt this week

Write one paragraph and stick it where payments happen:

We never change supplier bank details from an email, PDF, or chat alone. We call a number already on file, confirm with a named person, and get a second sign-off before we update the payee or release payment. If in doubt, we wait.

Train whoever clicks “Approve” in the bank. That is often the owner, not only the bookkeeper.

Bottom line

Invoice redirection works because payment routines are busy and polite. Slow down when bank details change. Call a number you already trust. Use dual control. Protect the mailbox with MFA and stop shared logins. That will not make every payment fully secure. It will catch the scam most UK SMEs actually see.

Written for UK SME owners. More guides · How we make money · Pages-ready draft only (held)