The pattern: business email compromise (BEC)
This is one of the most common ways businesses lose money to fraud. It usually looks something like this: an email, WhatsApp message, or even a follow-up phone call arrives claiming to be from a known supplier, saying their bank account has "changed" — often citing a plausible reason (a bank switch, an audit, a new finance system) — and asking you to pay your next invoice to the new account instead.
The email or message can look completely convincing: the right supplier name, the right invoice number, even a domain that looks almost identical to the real one. That's exactly why the check has to happen outside that same channel.
The core defence: call back on a number you already trust
Before paying any invoice where the bank account has changed, or where anything about the payment instructions looks different from usual:
- Do not reply to the email or message to "confirm." If the message itself is fraudulent, replying to it just reaches the scammer again.
- Find a phone number independently — one you already have on file from a previous, trusted interaction, or one you look up directly on the supplier's official website (typed directly, not clicked from the suspicious message).
- Call that number and verbally confirm the account change with a real person at the supplier before paying anything.
This single step — verifying out-of-band, through a channel the scammer doesn't control — defeats almost all business email compromise attempts, because the fraud depends entirely on you trusting the same channel the fake instruction arrived on.
Check the supplier's registration if they're new or unfamiliar
If this is a new supplier, or one you don't have a long history with, search their company name or registration number through SSM to confirm the entity is genuinely registered. This doesn't replace the call-back step above — a scammer can also register a shell company — but it's a useful additional check, especially combined with confirming the invoice and account details directly with a known contact.
DuitNow proxy and QR payments need the same caution
Don't assume a DuitNow proxy (phone number or ID-linked) payment or a QR code is any safer than a bank transfer just because it's a newer payment rail. If a "new" DuitNow-linked account or QR code arrives with a request to pay it instead of your usual account, apply exactly the same verbal, out-of-band confirmation before paying — the underlying scam pattern is identical, only the payment method has changed.
This isn't about refusing every change — it's about verifying it
Suppliers do sometimes genuinely change banks, merge with another entity, or update their finance details. The point of this guide isn't to treat every change as fraudulent — it's that a claimed bank-detail change is exactly the kind of instruction that should never be acted on based on the message alone, regardless of how official it looks. A payment request combined with a claimed change to bank details is a high-risk combination precisely because it's what fraud typically looks like — verify it every time, and pay normally once you have.
If you want a message, email or invoice checked against known Malaysian scam patterns before you act on it, you can run it through our free checker.
FAQ
The email came from what looks like the supplier's real email address — isn't that enough?
No. Email addresses and display names can be spoofed, and a scammer who has compromised either your or the supplier's email account can send messages from the genuine address. The email address alone is not verification — a verbal call-back to a number you already trust is.
What if I can't reach anyone by phone before the payment is due?
Delay the payment. A short delay to verify is far cheaper than paying a fraudulent account, and any reasonable supplier will understand a call-back check on a bank detail change. If you're genuinely unable to reach them, don't pay the new account until you can.
Is a QR code or DuitNow ID payment safer than a bank transfer for this?
No — the payment rail doesn't change the underlying risk. A "new" QR code or DuitNow-linked account presented alongside a claimed detail change should be verified the same way: a phone call to a number you already trust, not a reply to the message that introduced the change.