JagaShieldBahasa Malaysia

Invoice scams & fake bank-detail changes

Last verified: 20 Aug 2026

An attacker compromises or spoofs a supplier's email and sends your business an invoice, or a notice that their bank account has "changed," asking you to pay into a new account. Some attackers quietly watch a real email thread for weeks before injecting the fake instruction right as a genuine payment falls due. Never change a payment based on email alone — always call back a number already on file.

How this scam typically works

This is business email compromise (BEC). An attacker gains access to — or convincingly spoofs — a supplier's email account, then sends your business an invoice or a message saying the supplier's bank account details have "changed" and future payments should go to a new account. Because it appears to come from a real, known counterparty, and often references genuine invoice numbers or an ongoing project, it doesn't look like a stranger asking for money — it looks like routine business correspondence.

In more patient versions, the attacker sits inside a real, compromised email thread for days or weeks, quietly reading how your business and the supplier normally communicate, before injecting the fake payment instruction at exactly the moment it will do the most damage — right before a real invoice is due, or during a large one-off payment such as a deposit or final settlement. By the time the fraud is discovered, the funds have often already moved on from the receiving account.

The defence is procedural, not a matter of reading more carefully: never change how you pay a supplier, or where you send a payment, based on an email instruction alone — no matter how convincing the email looks, how well it matches past correspondence, or how much urgency it carries. Before paying into any new or "changed" account, verbally confirm the change with the supplier by phone, using a number you already have on file — never a number provided in the suspicious email itself. See How to verify a supplier's bank details before paying an invoice for the full call-back procedure.

Warning signs

If you're being targeted right now

Do not pay, and do not reply to the email confirming anything. Contact the supplier using a phone number you already had on file — from a previous contract, your own records, or their official website — not any number in the suspicious message — and verbally confirm whether the account change is real before anything is paid. If your business uses a payment or fraud-screening tool, a bank-detail-change claim combined with a payment request is exactly the kind of pattern it should flag as high risk — treat that flag seriously rather than overriding it under time pressure.

If you've already sent a payment

See Scammed in Malaysia? The first 24 hours for the exact steps to take next — every hour matters for freezing a transfer, and the guide covers who to call, in what order, and what to preserve as evidence.

FAQ

We've paid this supplier the same way for years — why would we need to verify now?

That history is exactly what makes this attack work — the request looks routine because it's built to. A long-standing relationship is a reason attackers target that thread, not a reason to skip verification. The one-time cost of a phone call is far lower than the cost of an unrecoverable payment sent to the wrong account.

The email came from the supplier's real email address — doesn't that prove it's genuine?

Not on its own. If the supplier's account itself has been compromised, messages sent from it are genuinely from their address but not genuinely from them. This is why the verification step has to happen through a separate channel — a phone call to a number you already have — rather than by trusting the email thread itself, however legitimate the address looks.

What's the single most important habit to build into our payment process?

Treat any bank-account-change instruction, from any supplier, as requiring a verbal callback to a known number before the first payment goes to the new account — every time, with no exceptions for urgency or the seniority of whoever is asking. See How to verify a supplier's bank details before paying an invoice for the full procedure.

Checklist

  • An email claims a supplier's bank account details have changed and asks you to update where you pay
  • The request arrives with unusual urgency, often timed just before a real payment is due
  • The sender address is close-but-not-quite right (a swapped letter, extra character, or different domain), or the thread's tone has subtly changed
  • You're discouraged from calling to confirm, or a phone number is supplied in the same email instead of one you already had on file
  • The new bank account name doesn't match the supplier's registered business name