Chinese Supplier Changed Its Bank Account: What Should You Do?

A bank-account change can be legitimate, but it is also a common feature of business-email-compromise fraud. Treat every change as a controlled exception: stop the payment, verify through an independent channel and document approval before funds move.

Stop the payment workflow

Do not reply with a quick confirmation and do not let shipping urgency override verification. Notify finance that the beneficiary change is on hold and preserve the original email, attachment and message headers.

Verify outside the same communication chain

  • Call a previously verified phone number, not a number provided in the change email.
  • Contact a known senior person at the supplier through an established channel.
  • Use a second internal employee to review the request.
  • Confirm whether the supplier’s email account or domain may have been compromised.

Check the new beneficiary against the transaction

  • Beneficiary legal name and relationship to the contracting supplier.
  • Bank country, branch and account currency.
  • Reason for the change and effective date.
  • Whether the purchase contract permits third-party payment.
  • Signed company confirmation using the supplier’s verified legal name and company seal where appropriate.

Escalate suspicious differences

Warning signs include a personal account, an unrelated company, a new country, unusual secrecy, pressure to act immediately or instructions not to contact the normal representative. A small “test payment” does not make an unverified account safe.

If payment has already been sent

  • Contact your bank immediately and request a recall or fraud hold.
  • Notify the beneficiary bank through your bank.
  • Preserve all correspondence, invoices and payment records.
  • Report the incident to relevant law-enforcement or cybercrime channels in the jurisdictions involved.
  • Do not continue negotiating with the suspected attacker as if the email is trustworthy.

Create a permanent control

Require dual approval for beneficiary changes, maintain a verified supplier bank master file and use a documented callback procedure. The control should apply even when the request appears to come from a familiar contact.

Use a callback protocol that does not depend on the email

A callback is useful only when the contact information comes from a trusted record created before the change request. Do not call a new telephone number in the email, amended invoice or attached letter. Use the supplier contact already held in the approved vendor file, a previously verified company switchboard or a known video contact.

During the callback, confirm the old and proposed beneficiary names, bank country, reason for the change, effective date and who approved it. Require a second person in the buyer organization to review the evidence before the vendor master record is changed. Record the confirmation without placing passwords or sensitive banking credentials in general project notes.

If payment was sent, act in parallel

Contact the sending bank through its official fraud channel immediately and request a recall or hold. Preserve the original email, headers, invoice, payment record and communication timeline. Notify the supplier through a trusted channel so both parties can secure accounts and establish which messages are genuine.

Reporting requirements and recovery options depend on the jurisdictions and institutions involved. Obtain appropriate legal and law-enforcement guidance. Do not delay bank contact while trying to prove internally exactly how the compromise occurred; recovery options can narrow quickly.

Sources and further reading