How the situation unfolds
- 01
Contact
An existing supplier email thread or reconciliation message.
- 02
The lure
Our old account is under audit; use the new one.
- 03
The demand and outcome
An attacker monitors compromised email and inserts new payment instructions, or continues the thread from a lookalike address.
Verify these things before paying
- Verify changes by an independent callback
- Check account names against contracts
- Separate change review from payment approval
Already engaged or paid?
- Alert the sending bank immediately
- Confirm instructions with the original contact
- Notify security staff and preserve the email chain
Contact your payment provider and local police promptly. The responsible institution must confirm whether a payment can be stopped, disputed or returned.
Keep these records
Keep originals and organise working copies. Never give strangers verification codes, banking passwords, private keys or seed phrases.
Original references
- FBI Internet Crime Complaint Center (IC3)Publisher location:United States · EnglishOpen the original reference ↗https://www.ic3.gov/PSA/2020/PSA200406
This page summarises public prevention guidance to help recognise methods. It is not an enforcement conclusion about a particular incident. Check the source page for its original title. Procedures and reporting routes vary by jurisdiction. Compiled October 2026.
