What to do now
Hold use of the new payment destination and verify the request through an independently established contact channel, not the number or link supplied in the change message. Record who confirmed the change, which instructions they confirmed, and who authorized the update. Recheck the actual payment destination before release; a valid invoice does not validate new bank instructions.
Work through the problem
From evidence to a recorded decision
01
Identify the affected payment
Preserve the request and locate queued transactions before using the new destination.
02
Verify independently
Use a separately established contact route and confirm identity, authority, and the specific change.
03
Authorize the version
Record the instruction version, verification evidence, and authorized updater or approver.
04
Compare before release
Check the actual pending payment against the approved amount and destination.
05
Reconcile or escalate
Retain the provider outcome; if a suspicious transfer occurred, contact the institution and incident owner promptly.
Key takeaways
- An existing email thread and a matching invoice are not independent confirmation of changed payment instructions.
- Approval to pay for work and approval to change the payment destination are different decisions.
- A destination edit must be checked against queued payments and the final payment instruction, not just the vendor profile.
Pause the changed instruction, preserve the request
Save the change message and its attachments in the restricted vendor record. Identify the vendor, invoice, requested destination version, affected payment run, and any pending transaction. Tell the internal payment owner that destination verification is incomplete. Do not delete the message or overwrite the old instruction before the review can compare them.
A hold here is an internal control on using unverified instructions, not a conclusion about when money is contractually due. Resolve any timing or contractual question through the responsible person. Do not assume that the old destination is still usable; the legitimate contractor may really have closed or restricted that account.
Check where the confirmation channel came from
The FBI recommends independently checking a company’s phone number and verifying changes to account numbers or payment procedures. Its business-email-compromise guidance also explains that attackers can exploit legitimate correspondence. Replying to the same thread therefore does not provide an independent check.
Use an established vendor contact record whose provenance predates the request, or independently obtain an appropriate company contact. Confirm you are speaking with a person authorized to handle the vendor’s payment instructions. A familiar voice, caller ID, or a successful call by itself does not document that authority.
For context, the FBI’s 2025 IC3 Annual Report, released April 6, 2026, records US$3,046,598,558 (about US$3.05 billion) in Business Email Compromise complaint losses on page 8. This covers BEC reports across IC3’s reporting population, not landlord-specific losses or total real-world incidence. Appendix C notes that complaint data can change and duplicates can occur. The figure gives context for verifying payment changes; it does not estimate whether this request is fraudulent or how effective this checklist is.
| Confirmation route | What it establishes | Review decision |
|---|---|---|
| Number in the bank-change email | Only that the requester supplied a number | Do not treat as independent verification |
| Reply in the existing email thread | A response inside the same channel | Keep destination verification open |
| Established contact record, unchanged before the request | A separately recorded route to the vendor | Verify identity, authority, and exact change |
| New company contact obtained independently | A separate contact lead | Establish role and authority before relying on confirmation |
| No reliable independent contact available | Verification remains incomplete | Escalate; do not guess a destination |
Keep a small instruction-change packet
The working packet should reference the restricted payment instruction rather than copying full account information into team chat or an owner report. Record a stable version or secure record ID, the contact route’s provenance, confirmation time, verifier, authorizer, and affected pending payments. Use masked identifiers only where they distinguish records adequately; masking is not proof that the destination is correct.
Ask the authorized contact to confirm that the requested change is genuine and which instruction version it concerns using your approved secure process. Do not request an online-banking password, one-time login code, or unnecessary identity documents. If your payment provider supplies destination-verification controls, record their actual scope rather than assuming they establish every fact about authority.
| Decision | Evidence to retain | What it does not prove |
|---|---|---|
| Invoice approved | Scope, completion evidence, amount, invoice ID | That a new destination belongs to the vendor |
| Change independently confirmed | Contact provenance, identity/role, instruction version, time | That the internal updater has payment authority |
| Destination update authorized | Named approver and exact approved version | That already queued payments use that version |
| Payment ready to release | Final destination and amount compared with approval | That the provider has settled the transfer |
| Outcome reconciled | Provider result and matching internal record | That future changes can skip verification |
Make the control workable for a small team
Where the team has separate people available, distinguish verification, authorization, and payment release in the record. Where one landlord fills several roles, say so honestly and still record the independent contact evidence and the final instruction comparison. A second checkbox completed by the same person is not independent review.
Set a clear backup contact for an absent payment owner. Urgency should change the escalation path, not turn an unverified message into authority. Keep vendor-facing communication factual: “We are confirming the changed payment instructions through our established process.” There is no need to accuse the contractor of fraud while facts remain uncertain.
Operational checklist
Mark your progress, then save a working copy. Selections reset when you leave this page. A checked box is not an approval or evidence of completion.
☐
Original change request preserved
☐
Pending payment and instruction version identified
☐
Independent contact provenance recorded
☐
Vendor contact identity and authority checked
☐
Exact change confirmed through the secure process
☐
Update authorization recorded
☐
Final queued-payment destination compared with approval
☐
Provider outcome reconciled or incident escalated
0 of 8 marked
Edge cases
- The contractor changed both email and phone details: verification is incomplete until an independent route is established.
- A payment run was created before the vendor profile changed: inspect the instruction in the run itself.
- The legitimate contractor confirms that the old account is closed but new details remain unverified: escalate the unresolved payment method rather than reverting automatically.
- A bank change concerns a different legal vendor entity: route it for appropriate vendor-identity and authority review rather than treating it as a simple profile edit.
Questions that come up
Does a matching invoice validate the new bank account?
No. The invoice may validate the work and amount, but it does not independently validate a changed payment destination. Verify the destination through an established channel.
Can the team keep paying the old account while checking?
Do not assume the old destination remains valid. Hold or route the payment under the organization’s approved process while the responsible reviewer resolves timing and destination.
What if a payment was already released?
Preserve the instruction and payment evidence, promptly contact the relevant financial institution or provider, use the incident process, and reconcile the actual outcome. Do not promise recovery.
Sources and references
Follow each source to check the underlying claim. Access checks and professional review are different steps.
1. Primary source · Federal Bureau of Investigation
Business Email CompromiseIndependently verify changes to payment instructions; familiar correspondence can be compromised. For suspected BEC, promptly contact the financial institution and report through IC3. No recovery guarantee or mandatory payment-hold period is stated here.
Source checked 2026-09-06
Automated source-access check: 2026-09-06.
2. Primary source · Federal Bureau of Investigation, Internet Crime Complaint Center
2025 IC3 Annual Report — BEC complaint losses, page 8; data notes, page 62Page 8 reports US$3,046,598,558 in 2025 Business Email Compromise complaint losses across the IC3 reporting population. Appendix C, page 62, explains variable complaint data, possible duplicates, loss deduplication, and conversion of foreign currencies to U.S. dollars when possible. Not landlord-specific incidence or a measure of checklist efficacy.
Published 2026-04-06 · Source checked 2026-09-06
Automated source-access check: 2026-09-06.
Continue the workflow
Recover from an uncertain integration outcomeReview a rent payment allocationCheck an owner report’s recipient and property scope before sendingRevision history
2026-09-06
Initial original operational workflow and fictional examples, with explicit AI-assisted technical review and narrowly scoped primary references.