Supplier changes bank details by email — your payment lands in a fraudster's account
Fraudsters spoof or hack a supplier's email and send a fake 'bank account change' notice. The company pays a real invoice to the fraudster's account. Pune firms lost ₹56 lakh and ₹73 lakh in separate cases; a .com→.cam domain swap cheated a polymer company ₹10 lakh.
Also known as: vendor email compromise, supplier bank account change scam, BEC vendor fraud, fake invoice bank details fraud, business email compromise India, domain spoof supplier fraud
Already happened to you? Do this in the next few minutes
Call 1930 now- 1 Call 1930 — the national cyber-crime helpline — right now. The sooner you report, the better the chance of freezing the money before it moves.
- 2 Call your bank to freeze the account and block the card immediately. Use the number printed on your card, never a number from the message or caller.
- 3 File a report at cybercrime.gov.in and keep every message, screenshot, and transaction ID.
What to do right now
- 1 Never update a supplier's bank details based on email alone — call the supplier on a number from your records, not from the email
- 2 Verify every bank-detail change through a second, out-of-band channel (phone call, in-person, supplier's official website)
- 3 Check the sender domain carefully for character swaps — one changed letter creates a convincing lookalike domain
- 4 If a payment has already gone to a fraudulent account, call your bank's fraud helpline immediately to initiate a NEFT/RTGS recall — every hour matters
- 5 Report at https://cybercrime.gov.in or call 1930 (national cyber helpline).
Red flags
- ⚠ An email from a known supplier saying their bank account details have changed — always verify by calling the supplier's registered number, not a number in the email
- ⚠ The sender domain looks almost identical to the real supplier but has a one-letter swap (.com → .cam, .co.in → .c0.in)
- ⚠ The email arrives shortly before a large payment is due, creating urgency to update records before the transfer
- ⚠ The new account is in a different bank or city than all previous payments to that supplier
- ⚠ The email asks you to update your system with new details before the 'old account closes on a specific date'
Known variants
-
Domain lookalike variant: attacker registers a domain with one character swapped (e.g. supplier-name.cam instead of .com) and sends email from it. Finance team sees familiar supplier name in the display field and misses the domain change. Pune polymer firm lost ₹10 lakh this way in July 2026.
Last seen: 7/18/2026