Recognize the pattern
How it starts
Vendor invoices, real estate closing emails or a familiar business email thread.
Our old account is under audit; use the new one.
What happens next
An attacker monitors compromised email and inserts new payment instructions, or continues the thread from a lookalike address.
Signs to watch for
- Last-minute bank detail changes
- New account name differs from the contract
- Refuses verification through known contacts
Start with what you can do now
If this happened to you
Ask your sending bank immediately about a recall or other available steps.
Notify the actual vendor, title company or other intended recipient.
Preserve the complete email thread and report online fraud at IC3.gov.
What to save
Keep the original records. Use copies to organize the details.
- Contract and original bank details
- Change emails and headers
- Verification call records
- Transfer times and account details
Before you send money
- Verify any change by calling a number you already know.
- Do not use contact details supplied in the change request.
- Require a separate review before changing saved payment instructions.
These guides explain common patterns. The facts of your situation and your payment provider’s rules determine which steps are available.

