A supplier emailed new bank details. What should I do?
Treat an unexpected change to payment details as something that needs independent confirmation before you transfer money—even when the email looks genuine.
Why a genuine-looking email may not be enough
Business email compromise can involve an attacker impersonating a business or gaining access to a real email account. Australian cyber-security guidance describes invoice fraud where legitimate-looking invoices or messages are altered so payment goes to an account controlled by the attacker.
Confirm outside the email
Pause the payment. Contact the supplier using a phone number you already have, an established contact or independently sourced official details. Do not rely on the phone number, link or reply address contained in the message asking you to change payment details.
If you believe money or financial details are at risk, Australian Cyber Security Centre guidance says to contact your financial institution as soon as possible. You can also report scams through the appropriate Australian reporting services.
Verify First can review the sender, reply-to, wording, links and payment-change signals you provide. It is a risk assessment, not proof that a sender is a scammer.
Run Email Scam CheckOfficial guidance: Cyber.gov.au — Business email compromise and Report and recover from BEC.