How to Verify Supplier Payment Changes Safely
Supplier payment changes should be verified through a known contact method and recorded before business payment details are updated.
Quick answer: stop and verify using a trusted contact method before you pay, approve, reply or ignore warning signs.

Quick answer
Treat unexpected payment or bank-detail changes as a verification problem, not an email problem. Pause the transaction and confirm the request through a known contact method before approving or paying it.
Fast decision
What this means for a small business
Supplier payment changes should be verified through a known contact method and recorded before business payment details are updated.
Most business cyber problems become expensive when a normal-looking request is handled too quickly. A safer process gives staff permission to pause, check the source, and ask for help before money, access or sensitive information is exposed.
This guide uses fake examples only. It is designed to help you prepare a safer next step, not to collect private records or replace professional investigation.
Warning signs to check
- The request asks you to update stored bank details.
- The request came from email only, with no trusted second contact.
- A new person or changed email domain is asking for the change.
- There is pressure to update details before the next payment run.
What to do now
- Verify using a known phone number or contact already saved in your records.
- Ask a second staff member or owner to review the change before approval.
- Keep a short verification note with date, name, contact method and outcome.
- Hold payment if anything feels inconsistent.
What not to do
- Do not use the contact details supplied in the change request.
- Do not let one staff member both verify and approve high-value changes.
- Do not update accounting software without a recorded verification trail.
Related Business Cyber Safety links
Invoice bank details changed
Continue with the related Business Cyber Safety guide.
Two-person approval for supplier payments
Continue with the related Business Cyber Safety guide.
Scam Safety hub
Use this when the issue looks like a scam message, fake invoice or payment redirection attempt.
Essential Eight small business hub
Review broader basics like two-step login, backups, updates, admin access and safer devices.
Benefits and practical outcomes
Use these outcomes as a practical check on whether the advice is making the situation clearer and easier to manage.
Reduce avoidable exposure
Simple account, update, access and verification controls can reduce common preventable weaknesses.
Recover with less guesswork
Documented owners, backups and evidence make incident response and restoration easier to organise.
Give staff a repeatable check
Plain-English steps are easier to follow than relying on memory when an unusual request arrives.
Prioritise the next fix
A short checklist helps separate urgent controls from improvements that can be scheduled later.
Example: payment instruction changes
An accounts email asks staff to pay a familiar supplier into a new bank account. The team pauses the payment and verifies the change using the supplier contact details already held in its system.
Outcome: a high-risk instruction receives an independent check before money moves.
FAQ
Is this a formal cyber audit?
No. This is a practical self-check guide, not a formal audit, investigation, certification or guarantee.
Should I share passwords or login codes?
No. Do not share passwords, login codes, banking passwords, card numbers or private customer records through this guide.
What if money has already been sent?
Contact your bank immediately. Then collect the invoice, email details and verification notes for review.