← Back to Knowledge Center
KNOWLEDGE CENTER

Payment Fraud: Stop When the Details Change

Financial & Payment Securityen-NG
BEFORE YOU BEGIN

Understand the issue before you decide what to do.

This lesson is designed to explain the subject in practical terms so that you can understand not only what the risk is, but why it matters, how it can appear in real situations and what you can do to reduce your exposure.

Read the explanation carefully before acting on a suspicious message, request, transaction, account notification or other security-related situation.

FULL LESSON

Understanding the subject

Take your time with this explanation. The goal is not simply to recognise a warning sign, but to understand what is happening and make a safer decision when you encounter it.

PAYMENT FRAUD: STOP WHEN THE DETAILS CHANGE

Payment fraud often succeeds when a familiar transaction is changed at the last moment.

A supplier may send a new bank account. A customer may say they have changed payment details. A colleague may ask you to pay a different beneficiary. A supposed executive may request an urgent transfer. A message may say that a previous account is no longer working.

The request can look completely normal because the underlying business relationship is real.

The danger is the CHANGE.

THE CORE PRINCIPLE

WHEN PAYMENT DETAILS CHANGE, TREAT THE CHANGE AS A NEW CLAIM THAT MUST BE VERIFIED — EVEN IF THE PERSON, SUPPLIER, ACCOUNT OR CONVERSATION IS FAMILIAR.

Do not let a new message become the only evidence that a new payment instruction is legitimate.

A useful payment-verification sequence is:

PAUSE → IDENTIFY → VERIFY → CONFIRM → APPROVE → RECORD

01 · START WITH THE PAYMENT YOU ALREADY EXPECT

Before looking at the new instruction, identify what you originally expected to happen.

Ask:

  • Who were you expecting to pay?
  • What amount was expected?
  • What account or beneficiary was previously on record?
  • What invoice, order, contract or service does the payment relate to?
  • When was the payment supposed to be made?
  • What payment method was previously agreed?

This creates a baseline.

If the new instruction differs from the baseline, the difference needs verification.

02 · IDENTIFY EXACTLY WHAT CHANGED

Do not describe a change simply as "the payment details changed."

Identify the specific change.

It could be:

  • Bank account number
  • Account name
  • Beneficiary name
  • Bank name
  • Other bank identifier
  • Payment method
  • Wallet address
  • Invoice number
  • Amount
  • Currency
  • Payment deadline
  • Supplier contact
  • Payment destination
  • Instructions for approving the payment

One small change can be enough to stop the transaction until it is independently confirmed.

03 · WHY A FAMILIAR CONVERSATION CAN STILL BE DANGEROUS

A genuine conversation does not automatically make every new instruction genuine.

An existing email account, WhatsApp account or business relationship can be compromised.

For example, a real supplier's mailbox may be compromised and used to send a fraudulent bank-account change.

That means:

Familiar person ≠ verified new payment instruction.

Familiar email thread ≠ verified new beneficiary.

Familiar company ≠ verified changed account details.

The thing being verified is the NEW PAYMENT INSTRUCTION.

04 · DO NOT VERIFY THE CHANGE THROUGH THE SAME MESSAGE

This is one of the most important rules.

Suppose a supplier emails:

"Please use our new bank account for all future payments."

Do not simply reply:

"Can you confirm this is genuine?"

If the email account has been compromised, the attacker can confirm it.

Instead, use a channel that existed before the change request.

EXAMPLE

  • Call the supplier using a number already stored in your business records.
  • Contact a known supplier representative through an established channel.
  • Use a previously verified contact in your accounting or procurement records.
  • Visit or contact the organisation through independently obtained official details.
  • Follow an established internal approval process.

The verification channel should be independent of the changed instruction.

05 · VERIFY THE BENEFICIARY

Before approving the payment, compare the new beneficiary with your existing records.

Check:

  • Account name
  • Account number
  • Bank
  • Other relevant beneficiary identifiers
  • Previous payment records
  • Supplier or customer records
  • Invoice information

A name that looks correct is not enough.

A familiar business name can be paired with an unfamiliar account.

Do not assume that because the beneficiary name looks right, the destination is correct.

06 · VERIFY THE PURPOSE OF THE PAYMENT

A payment can be fraudulent even when the beneficiary details look plausible.

Ask:

  • What exactly is this payment for?
  • Does the invoice match the goods or service?
  • Does the amount match the agreement?
  • Is the timing consistent with the contract?
  • Is the payment being requested outside the normal process?
  • Has someone introduced a new reason for urgency?

If the purpose does not make sense, stop before approving the payment.

07 · VERIFY THE AMOUNT

Compare the requested amount with the original agreement, invoice, purchase order or other authoritative record.

Watch for:

  • Unexpected increases
  • Changed decimal places
  • New fees
  • Duplicate invoices
  • Different currency
  • Split payments
  • Requests for an additional "verification" payment
  • Requests to send money to a personal account

Do not let an urgent explanation replace a normal financial check.

08 · WATCH FOR URGENCY AND AUTHORITY

Payment fraud often becomes more convincing when pressure is added.

Examples include:

  • "Pay today or the contract will be cancelled."
  • "The director approved this already."
  • "The supplier changed banks and we must act immediately."
  • "Do not call; I am in a meeting."
  • "This is confidential."
  • "We only have a few minutes."
  • "Use this new account just this once."

Urgency is not proof.

Authority is not proof.

A senior person's name or title does not remove the need for payment verification.

09 · EXECUTIVE OR CEO PAYMENT REQUESTS

An unusual payment request that appears to come from a senior executive should be verified through an established channel.

Do not rely on:

  • Display name
  • Profile photo
  • Email signature
  • Familiar writing style
  • Previous messages
  • A message saying the executive is unavailable
  • A request for secrecy

If your organisation has a payment approval policy, follow it even when the requester appears senior.

A useful rule is:

NO EXCEPTION TO PAYMENT CONTROLS JUST BECAUSE THE REQUESTER APPEARS IMPORTANT.

10 · SUPPLIER BANK-ACCOUNT CHANGES

Supplier account changes deserve special attention because the underlying supplier may be genuine while the new payment destination is not.

When a supplier says its bank details have changed:

  1. Stop the payment until the change is verified.
  2. Retrieve the supplier's established contact details from your own records.
  3. Contact the supplier through that established channel.
  4. Confirm that the account change was actually requested.
  5. Confirm the exact new beneficiary details.
  6. Record who confirmed the change and when.
  7. Follow your organisation's approval process.
  8. Only then update the payment record.

Do not use the phone number or link supplied in the suspicious change message as your only verification route.

11 · INVOICE AND DOCUMENT CHANGES

Fraudulent payment instructions do not always arrive as a simple message.

A new invoice may contain:

  • A different account number
  • A different QR code
  • A different wallet address
  • A changed amount
  • A new payment method
  • A new contact person
  • A new attachment
  • A different company name or spelling

Compare the new document with a previously trusted invoice or contract.

If important payment information has changed, verify the change independently.

12 · CRYPTOCURRENCY PAYMENT CHANGES

The same principle applies to digital assets.

If someone says:

"Use this new wallet address."

Stop and verify.

Do not assume a new wallet address is genuine because:

  • It came from a familiar contact.
  • It appeared in an existing conversation.
  • The profile looks correct.
  • The person says the old address no longer works.
  • The new address has been copied and pasted.
  • The transaction is urgent.

For an important crypto payment, independently verify the destination address and network before signing.

A successful blockchain transaction can still be a successful payment to the wrong destination.

13 · QR CODES AND PAYMENT LINKS

A QR code or payment link can hide the destination until you scan or open it.

Before paying:

  • Check where the link leads.
  • Confirm the beneficiary or merchant.
  • Check the amount.
  • Check the payment method.
  • Do not approve a payment simply because the QR code came from a familiar conversation.
  • For important payments, verify the destination through an established channel.

A QR code is a convenience mechanism, not proof of identity.

14 · NEVER SEND A "TEST PAYMENT" WITHOUT VERIFYING THE DESTINATION

A small amount is still money.

Fraudsters may describe a small transfer as a "test" before a larger payment.

If the destination itself has not been verified, a small payment does not make the situation safe.

If your organisation uses test transfers as part of a legitimate process, the process should be defined in advance and independently verified.

15 · WATCH FOR SECOND-STAGE FRAUD

After a fraudulent payment or attempted payment, another person may contact the victim claiming to help recover the money.

They may say:

  • "We can reverse the payment."
  • "Pay a recovery fee."
  • "Send a verification payment."
  • "Give us your OTP so we can process the refund."
  • "Install this application so we can recover the funds."
  • "Give us your banking credentials so we can trace the transaction."

Treat unexpected recovery offers as a separate request that also requires verification.

Do not send additional money or authentication secrets simply because someone claims to be helping.

16 · PAYMENT SCREENSHOTS ARE NOT PAYMENT CONFIRMATION

A screenshot can be edited, incomplete or taken from a different transaction.

Before releasing goods, services or assets, verify the actual payment through the relevant bank, payment service or account record.

The authoritative record should come from the receiving side or the trusted payment system, not only from the person who claims to have paid.

17 · USE TWO-PERSON OR MULTI-STEP APPROVAL WHERE APPROPRIATE

For organisations handling significant payments, consider controls such as:

  • Separate preparation and approval roles
  • Independent callback verification
  • Dual approval for high-value payments
  • Beneficiary-change review
  • Supplier-master-data controls
  • Transaction limits
  • Audit logs
  • Periodic review of payment permissions

The exact controls should match the organisation's size, systems and risk.

The goal is to prevent one compromised message or account from immediately becoming an irreversible payment.

18 · RECORD VERIFIED CHANGES

When a payment detail is legitimately changed, record the verification.

Depending on the organisation, record:

  • Who requested the change
  • Who independently confirmed it
  • Date and time of confirmation
  • Previous payment details
  • New payment details
  • Supporting invoice or contract
  • Approval reference
  • Relevant internal record

This creates an audit trail and reduces the chance that the same change will be questioned repeatedly or reintroduced through another message.

19 · WHAT TO DO WHEN THE DETAILS DO NOT MATCH

If something does not match:

STOP.

Do not try to "make it work."

Do not send a small amount just to test it.

Do not ask the suspicious sender to explain why the information changed and then treat their explanation as proof.

Do not approve the payment until the discrepancy is resolved through an independent channel.

20 · WHAT TO DO IF YOU ALREADY SENT THE MONEY

If you discover that a payment may have gone to a fraudulent destination:

  • Stop any additional payments connected to the incident.
  • Contact the bank or payment provider immediately through its official channel.
  • Provide the transaction reference, amount, destination and relevant timeline.
  • Preserve the messages, invoices, emails and payment records.
  • Notify the appropriate person in your organisation.
  • Follow the bank's or payment provider's fraud-response process.
  • If appropriate, report the incident to the relevant authority.
  • Be cautious of anyone who later offers paid recovery services without independently verified credentials.

Speed matters after a suspected fraudulent payment, but the response should still use verified channels.

21 · NIGERIAN BUSINESS CONTEXT

In Nigeria, payment changes may appear through email, WhatsApp, SMS, phone calls, invoices, bank notifications or informal business communication.

Examples include:

  • A supplier sends a new account number on WhatsApp.
  • A customer says payment should go to a different account.
  • A business owner receives an urgent transfer request from someone using a familiar profile.
  • A staff member receives a message saying the company's bank account has changed.
  • A POS or payment instruction shows an amount different from what was agreed.
  • A crypto customer sends a different wallet address shortly before payment.

The communication channel can change, but the principle does not:

VERIFY THE CHANGE BEFORE THE MONEY MOVES.

22 · THE PAYMENT CHANGE TEST

Before approving a changed payment instruction, ask:

WHO — Who is requesting the change?

WHAT — Exactly what payment detail changed?

WHY — Why is it changing?

WHERE — Where will the money now go?

HOW — How did the new instruction arrive?

WHEN — Why is the change being made now?

INDEPENDENTLY — Can I confirm the change through a channel that existed before this request?

If the independent verification step has not happened, the payment should not be treated as verified.

23 · THE FIVE-SECOND FINAL CHECK

Immediately before approving a consequential payment, stop for a final review:

  • Is the beneficiary correct?
  • Is the account or wallet destination correct?
  • Is the amount correct?
  • Is the purpose correct?
  • Was any detail changed?
  • If something changed, was it independently verified?
  • Am I relying on a screenshot, forwarded message or urgent instruction instead of the authoritative record?

If any answer is uncertain, pause.

24 · PAYMENT FRAUD CHECKLIST

Before approving a payment:

□ Confirm the original payment expectation.

□ Identify exactly what changed.

□ Verify the beneficiary.

□ Verify the amount and currency.

□ Verify the purpose or invoice.

□ Check for urgency or unusual secrecy.

□ Do not rely on the same message to verify its own change.

□ Use a previously trusted contact channel.

□ Follow the organisation's approval process.

□ Record legitimate changes.

□ Confirm actual payment receipt through the authoritative account or payment system.

□ If something looks wrong, stop before sending.

FINAL PRINCIPLE

A payment instruction does not become trustworthy because it arrived through a familiar conversation.

A supplier can be real while a changed bank account is fraudulent.

A colleague can be real while their account is compromised.

A manager can be real while the request was not actually made by them.

A document can be genuine while the payment destination inside it has been changed.

The safest habit is simple:

WHEN THE PAYMENT DETAILS CHANGE, STOP.

VERIFY THE CHANGE THROUGH A CHANNEL YOU TRUST INDEPENDENTLY.

THEN — AND ONLY THEN — CONTINUE.

VERIFY BEFORE YOU TRUST.

APPLY WHAT YOU LEARNED

Turn understanding into a security habit.

Knowing the definition is only the beginning. The real value of cybersecurity education is being able to recognise the situation and make a safer decision when it happens to you.

How should you use what you learned?

Understanding a cybersecurity concept is useful only when it changes how you make decisions. When you encounter a similar situation in real life, slow down and identify what is being requested before you respond.

Ask yourself who is making the request, what they are asking you to do, what information or access is involved, and whether the request can be independently verified.

Do not allow urgency, fear, authority, familiarity or the promise of a reward to replace independent verification.

What if I still do not understand something?

Cybersecurity concepts can sometimes involve technical terms or situations that are difficult to interpret from a single lesson. If something is unclear, do not guess when the decision could affect your money, identity, account access, device or sensitive information.

You can seek further guidance through the consultancy channel. Explain the situation clearly, but never include passwords, OTPs, PINs, recovery phrases, private keys or other authentication secrets.

Use the consultancy form →

THE VERIFY BEFORE YOU TRUST PRINCIPLEVERIFY BEFORE YOU TRUST.

A convincing message, familiar name, professional appearance or urgent request is not proof of legitimacy. Verify the important facts independently before taking an action that could be difficult to reverse.