Verify Suppliers After a Fraud
A fake invoice got paid, and now every supplier account needs a second look.
Updated 2026-09-29 · Independent resource. Legal review pending.
Why one fraud means checking every supplier
A single fraudulent invoice often signals that a compromised inbox, a lookalike domain, or a leaked document exists somewhere in your supplier chain, not just in the one payment that went wrong. The same access can be used to target other suppliers or other invoices from the same one.
Reviewing every active supplier account after a fraud is discovered is a reasonable, proportionate response, not an overreaction. It is far less costly than a second incident.
The callback method that works
Call each supplier on a number you already have on file, from an old invoice, a contract, or your own records, never a number given in a recent email. Ask them to confirm their current bank account details out loud, and note who you spoke to and when.
A genuine supplier will not mind this call, and many expect it once they hear a fraud has affected a business they work with. Treat any supplier who resists this simple check as a request that needs further verification before payment.
Building a supplier contact registry
Keep a central record of each supplier’s verified phone number, the person who confirmed it, and the date, separate from the email thread where invoices arrive. Update this registry only through a verified call, never based on a new email alone.
This registry becomes the reference point for every future payment, so a compromised inbox cannot quietly introduce a new bank account without being noticed. It is one of the practical controls to tighten after a fraud.
What to do with payments still pending
Hold any payment to a supplier that has not yet been re-verified, even if this means a short delay to a genuine invoice. Communicate the delay honestly: a security review is underway following a fraud, and payment will follow once the account is confirmed.
This is a reasonable message to send to a real supplier, and most will understand it without difficulty.
What to do next
Work through your active supplier list in order of upcoming payment dates, starting with the largest or most urgent. This sits alongside the wider business email compromise response set out in the BEC incident response checklist.
If the fraud already resulted in a payment being lost, recall the transfer and make a police report at the same time as this review, since neither step should wait for the other.
If your business needs help reviewing supplier accounts after a fraud, tell us where you are in the process and we can help you see what to prioritise.
Common questions
Do we need to check every supplier, or just the one involved in the fraud?
Check every supplier with upcoming payments, not just the one connected to this incident, since a compromised inbox or a copied invoice format can sometimes be reused against other accounts. A short review across active suppliers is worth the time compared to a second fraud.
How do we verify a supplier without seeming to accuse them?
Frame it as a routine security check rather than a suspicion, since most genuine suppliers expect this after any business hears about a fraud in its industry. A simple call confirming their bank details are unchanged takes only a few minutes and rarely causes offence.
What if a supplier cannot be reached quickly?
Hold any pending payment to that supplier until the account is confirmed through a number you already have on file, even if it delays the payment slightly. A short delay is a reasonable trade off against paying a fraudulent account again.
Read next
A BEC Incident Response Checklist
A practical checklist for responding to business email compromise, covering the first hours through the following weeks.
Read thisCheck Your Cyber Insurance After Fraud
If your SME has suffered a fraud, here is how to check a cyber insurance policy and notify the insurer correctly.
Read thisHandle a Data Breach After BEC
If a compromised inbox during a business email compromise incident may have exposed personal data, here is how to assess and respond.
Read thisHow to Recall a Corporate Wire Transfer
How a business can request a recall on a corporate wire transfer sent on a fraudulent instruction, and what your bank needs from you.
Read thisIf your business needs help reviewing supplier accounts after a fraud, tell us where you are in the process and we can help you see what to prioritise.