Technical Support: 0 (552) 380 25 25  |  24/7 Technical Support

🇹🇷 TR

Digital Bridge Blog

Business Email & Documents

Bank Detail Change Email Fraud: Why "Our Account Has Changed" Emails Pass Your Filter — and How to Stop Them

Bank detail change email fraud passes SPF, DKIM and DMARC. See how the attack is built and the eight-step control framework that protects your finance team.

 · 8 min read  · Digital Bridge Engineering Team
Bank Detail Change Email Fraud: Why "Our Account Has Changed" Emails Pass Your Filter — and How to Stop Them

Bank detail change email fraud is when an attacker impersonates one of your suppliers, announces that "our bank account has changed", and your next payment lands in the fraudster's account. These emails usually get past spam filters because the attacker writes from a domain they control, so SPF, DKIM and DMARC all pass. The defence is a payment process that verifies any change outside email, combined with an email platform that separately flags look-alike domains and messages about changed payment details.

What actually happens on the finance desk

Your accounts team receives dozens of supplier emails a day. One of them reads: "Our bank account has changed; please make this month's payment to the new account details attached." The display name is familiar, so is the signature, and the invoice number is right. Sometimes the message even appears to continue a real thread. In the month-end rush the payment run is prepared, the new IBAN goes into the supplier record and the money leaves. The mistake typically surfaces weeks later, when the real supplier calls to ask why they have not been paid.

This is payment diversion fraud, a form of Business Email Compromise (BEC). What sets it apart from ordinary phishing is that it usually carries no malicious link or attachment and is written in completely routine business language. That lets it slip past the filter and a careful employee at the same time.

The cost of leaving it unsolved

There is no regular public statistic on BEC losses in Türkiye; the most detailed data comes from the United States, and the picture is clear:

According to the FBI's Internet Crime Complaint Center (IC3), 24,768 business email compromise complaints in the US reported total losses of $3.05 billion in 2025. (FBI IC3 2025 Internet Crime Report)

The sums being requested are growing too. According to the APWG Phishing Activity Trends Report for Q2 2026, the average amount requested in wire-transfer BEC attacks rose to $61,732, up 45% on the previous quarter. For a small or mid-sized business, one successful email can knock a month's cash flow off course.

The data also shows why filters miss it. According to the Verizon 2026 Data Breach Investigations Report, 80% of attacks blocked by email security gateways were plain phishing, while only 3% were BEC-style emails trying to get the victim to update a bank account ahead of a wire transfer. Gateways mostly catch the crude attacks; the quiet, targeted ones are a small slice of what they stop.

Once money has gone, hours matter. The FBI IC3 2025 report says its Recovery Asset Team initiated 3,900 incidents in 2025 involving $1.16 billion in attempted theft and froze $679 million of it (a 58% success rate), stressing that "time is of the essence" once a fraudulent transfer is discovered. Acting fast depends on everyone knowing, in advance, whom to call and how.

How the attack is built, step by step

The attacker does not need to break into your systems. The usual sequence is:

  1. Pick the counterparty. Your website, reference lists, LinkedIn or previously leaked correspondence reveal which suppliers you work with.
  2. Register a look-alike domain. example-logistics.com becomes example-logistlcs.com (an l for an i), or an address using international characters that looks identical.
  3. Configure authentication properly. It is the attacker's own domain, so SPF, DKIM and DMARC are set up perfectly.
  4. Time it. Month end, the invoicing period, or the week the real supplier sends a genuine invoice.
  5. Send the request. Short and urgent — "our bank details have changed", "our account is frozen, please pay into this one" — or a copy of the genuine invoice PDF with the IBAN swapped.

In some cases the attacker takes over the supplier's real mailbox, so the email comes from exactly the right address. That is why technical checks alone are never enough and process controls are essential.

Why the spam filter lets it through

Spam filters essentially ask two questions: does the sender prove who they are? and does the content look like known spam? In this attack both answers reassure the filter.

CheckClassic spamBank detail change email
SPF / DKIM / DMARCOften failsPasses (attacker's own domain)
Bulk sendingYesNo, a single recipient
Links / malicious attachmentCommonOften none — plain text or a clean PDF
Spam wordingPresentNone, ordinary business language
Reply addressIrrelevantOften a different Reply-To

The problem is not a bad filter; it is a filter looking in the wrong place. Catching this attack means adding three questions to "is this email technically valid?": does the sender's domain imitate a known counterparty, are replies being redirected elsewhere, and does the message talk about a change in payment details? We cover the domain tricks in our guide to look-alike domain attacks and the invoice variant in fake invoice email scams.

An eight-step control framework for your finance team

  1. Never confirm a bank change by email. Call the supplier on the number held in your own records — not the one in the email.
  2. Require two people for any change. The person who enters the new IBAN in the supplier record and the person who approves it should be different.
  3. Watch the first payment. After the first transfer to new details, get the supplier to confirm receipt.
  4. Move your own domain's DMARC to p=reject. This makes it harder to send fake mail as you; on its own it does not stop look-alike domains.
  5. Flag look-alike domains and Reply-To mismatches. Addresses one character away from your suppliers' domains should raise a separate warning.
  6. Log who does what on shared mailboxes. You should know who opened a request in accounts@ and how they replied.
  7. Put sensitive outgoing mail through approval. A payment confirmation or a reply containing bank details should not leave on one person's initiative; our email approval workflow guide shows how to set this up.
  8. Write down the incident playbook. Who calls the bank, how correspondence is preserved, and how a notification under KVKK (Türkiye's Personal Data Protection Law, the local counterpart of GDPR) is assessed if personal data is involved — all decided in advance.

How we handle this at Digital Bridge

We solve this by working on process and infrastructure together, not just by installing software:

  • We map where you stand. As part of our cyber security consultancy we review your domain's SPF, DKIM and DMARC records, the permission structure of your shared mailboxes and the approval steps in your payment process.
  • We put the payment process in writing. With your finance and procurement teams we define which channel verifies a bank change, who approves it and what happens if something goes wrong.
  • We cover the data protection side. If a successful attack could expose correspondence containing personal data, our data protection compliance work prepares your breach notification and record-keeping procedures.
  • We train with realistic scenarios. Phishing and BEC awareness sessions use examples modelled on your own supplier names.

What SmartMail does in this scenario

SmartMail, the business email product in our own Smart360 family, asks those missing questions on every incoming message. Each email is assessed on 12 signals: its own SPF/DKIM/DMARC and PTR checks, look-alike and international-character domains, display-name and brand impersonation, Reply-To and link mismatches, risky attachments, content assessment and comparison with known fraud techniques.

The result is not just a score but a report with written reasoning, so the person in accounts sees something concrete — "the domain imitates a known contact and the reply address differs" — before a payment is made. Your organisation sets the quarantine threshold (the default trust threshold is 70), and before you change it SmartMail shows how many messages the change would affect. Authentication and domain checks run in software and keep working even when the AI allowance is used up.

The second layer is send approval: a payment confirmation leaving on the organisation's behalf can be put to one or more approvers first — approve, request a revision with a reason, or reject, each step time-stamped. On shared mailboxes access is split into nine separate permissions; deletion and quarantine management are off by default for new assignments, and every message carries its own action history. Attachment analysis pulls the parties, due date, grand total, document number and tax number out of an invoice PDF without downloading the file, which makes it easy to compare against the supplier record.

Next step

Start with a simple exercise: list the bank change requests your accounts mailbox received in the last three months and how each was verified. Then get in touch — we will review your domain records with you and demonstrate SmartMail's security analysis and approval flow in an environment set up with your own addresses.

Let us look at your case

Tell us about your process; after a needs analysis we send a written proposal with scope, phases and cost.

Request a Quote +90 552 380 25 25
Questions we hear most often

Frequently Asked Questions

How can I tell whether a bank change email is genuine?

Check the sender address character by character, see whether the Reply-To matches the sender, and confirm with the supplier by calling the number held in your own records. The phone number in the email may belong to the attacker; a bank change should never be accepted by email alone.

We have a DMARC record. Are we still at risk?

Yes. DMARC stops others sending mail as your domain, but if the attacker writes from their own look-alike domain, that domain's DMARC passes too. Look-alike domain, Reply-To and content checks are needed on top.

What should we do if a payment has already been made?

Call your bank immediately and ask for the transfer to be recalled or frozen at the receiving bank, keep all correspondence and report it to the authorities. If personal data was involved, assess your obligations under KVKK, which requires notifying the Board without delay and within 72 hours at the latest of becoming aware of a breach (KVKK 2025 Annual Report, Board Decision 2019/10).

What if the supplier's real mailbox has been compromised?

Then the email comes from the correct address and the technical checks pass. What protects you is the process: phone verification of the change, two-person approval and a receipt check after the first payment. Content assessment can still flag a message that talks about changed payment details.

Does SmartMail work with our existing domain?

Yes. Domains and DNS settings are managed from the Smart360 admin panel; there is nothing to install, and the account opens as soon as payment is confirmed.

Have a different question? Ask Us

Talk to an Expert

Ready to Build Your Custom Solution?