Bank detail change email fraud is when an attacker impersonates one of your suppliers, announces that "our bank account has changed", and your next payment lands in the fraudster's account. These emails usually get past spam filters because the attacker writes from a domain they control, so SPF, DKIM and DMARC all pass. The defence is a payment process that verifies any change outside email, combined with an email platform that separately flags look-alike domains and messages about changed payment details.
What actually happens on the finance desk
Your accounts team receives dozens of supplier emails a day. One of them reads: "Our bank account has changed; please make this month's payment to the new account details attached." The display name is familiar, so is the signature, and the invoice number is right. Sometimes the message even appears to continue a real thread. In the month-end rush the payment run is prepared, the new IBAN goes into the supplier record and the money leaves. The mistake typically surfaces weeks later, when the real supplier calls to ask why they have not been paid.
This is payment diversion fraud, a form of Business Email Compromise (BEC). What sets it apart from ordinary phishing is that it usually carries no malicious link or attachment and is written in completely routine business language. That lets it slip past the filter and a careful employee at the same time.
The cost of leaving it unsolved
There is no regular public statistic on BEC losses in Türkiye; the most detailed data comes from the United States, and the picture is clear:
According to the FBI's Internet Crime Complaint Center (IC3), 24,768 business email compromise complaints in the US reported total losses of $3.05 billion in 2025. (FBI IC3 2025 Internet Crime Report)
The sums being requested are growing too. According to the APWG Phishing Activity Trends Report for Q2 2026, the average amount requested in wire-transfer BEC attacks rose to $61,732, up 45% on the previous quarter. For a small or mid-sized business, one successful email can knock a month's cash flow off course.
The data also shows why filters miss it. According to the Verizon 2026 Data Breach Investigations Report, 80% of attacks blocked by email security gateways were plain phishing, while only 3% were BEC-style emails trying to get the victim to update a bank account ahead of a wire transfer. Gateways mostly catch the crude attacks; the quiet, targeted ones are a small slice of what they stop.
Once money has gone, hours matter. The FBI IC3 2025 report says its Recovery Asset Team initiated 3,900 incidents in 2025 involving $1.16 billion in attempted theft and froze $679 million of it (a 58% success rate), stressing that "time is of the essence" once a fraudulent transfer is discovered. Acting fast depends on everyone knowing, in advance, whom to call and how.
How the attack is built, step by step
The attacker does not need to break into your systems. The usual sequence is:
- Pick the counterparty. Your website, reference lists, LinkedIn or previously leaked correspondence reveal which suppliers you work with.
- Register a look-alike domain.
example-logistics.combecomesexample-logistlcs.com(an l for an i), or an address using international characters that looks identical. - Configure authentication properly. It is the attacker's own domain, so SPF, DKIM and DMARC are set up perfectly.
- Time it. Month end, the invoicing period, or the week the real supplier sends a genuine invoice.
- Send the request. Short and urgent — "our bank details have changed", "our account is frozen, please pay into this one" — or a copy of the genuine invoice PDF with the IBAN swapped.
In some cases the attacker takes over the supplier's real mailbox, so the email comes from exactly the right address. That is why technical checks alone are never enough and process controls are essential.
Why the spam filter lets it through
Spam filters essentially ask two questions: does the sender prove who they are? and does the content look like known spam? In this attack both answers reassure the filter.
| Check | Classic spam | Bank detail change email |
|---|---|---|
| SPF / DKIM / DMARC | Often fails | Passes (attacker's own domain) |
| Bulk sending | Yes | No, a single recipient |
| Links / malicious attachment | Common | Often none — plain text or a clean PDF |
| Spam wording | Present | None, ordinary business language |
| Reply address | Irrelevant | Often a different Reply-To |
The problem is not a bad filter; it is a filter looking in the wrong place. Catching this attack means adding three questions to "is this email technically valid?": does the sender's domain imitate a known counterparty, are replies being redirected elsewhere, and does the message talk about a change in payment details? We cover the domain tricks in our guide to look-alike domain attacks and the invoice variant in fake invoice email scams.
An eight-step control framework for your finance team
- Never confirm a bank change by email. Call the supplier on the number held in your own records — not the one in the email.
- Require two people for any change. The person who enters the new IBAN in the supplier record and the person who approves it should be different.
- Watch the first payment. After the first transfer to new details, get the supplier to confirm receipt.
- Move your own domain's DMARC to
p=reject. This makes it harder to send fake mail as you; on its own it does not stop look-alike domains. - Flag look-alike domains and Reply-To mismatches. Addresses one character away from your suppliers' domains should raise a separate warning.
- Log who does what on shared mailboxes. You should know who opened a request in
accounts@and how they replied. - Put sensitive outgoing mail through approval. A payment confirmation or a reply containing bank details should not leave on one person's initiative; our email approval workflow guide shows how to set this up.
- Write down the incident playbook. Who calls the bank, how correspondence is preserved, and how a notification under KVKK (Türkiye's Personal Data Protection Law, the local counterpart of GDPR) is assessed if personal data is involved — all decided in advance.
How we handle this at Digital Bridge
We solve this by working on process and infrastructure together, not just by installing software:
- We map where you stand. As part of our cyber security consultancy we review your domain's SPF, DKIM and DMARC records, the permission structure of your shared mailboxes and the approval steps in your payment process.
- We put the payment process in writing. With your finance and procurement teams we define which channel verifies a bank change, who approves it and what happens if something goes wrong.
- We cover the data protection side. If a successful attack could expose correspondence containing personal data, our data protection compliance work prepares your breach notification and record-keeping procedures.
- We train with realistic scenarios. Phishing and BEC awareness sessions use examples modelled on your own supplier names.
What SmartMail does in this scenario
SmartMail, the business email product in our own Smart360 family, asks those missing questions on every incoming message. Each email is assessed on 12 signals: its own SPF/DKIM/DMARC and PTR checks, look-alike and international-character domains, display-name and brand impersonation, Reply-To and link mismatches, risky attachments, content assessment and comparison with known fraud techniques.
The result is not just a score but a report with written reasoning, so the person in accounts sees something concrete — "the domain imitates a known contact and the reply address differs" — before a payment is made. Your organisation sets the quarantine threshold (the default trust threshold is 70), and before you change it SmartMail shows how many messages the change would affect. Authentication and domain checks run in software and keep working even when the AI allowance is used up.
The second layer is send approval: a payment confirmation leaving on the organisation's behalf can be put to one or more approvers first — approve, request a revision with a reason, or reject, each step time-stamped. On shared mailboxes access is split into nine separate permissions; deletion and quarantine management are off by default for new assignments, and every message carries its own action history. Attachment analysis pulls the parties, due date, grand total, document number and tax number out of an invoice PDF without downloading the file, which makes it easy to compare against the supplier record.
Next step
Start with a simple exercise: list the bank change requests your accounts mailbox received in the last three months and how each was verified. Then get in touch — we will review your domain records with you and demonstrate SmartMail's security analysis and approval flow in an environment set up with your own addresses.