SEC Warns About Vendor Payments: How to Prevent Payment-Redirection Fraud

A real invoice can still send your money to a criminal. Learn what the SEC’s vendor-payment fraud warning means and why verifying bank-account changes matters.

A legitimate invoice can still lead to a fraudulent payment. The purchase may be authorized, the amount correct, and the supplier familiar. But if someone changes the destination account, your business can pay the criminal while still owing the vendor.

Consider a hypothetical example: Accounts payable receives an email in an existing supplier conversation announcing new banking instructions. The message references a real invoice and arrives shortly before payment is due. An employee updates the vendor record and releases the funds. Only later does the supplier ask why its invoice remains unpaid.

That is the control failure behind the SEC’s warning about vendor-payment fraud. The warning dates to 2018, but its lesson remains current: approving an invoice and approving where the money goes are separate decisions.

A credible message can initiate a payment-change request. It should not be the only evidence that authorizes the change.

What the SEC Actually Warned About

On October 16, 2018, the SEC announced an investigative report examining nine public companies that fell victim to business email compromise, or BEC. Together, they lost nearly $100 million. Each lost at least $1 million, and most of the money was not recovered. The SEC brought no charges against those companies or their personnel in the investigations, according to its announcement.

The schemes involved criminals impersonating executives or vendors. In the vendor cases, attackers compromised suppliers’ email accounts and inserted fraudulent payment instructions into legitimate business communications.

The SEC’s investigative report emphasized existing internal-accounting-control obligations under Section 13(b)(2)(B) of the Securities Exchange Act. Controls needed to account for cyber-enabled fraud and operate effectively—not simply exist in a policy document.

This was not a new rule requiring every business to follow one prescribed callback procedure. The legal discussion concerned covered public issuers. Private businesses can nevertheless apply the same operational lesson: payment controls must withstand convincing impersonation.

Why Vendor-Payment Fraud Remains a Current Risk

The FBI’s 2025 IC3 Annual Report records 24,768 BEC complaints and approximately $3.05 billion in reported losses. Those figures cover BEC broadly, not only vendor-payment fraud, and reflect complaints received rather than every incident that occurred.

The threat extends beyond poorly written messages from unfamiliar addresses. The FBI’s BEC guidance describes look-alike addresses and compromised accounts that make requests appear legitimate. Its 2025 report also describes AI-generated messages and voice cloning used in BEC. A polished email or familiar-sounding voice is not sufficient proof of authorization.

Nor is switching from wires to ACH a complete solution. FinCEN’s BEC advisory documents multiple payment methods. The central question remains whether the intended supplier controls the destination account.

A Practical Process for Verifying Vendor Banking Changes

The following workflow is a recommended control design, not a claim that the SEC mandates each step.

1. Separate Payment-Destination Approval From Invoice Approval

Require a distinct review for new vendor banking details and changes to existing instructions. Cover account numbers, routing numbers, beneficiary names, payment methods, and remittance addresses. Protect changes to vendor contact information, too: a criminal who replaces the verification number can undermine the next callback.

During onboarding, establish authorized contacts and backup contacts through independently validated channels. Do not let an email attachment automatically update the vendor master record.

2. Verify Through a Previously Established Channel

Call an authorized vendor representative using a number already held in a trusted record—not one supplied solely in the change request, attachment, or new signature block. Confirm both that the vendor requested the change and the specific destination details.

The FBI recommends using previously known telephone numbers to verify payment changes. Replying to the same email thread is not independent verification if an attacker controls that mailbox.

For example, if a supplier announces both a new bank account and a new phone number, do not use the new number to validate the new account. Reach the existing contact or another previously established representative. If neither is available, leave the change pending and escalate internally.

3. Make the Second Approval Meaningful

A second authorized person should review the verification evidence and destination details before approving the change. Two people reading the same fraudulent email do not provide two independent checks.

Separate vendor-record maintenance from payment release where practical. In a small business, an owner or authorized manager can review banking changes before the bookkeeper uses them. That is a practical compensating measure, not a substitute for every benefit of full separation of duties.

4. Preserve Evidence and Test the Process

Keep a restricted-access record of the original request, the contact reached, the source of the callback number, the details confirmed, the verification date, and the independent approver. Record any exception and its authorization. Avoid spreading sensitive banking information through unnecessary email copies.

Periodically sample completed changes. Did verification happen before payment? Was the callback number independent of the request? Did the approver examine evidence? The SEC’s report shows why these questions matter: documented procedures did not prevent losses when employees misunderstood or failed to follow them.

Technology Helps, but It Does Not Authorize a Payment

Protect business email, finance systems, and vendor portals with multifactor authentication. CISA recommends aiming for phishing-resistant MFA. Prioritize administrators and employees who handle payments or sensitive information.

Also restrict who can change vendor records and monitor unusual account activity. Where supported, configure workflows that prevent one person from changing banking details and immediately releasing a payment.

Account security and transaction authorization solve different problems. MFA can reduce account takeover risk, but it cannot prove that a supplier’s request is legitimate—especially when the supplier’s own account has been compromised. Likewise, a small test payment only demonstrates that funds can reach an account; it does not independently establish who controls it.

Manage Friction Without Creating a Bypass

Verification adds work. Design that work explicitly rather than expecting employees to improvise under pressure.

  • Urgent payments: Maintain backup vendor contacts and a documented escalation route. Urgency should accelerate review, not eliminate it.
  • High transaction volumes: Concentrate additional scrutiny on onboarding and destination changes while preserving ordinary invoice controls for established payments.
  • Small teams: Use owner or manager review and retain evidence of that review.
  • Executive pressure: Apply verification regardless of seniority and explicitly authorize employees to pause suspicious instructions.
  • Payment deadlines: Explain verification requirements to vendors during onboarding so a legitimate banking change does not become a last-minute surprise.

These are implementation choices, not a regulatory safe harbor. Their value depends on whether they operate consistently.

What to Do If Money Has Already Been Sent

Contact the Bank Immediately

Call your financial institution’s fraud team and request an urgent recall or reversal and coordination with the receiving institution. Ask what documentation, including any indemnification paperwork, is required. Do not wait for the internal investigation to finish.

The FBI’s recovery guidance emphasizes prompt action. Procedures vary by institution and payment method, and a recall request does not guarantee recovery.

Report, Preserve, and Contain

File a complaint with the FBI’s Internet Crime Complaint Center. Preserve original emails, headers, invoices, payment confirmations, recipient banking details, and a timeline. Contact the vendor through a trusted channel, pause related payment changes, and involve finance leadership, security, counsel, and your insurer as appropriate.

Have authorized responders investigate whether your email environment, the vendor’s, or both were compromised. For Microsoft 365, Microsoft’s response guidance includes resetting credentials, revoking sessions, reviewing MFA methods and application consent, and checking forwarding and inbox rules. A password reset alone is not a complete response.

Vendor-Payment Verification Checklist

Use this suggested checklist for new or changed payment instructions:

  • Has the invoice and underlying purchase been approved?
  • Has the payment destination been reviewed separately?
  • Was the vendor contact independently validated during onboarding?
  • For a change, was verification completed through a previously established contact?
  • Was the callback number independent of the change request?
  • Did an authorized vendor representative confirm the destination details?
  • Did a second authorized person review the verification evidence?
  • Are the request, verification, and approval recorded securely?
  • Were urgency and executive pressure prevented from bypassing controls?
  • Do employees know how to pause payment and reach the bank’s fraud team?

Make the Destination a Separate Decision

The lasting lesson of the SEC’s warning is not to distrust every supplier. It is to avoid confusing a persuasive communication with payment authorization.

This week, assign an owner to vendor-payment verification and review a sample of recent banking changes. Confirm that independent verification and meaningful approval happened before money moved. If the process depends on someone noticing a suspicious email, strengthen the process—not just the training.

Browse all insights · Contact Bart McDonough