Docket fraud shield: a payment-diversion email claiming updated bank details, scored 98 out of 100 for risk and blocked before payment.
Fraud shield — a payment-diversion attempt held before the money moved.

Payment diversion fraud: the fake bank-account-changed email

Payment diversion fraud is business email compromise aimed at an import payment. An attacker impersonates your exporter or bank and asks you to wire to a new account, timed to a real invoice so it looks routine. Four signals give it away: a look-alike domain, a bank change mid-deal, a beneficiary that is not the contract party, and urgency. The control that works: a callback on a stored number.

Payment diversion fraud
A business email compromise scam in which an attacker impersonates a trusted counterparty and redirects a legitimate payment to an account they control, usually by announcing a change of bank details mid-deal.

This is the one that takes real money, in one transaction, from a desk that was doing nothing unusual. There is no malware to find, no system to restore, and no insurance claim that goes smoothly. A person on your team authorised a payment they were supposed to authorise, to an account they were not supposed to use.

How does payment diversion fraud work?

The attacker does not break into anything. They watch, or they guess, and they arrive at exactly the right moment: after a contract is agreed, when an invoice is genuinely due.

Then an email lands from what looks like your exporter. The regular banking channel is under a compliance audit, or the account is being restructured, or there is a temporary hold with the correspondent bank. Please remit to the alternate account instead. Treat as urgent and confidential.

Everything about it is plausible because everything about it is true except the account number. The shipment is real. The invoice is real. The amount is right to the cent. The signature block, the logo, the way the sender writes “kindly revert” are all correct, because the attacker has been reading the thread.

The sequence, in the order it actually happens:

1/ Access. A mailbox somewhere in the chain is compromised, usually the smaller party’s and usually through a reused password. It does not have to be yours. Your exporter’s shipping clerk is enough.

2/ Observation. Weeks of silence. The attacker reads the thread, learns the shipment cycle, the payment terms, the names, the tone.

3/ Positioning. A look-alike domain is registered, or a mail rule is created that quietly moves the real replies to a folder nobody opens.

4/ The ask. One email, at the right moment in the cycle, with new banking details.

5/ The cover. If you reply to verify, the reply goes to the attacker, who confirms warmly and provides a phone number that also belongs to them.

6/ The exit. The money lands in a mule account, is moved within hours, and is gone.

The four signals

One such attempt on a single shipment was worth US$62,500. These were the signals that gave it away, and they generalise — they are the same four Docket screens every inbound email for.

1/ Look-alike sender domain. In that case the mail came from a domain registered six days earlier, one character different from the exporter’s real domain of many years. Nobody reads the domain closely on the fortieth email of a working day.

2/ Bank details changed mid-deal, and to the wrong country. A new Hong Kong account for an exporter based in Oman, when originals were already lodged with the bank against the Oman account.

3/ Beneficiary name does not match the contract party. The money was requested for a company that was not the exporter named on the shipment.

4/ Urgency and secrecy. “Urgent, confidential, confirm today.” Genuine banking changes are boring, documented, and never in a hurry.

Any one of these deserves a pause. Two together is close to conclusive.

What are the variants, and how do you tell them apart?

Four shapes, one outcome. The shape decides which control catches it.

VariantWhat the attacker controlsThe tellWhat catches it
Look-alike domainA newly registered domain one character off yours or theirsDomain age, character substitution, reply-to differing from senderDomain screening on every inbound mail
Thread hijack from a compromised mailboxThe real mailbox, the real domain, the real historyNothing in the headers. Only the content is wrongCallback on a number you already had
Supplier compromise upstreamYour supplier’s actual account and their outbound invoicesThe bank change itself, and the beneficiary nameBank details matched to the contract party
Impersonation of a service provider, CHA, forwarder or bankA plausible third party in the chainA payment instruction from a party who never invoiced you beforeA named payee list per counterparty

The second row is the dangerous one. Everything in the message is genuine, including the sending address, because the attacker is sitting inside the real mailbox. Domain checks do not see it. Signature-based email security does not see it. The only thing that catches a thread hijack is a verification path the attacker does not control.

The control that actually works

Call back on a number you already have.

Not the number in the email. Not the number in the signature block of the email announcing the change. A number from the contract, from your own records, from the last time you spoke to them. The entire scam depends on your verification path running through a channel the attacker controls. Break that, and the scam has nothing left.

Everything else is useful and none of it survives a busy Friday afternoon on its own.

ControlCatchesFails whenCost to run
Callback on a stored numberEvery variant, including thread hijackNobody makes the callTwo minutes, per change
Bank details fixed in the contract, changes by signed addendum onlyMid-deal switchesA genuine change is needed and the process is slow, so somebody bypasses itOne clause
Beneficiary name matched to the contract partyMismatched payeeThe attacker registers a company with a similar nameOne check at payment entry
Domain-age and look-alike screeningNewly registered spoof domainsThe mailbox itself is compromisedAutomated
Dual authorisation above a thresholdCareless single approvalsBoth approvers see the same forged emailSlows every payment
Verification of payee at the bankName-account mismatch, where the corridor supports itCross-border payments outside schemes that offer itBank-side

That last row is moving. The EU Instant Payments Regulation, Regulation (EU) 2024/886, requires payment service providers to offer a verification-of-payee check on credit transfers, and the UK has run Confirmation of Payee through Pay.UK for years. Both help. Neither covers most of the corridors an importer in Singapore or Dubai actually pays into, which is why the callback stays first on the list.

Why are import desks exposed?

Six to ten parties touch a single shipment: exporter, CHA, bank, shipping line, forwarder, insurer, transporter, inspection agency. Payment instructions legitimately arrive by email from several of them, in several currencies, on several schedules.

There is no portal, no single system of record, and no one person whose job is to notice that this particular message is different from the last forty. The desk that pays the invoice is the desk that is also chasing the certificate of origin, the delivery order and the bank release, on a container that is already accruing demurrage.

That pressure is the attack surface. Docket’s operational baseline puts about 2.2 hours of desk work on a single container, with a 500-container desk consuming about 1,100 hours a month against 1,232 available hours across seven people. The desk runs at roughly 90% capacity on routine work. A team at 90% does not read the domain on the fortieth email. It processes it.

An LC amendment request is exactly the shape this attack takes. So is a request to reissue a bill of lading to a different consignee. So is a courier tracking number for originals that were never sent. The fraud does not need a new disguise. It borrows the ones the trade already uses.

What do you do in the first hour after the money has gone?

Speed is the only variable you still control.

Call your bank and ask for a recall immediately. Not an email. The window in which funds can be frozen is measured in hours, and it closes when the mule account is emptied.

Ask the receiving bank’s country regulator or police unit to act. In the US the FBI’s IC3 Recovery Asset Team runs a process for exactly this and works with the receiving institution. Singapore’s police anti-scam unit runs an equivalent line. Report through the official channel, not through a lawyer’s letter that arrives next week.

Preserve the mailbox. Do not delete the email, do not clean the mailbox, and do not let IT reimage the machine before the headers are exported. The full headers and the mail rules are the evidence.

Check for the mail rule. If the compromise is on your side, there is almost always a rule quietly filing the real counterparty’s replies somewhere you do not look. Find it before you tell the counterparty anything, because the attacker may be reading that too.

Call the counterparty on a stored number. They may be the compromised party and may not know it, and their next customer is about to get the same email.

Tell your insurer the same day. Crime and cyber policies carry short notification windows, and a claim reported late is a claim argued about.

Common misconceptions

“Our email is secure, so we are covered.” Most of these attacks never touch your mailbox. They touch a supplier’s, and everything that arrives at you is authentic.

“We would spot a fake domain.” The US$62,500 attempt used a domain registered six days earlier, one character off. It passed several readers before anyone questioned it.

“The bank will get it back.” Sometimes, within hours, through a recall process. After a day, rarely.

“Dual authorisation solves it.” Two people looking at the same forged email reach the same conclusion twice.

“It only happens to big transfers.” It happens at whatever size your desk pays without a second thought, which is the exact amount the attacker has been reading about for six weeks.

“We will train people to be careful.” Careful is not a control. A stored phone number is a control.

Where Docket sits

Docket is not an email security product, does not sit in your mail flow as a gateway, and does not stop your bank from executing a payment you authorise. If you decide to wire the money, it goes.

What Docket does is screen every inbound email on a shipment against the four signals above, which is what trade fraud screening software means here, check the payment instruction against the contract party and the bank account already on file, and hold the payment when something does not line up, with the reason spelled out rather than a generic warning banner nobody reads. It knows the contract party, because it read the contract. It knows the account on file, because it recorded the first one. It knows the shipment is at the stage where a payment is genuinely due, which is what makes a mid-deal bank change stand out instead of blend in.

That is the shape of the US$62,500 attempt: a mid-deal bank change, on a real shipment, at a moment a payment was genuinely due. Docket pauses the wire on that pattern and asks the desk to confirm with the exporter on their verified number — before the money moves, not after. On a Tuesday, on a desk doing nothing unusual.

The screening runs on the same inbound mail that Docket is already reading to chase documents. One pass, two jobs. The chase is what pays for the shield.

Sources

  1. FBI Internet Crime Complaint Center (IC3), business email compromise guidance
  2. FBI IC3 Recovery Asset Team, financial fraud kill chain process for fraudulent wire recall
  3. Regulation (EU) 2024/886 (Instant Payments Regulation), verification of payee on credit transfers
  4. Pay.UK Confirmation of Payee scheme
  5. SWIFT Customer Security Programme (CSP) controls framework
  6. Reported incident, import–export desk: one payment-diversion attempt