All insights
Payment operations · Wires

What Is Payment Diversion Fraud?

By James Pickren, Operations Coordinator at Coffr

Reviewed by Marc Pickren, President of Coffr

Published
October 5, 2026
Read
8 min
Diagram of payment diversion fraud: a company's payment is diverted past the vendor's bank to a fraudster's bank

Payment diversion fraud is when a criminal tricks a business into sending a payment to a fraudulent account while posing as the intended recipient. The criminal often poses as a supplier, executive or employee and sends "updated" bank details, so the business assumes it is safe.

You will see it go by business email compromise (BEC), [vendor impersonation fraud](/glossary/vendor-impersonation) or bank detail change fraud. The FBI tracks it as part of BEC.

How payment diversion fraud works

Most attacks follow the same five steps.

  1. Research. The criminal learns who your vendors are through publicly available information online or hacked accounts on either your side or the vendor's. (Construction is often targeted due to lots of information about vendors being available through permits and public filings.)
  2. Access or impersonation. A criminal will set up a lookalike domain or get access to a vendor's real email account.
  3. The request. A message will arrive asking you to update their banking details, or sending a corrected invoice with the wrong details.
  4. The payment. Someone on your team will send the payment to the wrong bank account, assuming it's the correct one.
  5. Discovery. Eventually the vendor will ask where their money is, and by this point it's too late.

In one case a client mentioned, a vendor requested a bank detail update through an email. Three people checked the email and confirmed it was safe. Minutes before the payment went out, the CFO checked the email again, saw that the email address was one letter off from their contact at the company, and saved $289,000 from being sent to a criminal. Even companies with a review process are still at risk. Three people approved this change, and it came down to one person catching a single letter at the last minute.

Common types of payment diversion fraud

Payment diversion fraud is very sneaky, but there are only a few ways it can appear.

  • Vendor bank detail change. A vendor changes banks and asks you to change it by email. This is the most common.
  • Fake or altered invoice. A real-looking invoice arrives with the criminal's account details, sometimes a copy of a previously sent one. This is especially dangerous with new vendors whose bank details you haven't received yet.
  • Executive impersonation. A message from an exec requesting an urgent payment or asking you to change where a payment goes on behalf of a vendor.
  • Payroll diversion. Someone posing as an employee asks HR or payroll to send their salary to a new account.

Payment diversion fraud vs. BEC and other terms

These names overlap heavily. Which one you hear mostly depends on who is reporting it.

TermMostly used byWhat it covers
Payment diversion fraudGeneral and search useAny scheme that redirects a payment to a criminal's account
Business email compromise (BEC)FBI, banks, security teamsEmail-based impersonation to steal money or data, including diverted payments
Vendor impersonation fraudFinance and AP teamsA criminal posing as a supplier to redirect payments
Bank detail change fraudFinance and AP teamsA fake request to change a payee's bank account
Invoice fraudFinance and AP teamsFake or altered invoices carrying the criminal's account details

How common is payment diversion fraud?

In the US, it is one of the most expensive frauds businesses face. The FBI's Internet Crime Complaint Center (IC3) recorded 24,768 business email compromise complaints in 2025, with $3.05 billion in reported losses, an average of about $123,000 per complaint (FBI IC3 2025 data). Those are only the cases reported to the FBI.

It is also getting more common. In the 2026 AFP Payments Fraud and Control Survey, 74% of organizations said they were hit by BEC in 2025. AFP also reports that vendor impersonation is rising while classic fake-CEO emails are declining (U.S. Bank summary).

Warning signs

Any request to change bank details should be treated with caution. Watch out for:

  • A supplier announcing new bank details by email, especially just before a large payment is due
  • An email address that is one character off from the real one, or a reply-to address that differs from the sender
  • Pressure to pay quickly or keep the request confidential
  • A new account in a different name, city or country than the supplier
  • An invoice that matches a real one except for the bank details
  • A request that arrives mid-thread in an otherwise normal conversation
  • Instructions to ignore the usual approval process "just this once"

How to prevent payment diversion fraud

The single most effective way is to verify the vendor before any money moves. That means confirming the person, company and bank account are all real and that the account belongs to them, while keeping an audit trail of every change. This is what Coffr does for every new or changed vendor account.

Other ways to help are:

  1. Call back on a number you already have. Use the number in your vendor master file or on an old contract, never one in the email or invoice asking for the change.
  2. Verify who owns the account. A callback confirms the request; it does not prove the new account belongs to the supplier. [Account ownership verification](/glossary/account-validation) confirms the account holder matches the supplier before you pay.
  3. Require two people for any bank detail change. One person updates the record, a second approves it.
  4. Send a test payment. Send a small amount of money and call your original contact to confirm they received it.
  5. Hold the first payment. Put a short hold on the first payment to any new or changed account, and confirm with the supplier once it lands.
  6. Lock down the vendor master file. Limit who can edit bank details and log every change. Better still, have vendors submit bank details through a secure portal, as they do with Coffr, so changes never arrive by email at all.
  7. Secure email. Turn on multi-factor authentication and set up email authentication (SPF, DKIM and DMARC) so your domain is harder to spoof.
  8. Train the people who pay. Accounts payable, treasury and payroll staff should know these warning signs and feel safe slowing a payment down.

What to do if it happens

Speed decides whether the money comes back. In 2025, the FBI's Recovery Asset Team froze $679 million of the $1.16 billion it was asked to stop, a 58% success rate, and its process works best when fraud is reported within 72 hours (Credit Union Connection on IC3 data).

  1. Call your bank immediately. Ask for a wire recall or ACH return and for the bank to contact the receiving bank's fraud team.
  2. Report it to the FBI at ic3.gov with the transaction details. US businesses can trigger the Recovery Asset Team this way.
  3. Tell the real supplier, using a number you already trust, and stop any other payments to the new account.
  4. Secure the email accounts involved. Reset passwords, check for forwarding rules you did not set up and preserve the original messages.
  5. Review what failed. Find which control was skipped and fix it before the next payment run.

This is general information, not legal advice. Talk to your bank and counsel about your specific situation.

If you feel like you are never sure if vendors are actually sending the right details, [book a demo](/demo) with Coffr today.

Frequently asked questions

Is payment diversion fraud the same as business email compromise?

Mostly, yes. Payment diversion fraud describes the outcome: a payment sent to the wrong account. Business email compromise describes the method: impersonation by email. Most payment diversion fraud starts with BEC.

Can you get the money back?

Sometimes, if you act fast. Call your bank to request a recall and report to ic3.gov right away. The FBI's Recovery Asset Team froze 58% of the funds it was asked to stop in 2025, but its chances drop sharply after 72 hours (FBI IC3).

Who is most at risk?

Any business that pays suppliers by wire or ACH. Accounts payable, treasury and payroll teams are the main targets because they can change bank details and release payments.

How do you safely verify a vendor's new bank details?

Call the vendor on a number you already have, never one from the request. Then confirm the new account is actually owned by the vendor, and have a second person approve the change.

Is a callback enough on its own?

No. A callback confirms the vendor made the request. It does not confirm the account belongs to them, and if the vendor's own email was hacked, the details they give may already be the criminal's. Verifying account ownership closes that gap.

About the author

James Pickren

Operations Coordinator at Coffr

James Pickren covers payment fraud for Coffr, researching real fraud cases and working with finance teams on how they verify vendor payments.

LinkedIn

How we research and correct our work: editorial standards · all questions answered

Share and cite

XLinkedInRedditEmail

Community newsletter

The Trust Layer Briefing

CFOs, controllers, and AP leaders subscribe for weekly research on BEC vectors, ERP gaps, and payment instruction security.

One email each Thursday. No spam, one-click unsubscribe.