Payment Diversion Fraud
Payment diversion fraud redirects a legitimate payment to an account controlled by a fraudster. It commonly involves altered invoices, compromised communications or false instructions announcing a change in beneficiary bank details.
Also called: invoice redirection fraud · mandate fraud
Payment diversion fraud, also called invoice redirection or mandate fraud, does not trick the buyer into paying for something that does not exist. The goods and the debt are real; only the destination of the money is changed. A fraudster who has seen or guessed the trading relationship sends a convincing notice that the supplier's bank account has changed, or alters the bank details on a genuine invoice, and the buyer pays the next installment into an account the fraudster controls.
International supplier payments are a frequent target because the parties communicate by email across time zones and languages, invoices arrive as attachments, and a change of bank is plausible. The new account may sit in a different country from the supplier, or in the name of an individual or an unrelated company, which is exactly the kind of beneficiary-account mismatch that should stop a payment. The fraud is often discovered only when the real supplier chases an unpaid invoice.
The most effective defense is procedural. Any change of bank details should be confirmed by telephone using a number already on file, never one supplied in the change request, and approved by a second person. Paying only the contracting legal entity, checking the account name, and holding new details for a short verification period all reduce the risk. If money has been sent, ask the sending bank immediately for a payment recall and report the fraud.
In practice
Recovery after a diverted payment is uncertain and gets harder by the hour. Verifying changed bank details through an independent channel before paying is far more effective than any action taken afterwards.
Example
Hypothetically, an importer receives an email that appears to come from its Dongguan supplier, saying the company has moved its account to a new bank in another country and attaching an updated invoice for the US$75,000 balance. The importer calls the supplier's sales manager on the number in its records, learns that no change was made, and pays the original account instead.
Commonly confused with
| Term | How it differs |
|---|---|
| Business email compromise | Business email compromise is a method of attack using a spoofed or hijacked email account. Payment diversion fraud is the result: a genuine payment redirected to the wrong account, by email or any other channel. |
See also
- Business Email CompromiseBusiness email compromise is a fraud in which an attacker impersonates or takes control of a business email account to manipulate payments or obtain sensitive information. Independent verification of changed bank instructions is one of the most important defenses.
- Beneficiary-Account MismatchA beneficiary-account mismatch occurs when the account holder’s name does not agree with the expected supplier or contractual payee. It can indicate a clerical error, undisclosed collection arrangement, payment-diversion fraud or an unrelated third party.
- Third-Party BeneficiaryA third-party beneficiary is a person or company receiving payment despite not being the seller or invoice issuer. The arrangement may be legitimate, but its contractual role and entitlement to receive the funds should be documented and accepted by the relevant institutions.
- Payment RecallA payment recall is a request by the sending institution to recover or stop a transfer after it has been released. A recall is not guaranteed because the funds may already have been credited, withdrawn or made subject to the beneficiary bank’s procedures.
