Supplier bank-detail change requests are one of the highest-value social engineering paths into accounts payable, and teaching staff to verify them is still the control that stops the wire after filters fail.
Key takeaways
- Treat every supplier bank-detail change as fraud until a verbal call-back on a number already in the vendor master confirms it.
- The FBI IC3 2025 Annual Report logged $3.05 billion in business email compromise losses across 24,768 complaints — bank-change scams sit inside that pile.
- Finance, AP clerks, and anyone who edits vendor masters get the first 30 days of training.
- Run three bank-change simulations in 30 days, then sample five live change requests each month.
- Measure call-backs completed, not training certificates alone.
Why this matters
Attackers do not need malware when a polite email from a compromised supplier inbox can re-point the next invoice. The message looks routine. The invoice number matches. Only the BSB and account digits changed.
In 2026, organisations that train the whole company on generic phishing still lose on bank-detail scams because the people who edit vendor masters never practised a call-back. Pair security awareness training with a non-negotiable verification rule and you finally have a behaviour you can score.
Verizon’s 2026 Data Breach Investigations Report found the human element involved in 62% of breaches. Bank-detail fraud is that human element with a payment attachment.
What you will need
- A one-page CFO-signed rule: call a number already stored on the vendor record before any bank change saves
- Named roster of AP, finance controllers, and anyone with vendor-master edit rights
- Three simulation templates built around real invoice language (not direct marketing spoofs)
- Access to phishing simulations for three sends in 30 days
- A shared call-back log (date, vendor, caller, outcome)
- Thirty minutes with each money-mover manager in week one
The steps
1. Freeze the policy before you train anyone
Write one rule in plain language: no supplier bank detail is saved, edited, or paid against until a verbal call-back is logged against a phone number that already exists in the vendor master or procurement file — never against a number in the email or attachment. Have the CFO sign it. Put it on one page on the intranet.
Training without the rule is optional advice. With the rule, training has a pass/fail.
Expected outcome: a signed one-pager dated in 2026 that AP can quote when pressured.
Common mistake: allowing “known supplier” exceptions. Compromised real Outdoor-supplier mailboxes are the whole attack.
2. Map every person who can edit or pay against vendor banks
Export roles with vendor-create, vendor-edit, or payment-release rights. That list — often 10–40 people — is your primary cohort. Broader staff get a lighter awareness later.
Expected outcome: a named roster, not an all-staff blast list.
Common mistake: training sales and skip-level managers at the same depth as AP, which wastes seats and dilutes the drill.
3. Teach the 90-second call-back script
Run a 10-minute lesson covering three patterns only: (1) PDF invoice with new bank details in the footer, (2) email “from” a known AP contact at the supplier asking to update details before Friday’s payment run, (3) lookalike domain that swaps one letter. End by making each person speak the call-back script once out loud.
Cyber Aware short story-led modules work here: one pattern, one quiz, same day.
Expected outcome: 100% of the cohort completes within five business days.
Common mistake: a 40-minute annual fraud video with no spoken practice of the call.
4. Run three bank-change simulations across 30 days
Space sends seven to ten days apart:
- Days 3–5: soft invoice with a subtle domain lookalike and a new account number in the remittance block.
- Days 12–15: mid-morning email during a real payment-run window, spoofing a supplier AP contact, asking for a “temporary” bank update.
- Days 22–25: urgent change tied to a real internal project name drawn from public information only, with a tight two-hour deadline.
Fail → automatic short remediation. Report → short congratulations so the habit sticks.
Expected outcome: click rate falls across three sends; report rate clears 20% by send three.
Common mistake: one ultra-hard send on day one that tanks trust and teaches nothing about the rule.
5. Sample live bank-change tickets every month
After each simulation week, pull five real vendor bank edits or change tickets and check the call-back log. Pair that with simulation report rate in a simple human risk reporting view so QBRs show behaviour, not vanity completion.
Expected outcome: a one-page monthly scorecard: training done, sims reported, live call-backs logged.
Common mistake: celebrating 98% course completion while the call-back log is empty.
6. Close with dual control and a 60-day re-test
Where one person still both edits and releases payment against a new bank, add dual approval above a fixed dollar threshold. Brief managers on who needed remediation. Re-run the hardest template at day 60 on the same cohort.
Expected outcome: one permanent workflow fix plus a dated re-test on the 2026 calendar.
Common mistake: stopping at the certificate folder and never touching vendor-master permissions.
Troubleshooting
AP says call-backs slow month-end. Time five real call-backs. Most clear in under three minutes. Compare that to one redirected wire.
Suppliers refuse phone verification. Your policy still holds. Offer a known-number call initiated by you; never accept a number the supplier just emailed.
Click rates stay flat. Templates are too similar or too obviously fake. Align send three to a real AP calendar day and a real supplier naming pattern.
IT quarantines simulation mail. Whitelist sending domains and IPs before campaign one.
Shared AP mailboxes blur who clicked. Assign simulations to named users, not only the shared inbox alias.
No historical baseline. Treat send one as baseline even if the click rate looks ugly. 20–35% on a first bank-change lure is common in 2026.
Tools and resources
- Short BEC/bank-change lessons and quizzes
- Phishing simulation templates for invoice and bank-update lures
- Human risk scores that fold training, quizzes, and phishing fails per learner
- CFO-signed verification policy and a shared call-back log
- FBI IC3 2025 figures for leadership ($3.05B BEC losses, 24,768 complaints)
- ACSC Essential Eight reading for Australian environments as defence-in-depth context around the human layer
What to do next
Once money-movers clear report-rate and call-back targets, fold a light monthly bank-change template into your standing simulation cadence and extend a shorter module to anyone who forwards invoices. Do not jump from a 20-person AP cohort to a full-company send in one go.
FAQ
How do you teach staff to verify supplier bank detail changes in 2026? Publish a verbal call-back rule, train only people who edit or pay vendors, run three escalating bank-change simulations in 30 days, and sample live call-backs monthly.
Is an email confirmation from the supplier enough? No. Confirm on a phone number already stored in your vendor master. Numbers inside the requesting email are part of the scam.
Who needs this training first? AP clerks, finance controllers, payroll if they share vendor files, and anyone with rights to create or edit supplier bank fields.
How often should bank-change simulations run? Three sends in the first 30 days, then at least quarterly inside the wider phishing programme.
What if the supplier’s only contact is the person who emailed? Use a second channel already on file — main switchboard, portal, or procurement record — not the signature block on the suspect message.
Does this replace email security? No. Filters still miss compromised-supplier threads. The call-back is the last control before money moves.
What report rate should we hit by day 30? Above 20% on the third simulation, with click rate trending down and live call-backs logged on real tickets.
Can a small AP team run this without a security department? Yes. One signed rule, three templates, short lessons, and a shared log are enough to start in 2026.
One last thing
The programme fails quietly when certificates stack up and nobody checks whether a human voice confirmed the last five bank edits. Put those five live tickets next to the simulation score every month. That single habit is what separates a compliance folder from a control that actually stops redirected payments in 2026.