Skip to main content
Norwood, Johannesburg · Established 1993
Call

Changed banking details by email: verify the payment instruction through an independent channel

Originally published By Hugh Raichlin AttorneysUpdated

Edited and expanded by Hugh Raichlin Attorneys

Originally published by Law DotNews (“Check All Emailed Bank Details for BEC (“Business Email Compromise”) Frauds”). © LawDotNews for the original provider material. Original authorship and source credit retained; substantive HRA editorial adaptation.

A familiar email thread can contain a fraudulent payment instruction. A copied invoice, altered bank letter or convincing message from a compromised account may arrive at exactly the moment a large payment is expected. The fact that the correspondence looks routine is not a reliable verification method.

For businesses and property clients, the immediate priority is a payment process that does not depend on trusting a single email. Hugh Raichlin Attorneys can assist with the contractual, evidential and dispute issues where instructions are contested or money has already been misdirected.

Use a genuinely independent verification channel

Before paying new or changed details, contact the intended recipient using a number independently obtained and previously verified. Do not use the telephone number contained only in the suspicious message or its attached bank letter.

Confirm the beneficiary and payment instructions through that channel and record who confirmed them, when and how. Follow the organisation’s established approval process. A small initial payment, a professional-looking attachment or a matching display name is not a substitute for verifying the instruction itself.

Look at the whole payment process

  • Check the actual email address and domain, not only the sender’s display name.
  • Treat an unexplained change in banking details, urgency or confidentiality demands as a reason to pause.
  • Verify the beneficiary through a reliable process before release, including payments inside an existing thread.
  • Use separate preparer and approver controls for material payments where practical.
  • Preserve the approved instruction and verification record with the payment evidence.

Bank-provided beneficiary checks can assist, but their availability and meaning must be understood. Do not assume any single automated response guarantees the destination or removes the need for the agreed checks.

Make the rules clear before the transaction

Contracts and onboarding documents should explain the authorised payment method, how a change may be notified and how it must be verified. Staff need a usable procedure and a clear route for escalating doubt without being pressured to bypass it.

A disclaimer saying “we never change our bank details” does not secure an email account or decide every future liability dispute. Nor does one party’s poor security automatically establish that the other party has discharged the payment obligation. Responsibility requires analysis of the agreement, communications, conduct and applicable duties.

When a suspicious payment has already been made

Contact your bank immediately through an established fraud-reporting channel and request the appropriate recall or recovery steps. Preserve references, times and responses. Notify the genuine intended recipient and your own authorised internal contacts through verified channels.

Retain the original email files, attachments and full message trail, not only screenshots. Preserve payment records and relevant access logs with appropriate technical help. Report to the relevant authorities and notify insurers where required. Avoid deleting accounts or wiping devices before evidence has been secured.

Speed can matter, but recovery is not guaranteed. Do not pay a further “release” or “recovery” fee to an unverified contact. HRA’s ordinary intake process is not a substitute for immediate reporting to your bank.

Assess the legal dispute without assuming the answer

The payer, intended recipient, bank, service provider and insurer may have different obligations. Establish what was compromised, which instruction was received, what verification occurred and what the contract required.

The original source article discussed an earlier court dispute. This HRA edition does not present that historical award as a universal or current allocation of liability. A matter-specific review should identify the available claims and defences before blame, repayment or cancellation is demanded.

Is a reply in the same email thread safe?

Not necessarily. Compromised accounts and altered communications can make fraudulent instructions appear in familiar correspondence. Use the independent verification process.

Can the contract say who carries every fraud risk?

Contract terms matter, but their wording, incorporation, enforceability and the actual facts must be assessed. Do not assume a generic clause settles every loss.

Discuss a payment-instruction or recovery dispute

Tell HRA the transaction type, payment date, parties and steps already taken with the bank. Send a brief outline first; the firm can identify which records are needed through an appropriate secure process.

Official sources

Related legal services

Discuss your business matter

This article provides general information and is not a substitute for advice on your circumstances.

Published by Hugh Raichlin Attorneys.Legally reviewed by Hugh Raichlin (Principal Attorney & Accredited Mediator).