Stop payment when a sweater supplier's bank details change unexpectedly. Do not verify the request by replying to the same email, calling a number inside it or trusting a familiar invoice thread. Compare the beneficiary with the contract, contact a previously verified company representative through an independent channel, require your normal internal approval, and ask your bank about validation options. If money was sent, contact the bank immediately.

Custom sweater invoice and shipping records reviewed before payment
AI-generated concept illustration: payment review should reconcile the approved order, invoice and shipping evidence; it does not display genuine banking details.

Treat every changed instruction as unverified

A legitimate supplier may change banks, account numbers, currency routes or payment agents, but a plausible explanation is not authentication. Business email compromise can use a look-alike domain or a genuinely compromised mailbox, so correct names, historic messages and order details can appear in a fraudulent request.

Place the invoice on hold without accusing the sender. Record the time received, sender address as fully displayed, reply-to address, attachment names, claimed reason, urgency, changed fields and people copied. Preserve the original message and headers according to company policy. Do not click a new portal link or open an unexpected attachment merely to investigate.

Compare the request with the controlled order

Retrieve the signed quotation, pro forma invoice, purchase order, contract, prior paid invoice and approved vendor master from your own system—not from the suspicious thread. Compare legal supplier name, contracting entity, invoice number, PO, amount, currency, due milestone, beneficiary name, bank country, account and routing fields.

CheckEvidenceStop signal
Order identityPO, style, quantity and approved revisionInvoice does not match the current order
Payee identityContracting entity and approved beneficiaryPersonal or unexplained third-party account
Change authorityNamed supplier and buyer approversOne email bypasses the agreed process
Independent contactPreviously verified phone or established channelOnly new contact details are available
Payment milestoneDeposit, inspection or shipment evidenceUrgency replaces required evidence
Internal releaseDual approval and vendor-master recordRequester pressures one employee to act alone

Verify through a channel you already trust

The FBI advises looking up and using a company phone number independently rather than the number supplied in the questionable message. For an existing supplier, use a previously verified number, known video contact, established platform account or another controlled channel. Start a new conversation instead of replying or forwarding within the suspect thread.

Ask the known contact to confirm the exact changed fields and business reason, then require the supplier's documented authorization under your agreed onboarding process. A voice call alone can also be manipulated or socially engineered; combine independent contact, written company authorization, contract identity and your own approval controls.

Resolve entity and beneficiary differences

A factory name, export company, sales company and bank beneficiary may differ for legitimate reasons, but the relationship must be understood before payment. Request evidence appropriate to the transaction and jurisdiction, and have finance or qualified advisers assess it. Do not infer ownership from a logo, email signature, bank letter image or messaging-app profile.

If a third party will collect payment, document who it is, why it is involved, which invoice and amount it covers, tax and customs consequences, authorization by the contracting party and whether the arrangement changes any contractual right. Never let an unexplained third-party beneficiary become normal because the first transfer succeeded.

Keep product milestones in the payment decision

Authenticating an account does not prove the invoice is due. Reconcile the requested amount with the agreed deposit, sample credit, quantity, price, change orders, inspection status, shipping documents and approved deductions. Likewise, a valid inspection report does not authenticate new bank details. Payment entitlement and payment destination are separate controls.

For balance payment before shipment, confirm the evidence required by the contract without asking the supplier to send confidential banking data through unsecured public channels. Use role-based access and share only what each reviewer needs.

Custom sweater products associated with a verified supplier relationship
Real product reference: product familiarity does not authenticate a new beneficiary; payment changes still require independent verification.

Use a controlled vendor-master change

Separate the person requesting a change, the person independently verifying it and the person approving payment where practical. Record effective date, old and new data, verification channel, verifier, approver and supporting evidence. Restrict who can edit supplier master data and alert finance when a payment follows soon after a change.

Consider a defined cooling-off or enhanced-review period for changed accounts based on risk, rather than inventing a universal delay. Ask your bank which beneficiary-name checks, transfer limits, callbacks or confirmation services apply to the payment route. Bank tools vary by country, currency and payment network.

Respond immediately if payment was sent

The FBI and IC3 instruct potential BEC victims to contact their financial institution immediately and request action with the receiving institution, then report the incident through the appropriate law-enforcement channel. Speed can matter. Do not wait for the supplier's email account to clarify the situation before notifying the bank.

Preserve messages, headers, invoices, phone records, transaction references, account details and the timeline. Follow instructions from the bank, insurer, counsel and relevant authorities. Do not send a second “correction” payment until identity, outstanding liability and recovery status are independently established.

Buyer payment-verification checklist

  • Unexpected bank changes automatically pause payment.
  • The original email and headers are preserved.
  • PO, contract, invoice and vendor master are reconciled.
  • A previously verified channel confirms the exact change.
  • Contracting entity and beneficiary differences are explained.
  • Payment milestone and destination are approved separately.
  • Vendor-master edits require recorded verification and approval.
  • Urgency never overrides dual control.
  • Bank validation options are checked for the payment route.
  • A sent suspicious transfer triggers immediate bank contact.

Yushengda's confirmed public inquiry channels are listed on the official contact page; this website does not publish bank account instructions, and no article can authenticate a payment request. Use the payment-milestone guide, quote-locking checklist and invoice review guide. Verify any actual payment instruction through previously established business and bank controls.

Primary references: Federal Bureau of Investigation, Business Email Compromise, and Internet Crime Complaint Center, Business Email Compromise, for independent-channel verification of account changes and immediate incident response. Procedures, reporting routes and recovery options depend on jurisdiction, bank and facts; this is not banking, legal or cybersecurity advice. Competitor material was reviewed only for buyer questions; no bank details, cases, loss figures, workflows, wording or images were reused.