brand logo

Partners

Testimonials

The fastest-growing accounts payable fraud: supplier bank details change

08/24/2026

by

Xtract

The fastest-growing accounts payable fraud: supplier bank details change

The rise in supplier bank account change fraud is shifting how finance teams must protect payments. 79% of organizations reported a payment fraud attempt, and many of those incidents involve attackers altering supplier bank details to reroute funds.

 

Supplier bank account change fraud: the new pattern

Historically, fraud prevention focused on fake invoices and bogus vendors. Today the most common scheme is subtler: attackers replace a supplier’s bank details so legitimate invoices are paid to an account controlled by the fraudster. The payment appears routine, and the discrepancy is often discovered only after the transfer.

 

BEC, social engineering and deepfakes: how attackers succeed

Successful attempts combine techniques such as business email compromise (BEC), impersonation, and increasingly, voice or video deepfakes. Typical steps include:

  • A seemingly authentic email requesting a bank account update.
  • Attached documents or forms that look official with the new banking details.
  • Approval processes that rely on responses within the same email thread or on a single approver.

These elements reduce suspicion and let attackers achieve fund redirection with minimal friction.

 

Minimum controls that materially reduce risk

Finance teams can adopt practical, low-friction controls that make attacks harder to execute:

  • Segregation of duties: separate the roles that request changes from those that approve payments.
  • Independent validation: confirm any bank detail changes through a known contact channel, not by replying to the same email.
  • Dual authorization: require two approvals for changes to supplier banking information, with documentation.
  • Maintain approved supplier bank lists for critical vendors to prevent ad-hoc updates.

 

How traceability and digital control shrink the attack surface

Reducing manual touch points and keeping an immutable audit trail are effective defenses. Digital controls provide:

  • Full traceability: who requested and who approved each change, timestamps and attached evidence.
  • Automated validations: flags for inconsistencies against historical supplier data.
  • ERP integration: removing manual data entry and the copying of sensitive banking information.
  • Configurable alerts for unusual changes (new country, different banking institution, etc.).

Applying these controls shortens attackers’ windows and speeds up incident response—making it harder for fraudsters to succeed while preserving efficient payment operations.

 

Want to see it in action?

Xtract automates supplier data capture and validation, preserves full traceability for any change, and reduces approval risks. Book a demo to see the workflow live.

Book a demo →
=== CUERPO ES (HTML) ===

El fraude en cuentas por pagar proveedores dejó de ser sólo un problema de facturas falsas: hoy la amenaza que más creció es el cambio fraudulento de datos bancarios del proveedor. El 79% de las organizaciones reportó un intento de fraude en pagos, y muchas de esas intrusiones se realizan modificando dónde se envía el dinero, no la factura en sí.

 

El nuevo patrón: del fraude de facturas al 'hijack' de datos bancarios

Hasta hace unos años, los equipos de Cuentas por Pagar estaban entrenados para detectar facturas duplicadas o proveedores ficticios. Ahora los atacantes apuntan a un cambio sutil pero crítico: reemplazar o actualizar la cuenta bancaria del proveedor. El pago se autoriza sobre una cuenta válida, pero controlada por el actor malicioso. La víctima sólo nota la transferencia cuando es tarde.

 

BEC, ingeniería social y deepfakes: cómo se logra el cambio

Los intentos combinan varias técnicas: compromiso de correo (BEC), suplantación de identidad del proveedor y, en casos avanzados, deepfakes o llamadas que imitan la voz del contacto legítimo. El proceso típico incluye:

  • Un correo aparentemente legítimo solicitando actualización de cuenta.
  • Documentos adjuntos con la nueva información bancaria que parecen oficiales.
  • Validación débil por parte de quien aprueba el pago (por ejemplo, responder al mismo hilo de correo).

Con esos elementos, el atacante consigue que el pago salga fuera del control organizacional sin levantar sospechas inmediatas.

 

Controles mínimos y de bajo fricción que hacen la diferencia

Para reducir la exposición conviene implementar controles concretos y prácticos que no dependan únicamente del criterio humano:

  • Segregación de funciones: separación clara entre quien solicita cambios y quien autoriza pagos.
  • Validación de datos por canales independientes: llamada a número conocido del proveedor o verificación contra el registro interno, nunca por respuesta al mismo hilo de correo.
  • Doble aprobación para cualquier modificación de cuenta bancaria, con evidencia documental y registro de quién aprobó cada paso.
  • Listas blancas de cuentas bancarias aprobadas para proveedores críticos.

 

Cómo la trazabilidad y el control digital reducen la superficie de ataque

La clave para mitigar este riesgo es disminuir las intervenciones manuales y dejar un rastro incontestable de cada cambio. El control digital aporta:

  • Trazabilidad completa: registro de quién solicitó y quién aprobó cada cambio, con sello de tiempo y evidencia adjunta.
  • Validaciones automáticas que detectan discrepancias entre la cuenta nueva y la histórica del proveedor.
  • Integración con ERP que evita copiar y pegar datos manualmente, reduciendo errores humanos y la posibilidad de manipulación.
  • Alertas configurables ante cambios inusuales (cambio de país de la cuenta, nueva entidad bancaria, etc.).

Con controles y trazabilidad digitales se reduce la ventana de oportunidad del atacante y se facilita la investigación cuando hay un incidente. No es cuestión de eliminar la comunicación: es garantizar que cada cambio pase por un flujo auditable y validado.

 

Querés ver cómo reducir este riesgo en tu empresa?

Con Xtract podés automatizar la captura y validación de datos de proveedor, conservar la trazabilidad de cada cambio y evitar aprobaciones débiles. Agendá una demo para ver el flujo en acción.

Agendá una demo →
=== CUERPO EN (HTML) ===

The rise in supplier bank account change fraud is shifting how finance teams must protect payments. 79% of organizations reported a payment fraud attempt, and many of those incidents involve attackers altering supplier bank details to reroute funds.

 

Supplier bank account change fraud: the new pattern

Historically, fraud prevention focused on fake invoices and bogus vendors. Today the most common scheme is subtler: attackers replace a supplier’s bank details so legitimate invoices are paid to an account controlled by the fraudster. The payment appears routine, and the discrepancy is often discovered only after the transfer.

 

BEC, social engineering and deepfakes: how attackers succeed

Successful attempts combine techniques such as business email compromise (BEC), impersonation, and increasingly, voice or video deepfakes. Typical steps include:

  • A seemingly authentic email requesting a bank account update.
  • Attached documents or forms that look official with the new banking details.
  • Approval processes that rely on responses within the same email thread or on a single approver.

These elements reduce suspicion and let attackers achieve fund redirection with minimal friction.

 

Minimum controls that materially reduce risk

Finance teams can adopt practical, low-friction controls that make attacks harder to execute:

  • Segregation of duties: separate the roles that request changes from those that approve payments.
  • Independent validation: confirm any bank detail changes through a known contact channel, not by replying to the same email.
  • Dual authorization: require two approvals for changes to supplier banking information, with documentation.
  • Maintain approved supplier bank lists for critical vendors to prevent ad-hoc updates.

 

How traceability and digital control shrink the attack surface

Reducing manual touch points and keeping an immutable audit trail are effective defenses. Digital controls provide:

  • Full traceability: who requested and who approved each change, timestamps and attached evidence.
  • Automated validations: flags for inconsistencies against historical supplier data.
  • ERP integration: removing manual data entry and the copying of sensitive banking information.
  • Configurable alerts for unusual changes (new country, different banking institution, etc.).

Applying these controls shortens attackers’ windows and speeds up incident response—making it harder for fraudsters to succeed while preserving efficient payment operations.

 

Want to see it in action?

Xtract automates supplier data capture and validation, preserves full traceability for any change, and reduces approval risks. Book a demo to see the workflow live.

Book a demo →

Latest entries

Recent highlights

There are no related entries

brand logo

Products

© 2026 Xtract.app

Support Center

+54 9 11 32873865

xtract@xtract.app