Skip to content
Fraud

My Chinese supplier changed their bank details by email — is it a scam?

Assume it is fraud until proven otherwise. Mid-transaction bank-detail changes are the signature of business email compromise, where an attacker reads the supplier’s mailbox and intervenes at the invoice. Never verify by replying to the email. Call a number you already held, and confirm the account name matches the supplier’s registered company name exactly.

If you have already sent the money, stop reading and call your bank now. Recovery depends on hours, not days. Come back to the rest of this page afterwards.

What the attack looks like

The attacker does not hack you. They get into the supplier’s email — usually a reused password on a free mailbox — and then they wait. They read the thread. They learn the tone, the product, the amount and the timing. Then, at the moment the invoice is due, they send a message from the real account, or from a lookalike domain one character different, explaining that the usual account is under audit, or frozen for the tax year, or that the company has moved banks. The English is good because they are copying earlier messages. Everything about the request fits the conversation, because they have been reading the conversation.

The verification rules

  1. Never verify a bank change using any contact detail contained in the message announcing it. That includes the phone number in the signature.
  2. Call a number you already held, from before the change. Speak to a person you have spoken to before.
  3. Check the account holder name against the registered company name on the national registry. A mismatch ends it.
  4. Refuse personal accounts and third-party payers outright. A legitimate Chinese exporter is paid in its own company name.
  5. Send a small test payment first and confirm receipt by voice before the balance.
SignalWhy it matters
Account name differs from the registered company nameThe single strongest indicator. Almost always fraud
Account is personal, or in a third party’s nameAlso a foreign-exchange compliance problem for the supplier
Account is in a different country to the supplierHong Kong accounts are common and legitimate — but must still be verified
New urgency, or a reason you must not callIsolation is the attacker’s objective
Sender domain differs by one characterCheck the full header, not the display name
Change arrives right as the invoice falls dueTiming is the tell — they have been reading
Red flags, in rough order of severity

Preventing it next time

  • Fix the payee bank account in the contract at the outset, and state in writing that it will never be changed by email.
  • Agree a call-back protocol with the supplier before the first order.
  • Verify the account name against the registry once, at onboarding, and keep the record.

We apply the same rule to ourselves: our own bank details never change by email, and if you ever receive a message that appears to come from us asking you to pay a different account, it is not from us.

Want this done rather than explained?

Verify a Chinese supplier before you pay — from US$180, 3–7 working days.

Supplier Due Diligence & Verification

Sources

All sources checked 23 August 2026. This page is general information, not legal, tax or customs advice. Requirements vary by product, market and circumstance — confirm your own position before acting.

Have the version of this question that has your company in it?

Book a 45-minute consult. We map your situation to the right process, tell you honestly what is and is not possible, and give you a fixed fee. No obligation.

Book a consult · US$120 Credited in full against any service you go on to book.