My Chinese supplier changed their bank details by email — is it a scam?
Assume it is fraud until proven otherwise. Mid-transaction bank-detail changes are the signature of business email compromise, where an attacker reads the supplier’s mailbox and intervenes at the invoice. Never verify by replying to the email. Call a number you already held, and confirm the account name matches the supplier’s registered company name exactly.
If you have already sent the money, stop reading and call your bank now. Recovery depends on hours, not days. Come back to the rest of this page afterwards.
What the attack looks like
The attacker does not hack you. They get into the supplier’s email — usually a reused password on a free mailbox — and then they wait. They read the thread. They learn the tone, the product, the amount and the timing. Then, at the moment the invoice is due, they send a message from the real account, or from a lookalike domain one character different, explaining that the usual account is under audit, or frozen for the tax year, or that the company has moved banks. The English is good because they are copying earlier messages. Everything about the request fits the conversation, because they have been reading the conversation.
The verification rules
- Never verify a bank change using any contact detail contained in the message announcing it. That includes the phone number in the signature.
- Call a number you already held, from before the change. Speak to a person you have spoken to before.
- Check the account holder name against the registered company name on the national registry. A mismatch ends it.
- Refuse personal accounts and third-party payers outright. A legitimate Chinese exporter is paid in its own company name.
- Send a small test payment first and confirm receipt by voice before the balance.
| Signal | Why it matters |
|---|---|
| Account name differs from the registered company name | The single strongest indicator. Almost always fraud |
| Account is personal, or in a third party’s name | Also a foreign-exchange compliance problem for the supplier |
| Account is in a different country to the supplier | Hong Kong accounts are common and legitimate — but must still be verified |
| New urgency, or a reason you must not call | Isolation is the attacker’s objective |
| Sender domain differs by one character | Check the full header, not the display name |
| Change arrives right as the invoice falls due | Timing is the tell — they have been reading |
Preventing it next time
- Fix the payee bank account in the contract at the outset, and state in writing that it will never be changed by email.
- Agree a call-back protocol with the supplier before the first order.
- Verify the account name against the registry once, at onboarding, and keep the record.
We apply the same rule to ourselves: our own bank details never change by email, and if you ever receive a message that appears to come from us asking you to pay a different account, it is not from us.
Want this done rather than explained?
Verify a Chinese supplier before you pay — from US$180, 3–7 working days.
Sources
All sources checked 23 August 2026. This page is general information, not legal, tax or customs advice. Requirements vary by product, market and circumstance — confirm your own position before acting.
