EVERGREEN GUIDESecurityEVERGREEN GUIDE · August 19, 2026
Fake payment instructions: a verification playbook for small businesses and tax firms
Turn business-email-compromise awareness into a repeatable control for changed bank details, urgent requests, lookalike messages, and incident response.
Key takeaways
A familiar name or email thread is not sufficient verification.
Changed bank instructions deserve an out-of-band check using a known contact path.
People, process, access controls, and an incident plan must work together.
Recognize the attack path
A criminal may compromise a mailbox, imitate a vendor or executive, register a lookalike domain, or enter a legitimate conversation at the moment payment is expected. The message often adds urgency, secrecy, a last-minute bank change, or pressure to bypass normal review. Good grammar and a familiar signature do not establish authenticity.
Verify outside the request
Do not reply to the suspicious message or use the phone number it supplies. Contact the vendor, client, or colleague through a previously verified number or separate trusted channel. Confirm the account change and the specific transaction. For high-risk changes, require a second authorized person to review the evidence before the master record or payment is released.
Reduce the blast radius
Use unique accounts, multifactor authentication, least-privilege access, payment limits, and separate preparation and approval roles. Alert reviewers when vendor bank details change. Protect tax documents and banking information in the secure portal rather than ordinary email. Logs should show who requested, verified, approved, changed, and paid.
Prepare the response before money moves
The written information security plan should name the people and steps for containment, bank contact, evidence preservation, password and session reset, insurance notice, legal review, and appropriate reporting. Test the contact list and decision path. During an incident, speed matters, but an improvised response can erase evidence or send more information to the attacker.
Put it into practice
- 1
Independently verify every new or changed payment instruction.
- 2
Require approval and an audit trail for sensitive master-data changes.
- 3
Practice the contact, containment, and reporting steps before an incident.
Educational informationThis ProTax resource helps you prepare and communicate. It is not a tax calculation, eligibility decision, legal opinion, or promise of a filing result.