Skip to content
EARLY ACCESSProTax ERPPrivate preview access is opening for CPA firms.
CPA Login Client Login
Start as a Client
Start as a ClientCPA LoginClient Login
Original ProTax editorial illustration for “Fake payment instructions: a verification playbook for small businesses and tax firms”EVERGREEN GUIDESecurity
Security

EVERGREEN GUIDE · August 19, 2026

Fake payment instructions: a verification playbook for small businesses and tax firms

ProTax Editorial Team6 min readPublished August 19, 2026Reviewed September 5, 2026

Turn business-email-compromise awareness into a repeatable control for changed bank details, urgent requests, lookalike messages, and incident response.

Key takeaways

A familiar name or email thread is not sufficient verification.

Changed bank instructions deserve an out-of-band check using a known contact path.

People, process, access controls, and an incident plan must work together.

On this page1Recognize the attack path2Verify outside the request3Reduce the blast radius4Prepare the response before money moves
01

Recognize the attack path

A criminal may compromise a mailbox, imitate a vendor or executive, register a lookalike domain, or enter a legitimate conversation at the moment payment is expected. The message often adds urgency, secrecy, a last-minute bank change, or pressure to bypass normal review. Good grammar and a familiar signature do not establish authenticity.

02

Verify outside the request

Do not reply to the suspicious message or use the phone number it supplies. Contact the vendor, client, or colleague through a previously verified number or separate trusted channel. Confirm the account change and the specific transaction. For high-risk changes, require a second authorized person to review the evidence before the master record or payment is released.

03

Reduce the blast radius

Use unique accounts, multifactor authentication, least-privilege access, payment limits, and separate preparation and approval roles. Alert reviewers when vendor bank details change. Protect tax documents and banking information in the secure portal rather than ordinary email. Logs should show who requested, verified, approved, changed, and paid.

04

Prepare the response before money moves

The written information security plan should name the people and steps for containment, bank contact, evidence preservation, password and session reset, insurance notice, legal review, and appropriate reporting. Test the contact list and decision path. During an incident, speed matters, but an improvised response can erase evidence or send more information to the attacker.

Put it into practice

  1. 1

    Independently verify every new or changed payment instruction.

  2. 2

    Require approval and an audit trail for sensitive master-data changes.

  3. 3

    Practice the contact, containment, and reporting steps before an incident.

Educational informationThis ProTax resource helps you prepare and communicate. It is not a tax calculation, eligibility decision, legal opinion, or promise of a filing result.

SOURCES OF RECORD

Current federal facts should be checked directly with the responsible agency.

IRS Publication 5708: WISP templateIRS Security Summit resourcesFinCEN business-email-compromise advisory
Start organizer

One connected experience for tax preparation, bookkeeping, client collaboration, and CPA-firm operations.

Platform
Solutions
Resources
Get in touchsupport@protaxservice.online
© 2026 ProTax Service Pvt. Ltd.Educational information is not individualized tax or legal advice.