A Verified Check Still Reached a Scammer: What Went Wrong

Business professional reviewing documents for signs of check fraud in 2026.

By Farmers State Bank | Updated: September 9, 2026 • 5 min read

Businesses are regular targets of fraudsters seeking to intercept payments and redirect funds. The following case study reflects a broader fraud trend that has affected organizations across the country.

The important distinction: Business payment fraud does not always begin when a check, ACH payment, or wire transfer is sent. In some cases, the fraudster first changes information inside a legitimate vendor record so the payment that follows appears completely normal.

How a Fraudulent Vendor Change Redirected a Legitimate Check

A simple request to update vendor information can create an opportunity for payment fraud if the change is not independently verified.

In this scenario, a business received an email that appeared to come from an established vendor. The email asked the business to update the vendor’s mailing information. An employee accepted the request and changed the vendor record without independently verifying it.

The business later issued a legitimate check to the vendor and mailed it to the fraudulent address. Check fraud protection software did not flag the check because the business had authorized the payment, and the check matched the expected payee and payment details. The fraud occurred earlier when the employee accepted the unverified change.

1

Key Lesson #1

Fraudsters often create emails that closely resemble legitimate messages. Small differences in an email address or request details may provide the only warning signs.

2

Key Lesson #2

Never accept changes to vendor, payee, mailing, or payment information based solely on email. Always verify the request with a trusted contact using information already on file.

Why Check Fraud Protection May Not Catch Vendor Change Fraud

Fraud prevention technology is an important layer of protection, but internal verification procedures still matter.

Tools such as Positive Pay can help businesses identify checks that do not match information they previously provided to their financial institution. But vendor change fraud can happen before the payment is ever created.

If an employee updates a legitimate vendor record based on fraudulent instructions and the business then intentionally issues a payment using that information, a fraud tool may not detect any unexpected payment information.

Technology and internal controls work together. Fraud tools can help monitor transactions, while verification procedures help determine whether the instructions used to create those transactions were legitimate in the first place.

Businesses that use checks or electronic payments can learn more about Positive Pay and payment verification as one part of a broader fraud prevention strategy.

How to Verify a Vendor Change Request

Create a repeatable process employees can follow whenever someone asks to change vendor information.

1

Pause before making the change. Treat requests to change payment, mailing, payee, contact, ACH, or wire information as requests that require additional verification.

2

Use contact information you already trust. Call a known vendor contact using a phone number already in your records, not a number included in the email requesting the change.

3

Confirm the exact request. Verify what information is changing and that the requester is authorized to make it.

4

Document the verification. Record who confirmed the change, when it was verified, and how confirmation was completed before updating the vendor record.

Warning Signs of a Fraudulent Vendor Request

A fraudulent message may look almost identical to a normal vendor conversation. Pay additional attention when one or more of these warning signs appear.

A Slightly Different Email Address

Look closely at the full sender address and domain. Fraudsters may use small spelling changes or similar-looking characters.

Unexpected Information Changes

Be cautious when an established vendor suddenly requests a different mailing address, bank account, payment method, or contact person.

Pressure to Act Quickly

Urgency can discourage employees from following normal verification procedures. A rushed request should not override established controls.

A Request to Avoid Normal Procedures

Be skeptical if the sender asks an employee to bypass another approver, avoid a phone call, or handle the request differently than usual.

Build Vendor Verification Into Your Payment Process

The most effective procedure is one employees can follow consistently, not only when a message already looks suspicious.

Consider establishing a written procedure requiring independent verification before employees change vendor mailing addresses, payment instructions, payee information, bank account information, or other details that determine where money is sent.

For businesses with multiple employees involved in accounts payable, an additional review or approval for sensitive vendor changes can create another opportunity to identify a fraudulent request before a payment is issued.

Employees should also know where to report unusual requests internally. When something feels different from the normal payment process, asking another employee or contacting the vendor directly can prevent a routine administrative change from becoming a financial loss.

For additional examples of scams affecting businesses, explore FSB's business fraud prevention resources.

The Takeaway

Employees can help prevent payment fraud by verifying changes before acting. A callback to a known contact can stop a fraudster from redirecting a legitimate payment.

The key is to verify the change before updating the vendor record. Once fraudulent information becomes part of a legitimate payment process, the transaction may appear exactly as the business intended it to.

Vendor Change Fraud FAQs

Common questions businesses should consider when reviewing vendor and payment verification procedures.

What vendor changes should a business verify?

+

Businesses should independently verify changes that could affect who receives a payment or where it is delivered. This can include mailing and remittance addresses, payee names, bank account information, ACH or wire instructions, payment methods, and vendor contact information.

How should a vendor change request be verified?

+

Contact a trusted person at the vendor using contact information your business already has on file. Do not rely solely on a phone number, email address, or other contact information supplied in the request you are trying to verify.

Can Positive Pay prevent vendor change fraud?

+

Positive Pay can provide an important layer of check and payment protection, but internal verification procedures remain important. If a business intentionally creates a payment using vendor information that was previously changed because of fraud, the payment may still match the information the business authorized.

What should a business do after discovering a fraudulent payment?

+

Contact your financial institution as soon as possible to discuss the payment and available next steps. Preserve relevant emails, payment records, and other communications so they are available when reviewing or reporting the incident.

Strengthen Your Business Fraud Controls

Payment verification tools and clear internal procedures can work together to help protect your business from check, ACH, and other forms of payment fraud.

Explore Fraud Prevention Solutions


Related Articles

Two professionals reviewing documents closely with a magnifying glass and calculator.

How Verification Prevented Loss

Learn how one business avoided a $17,000 payment scam.

See How Verification Helps


Frustrated small business owner after falling victim to Business Email Compromise fraud

Stop Business Email Scams Early

Learn how to protect your business from email fraud.

Prevent Business Email Compromise


Worried man at laptop with hands on his face, overwhelmed by a financial issue.

One Mistake Nearly Cost Thousands

See how a quick verification call stopped a $300,000 loss.

Read the Full Case