Supplier Asks to Change Payment Wallet: 3 Checks Before You Pay

 / 
1

A supplier suddenly emails you saying "we changed our payment wallet." That change request is a major red flag. In the first five months of 2026, Singapore police recorded at least 66 cases of scammers impersonating suppliers and changing payment accounts, with losses over S$19 million. Once money is sent, recovery is very unlikely. Before paying, you must check three things. Missing even one can lead to loss.

First: Confirm the sender is real

Scammers either create an email address that looks like the supplier's or hack into the supplier's real mailbox to send the change notice.

What to check:

  • Look at the full domain of the sender's email address. Scammers often use a domain that is highly similar to the real one but has one extra letter or a changed symbol. For example, supplier.com may become supp1ier.com or supplier.co. It is hard to spot by eye.

  • Check whether the email is unusual. A supplier changing its payment account is rare. Treat any such request as a red flag and verify it before updating your system.

Done when: You confirm the sender's full email domain exactly matches past correspondence, with no small differences.

Second: Confirm by phone through an independent channel, not by replying to the email

If you only reply to the same email, the scammer can keep stalling you inside that email thread. You must use another channel.

What to do:

  • Find a trusted phone number from your existing supplier records, not from the new email, and call the supplier to confirm whether they really sent the change request.

  • Try to speak to someone else in the supplier's finance or payment team who does not usually email you. This prevents a scammer from pretending to be your usual contact.

  • Ask the person to tell you the new bank account details verbally, including account name, account number, and SWIFT code. Do not read the email to them and ask "is this correct?" This avoids being guided by fake information.

Done when: An official supplier contact confirms the account change by phone, and both sides check the complete bank account information.

Third: Verify the new wallet or account through independent, authoritative channels

Supplier confirmation alone is not enough. For on-chain wallets, if the address is wrong or the address is right but the chain is wrong, the money is gone. You need to verify from multiple angles.

What to check (two cases):

Case A: The supplier still uses a bank account or traditional currency account

  • Use a bank account ownership verification tool or an authoritative third-party database to confirm the new account holder's name, tax number, and address match the supplier's legal information. These tools can check whether the account status is good in real time.

  • For example, bill payment platform Bill.com sends a confirmation email to the supplier when it receives an account change request, and the supplier must confirm in the backend. If your tool does not have this feature, you can manually require the supplier to issue an account change confirmation letter on official company letterhead, stamped or signed, and keep it as proof.

Case B: The supplier changes to an on-chain stablecoin wallet (USDC/USDT)

  • Ask the supplier to send a separate confirmation email from the company's official email address with the new wallet address written in full.

  • Ask the supplier to provide the wallet's public transaction history or a block explorer link. Check whether the address's past activity matches the supplier's business size and payment frequency. A brand new address with no transaction history suddenly used to receive large payments is a warning sign.

  • Send a very small test amount: transfer 0.1 USDC to the new wallet first. Confirm with the supplier that they received it before releasing the full payment. This step takes a little more time but can prevent large funds from being lost.

Done when: The new account information passes at least two independent checks, such as phone confirmation + third-party tool verification + small test transfer, and is confirmed correct.