SardineCon SF/2026

Learn More
Card & payment fraud4 min de leitura

O que é Payment diversion?

SUBSCRIBE

Payment diversion is rerouting a genuine payment to an account the fraudster controls, usually by hacking or faking emails and swapping the bank details on an invoice at the last second. It targets big business and supplier payments and often surfaces only when the real vendor asks why they were never paid.

What is payment diversion, in plain English?

Payment diversion is fraud that hijacks a payment that was always going to happen. The buyer genuinely owes a supplier and fully intends to pay. The fraudster does not create a fake invoice out of nothing; instead they change the destination, swapping the vendor's real bank details for their own so the legitimate payment lands in a criminal account.

The usual method is compromising or spoofing email. The attacker gets into a mailbox in the vendor's or buyer's chain, or fakes a convincing address, then sends updated banking instructions at just the right moment, often as a payment is due. Because the request looks like it comes from a known contact and the underlying transaction is real, it sails through.

This sits at the intersection of business email compromise, invoice fraud, and authorized push payment fraud. The payer authorizes the transfer themselves, believing they are paying a trusted supplier, which is exactly why it slips past controls designed to catch unfamiliar transactions.

How a diversion unfolds

  1. Access — Compromise the channel. The attacker breaks into or convincingly spoofs an email account in the buyer or supplier chain.
  2. Watch — Learn the payment rhythm. They observe invoices, contacts, and timing so their request will look normal and land at the right moment.
  3. Switch — Send new bank details. Posing as the vendor, they email updated banking instructions just as a payment comes due.
  4. Extract — Collect and disappear. The buyer pays the new account, funds are moved on quickly, and the loss surfaces only when the real vendor chases payment.

Who is involved?

Who

Their role

The buyer

Owes a genuine payment and is tricked into sending it to the wrong account.

The real vendor

The legitimate supplier who never receives the money and later raises the alarm.

The fraudster

Compromises or spoofs email and supplies the swapped bank details.

The receiving account

A mule or shell account that collects the diverted funds and moves them on.

What it looks like in practice

In practice

A finance clerk receives an email from a long-standing supplier saying they have changed banks and asking that the next invoice be paid to a new account. The message quotes the correct invoice number, matches the usual tone, and comes just as a large payment is due. The clerk updates the payee and releases the funds.

Weeks later the real supplier calls asking about the overdue invoice. The email had come from a compromised mailbox in the supplier's own domain, and the new account was a mule that emptied the funds the same day. A quick call to a known phone number, rather than a reply to the email, would have exposed the switch before the money moved.

Why it matters to operators

Payment diversion is dangerous because everything about it looks legitimate. The supplier is real, the invoice is real, and the payer authorizes the transfer willingly, so fraud rules built around unfamiliar recipients or odd amounts often stay quiet. The single point of failure is the change of bank details, which is why controls have to focus there rather than on the payment itself.

Losses tend to be large because the target is business-to-business flows, and they surface late because nobody notices until the real vendor complains. The defenses are process, not just detection: verify any change of details through a separate out-of-band channel, require two approvers on payee changes, and validate the payee account before releasing funds.

What to watch in the data

  • Last-minute detail changes. A request to update bank details right as a payment is due is the signature move of diversion.
  • Email-only instructions. Banking changes that arrive solely by email, with pressure to act quickly, should never be trusted on their own.
  • New payee, old relationship. A long-standing vendor suddenly pointing to a brand-new account warrants an out-of-band callback.
  • Subtle address spoofing. Look-alike domains or a compromised internal mailbox make the request look genuine.
  • Delayed complaints. A real supplier chasing an invoice you believe you paid is a classic late signal of diversion.

Quick questions

How is payment diversion different from invoice fraud?

Invoice fraud often involves a fake or inflated invoice. Payment diversion hijacks a genuine invoice by changing the destination account, so the debt is real but the money goes to the fraudster.

Is this the same as business email compromise?

Diversion is a common outcome of business email compromise. The attacker uses a hacked or spoofed mailbox to send the swapped banking details that reroute a legitimate payment.

Why is it usually caught late?

Because the payer believes they paid correctly and nothing looks wrong on their side. The loss only surfaces when the real vendor asks why they were never paid, by which time funds are moved on.

What is the single most effective control?

Confirming any change of bank details through a separate, known channel, such as calling the vendor on a trusted number. An out-of-band callback breaks the email-only trust the fraud relies on.

Why do fraud rules often miss it?

Because the supplier and invoice are legitimate and the payer authorizes the transfer. Rules tuned for unfamiliar recipients or unusual amounts do not fire on a payment that looks entirely expected.

Does dual approval help?

Yes. Requiring two people to approve any payee or bank-detail change adds a second set of eyes and makes it much harder for a single spoofed email to push a diversion through.

Go deeper

O que saber junto com Payment diversion