Supplier Red Flags Before a Wire Transfer

Use an approved beneficiary baseline, independent callback, release record, and first-hour response plan when a supplier wire instruction changes or looks unusual.

The most dangerous supplier wire instruction may arrive inside a familiar email thread, use the correct invoice amount, and appear to come from a person your team already knows. The payment control therefore cannot be “does this email look genuine?” It must compare the instruction with an independently established supplier and beneficiary baseline.

This playbook separates three clocks: controls established during onboarding, the release check for today's wire, and the first hour after a suspected misdirection. It focuses on payment-instruction risk rather than repeating a general supplier-red-flags list.

Two finance staff independently confirming a supplier bank instruction by phone before authorizing a wire transfer
Independent confirmation works only when the contact route and expected beneficiary were established before the disputed instruction arrived.

Clock 1: establish the baseline before an invoice is due

Create an approved supplier-payment record during onboarding, when nobody is under pressure to release funds. Record the registered Chinese name, Unified Social Credit Code (USCC), contract party, expected invoice issuer, approved beneficiary, beneficiary country or region, bank name, account ending, currency, and the commercial reason for any different entity in the chain.

Also establish two confirmation routes that do not depend on the same email account: for example, a phone number verified from prior communication and a second known contact. Document who in your organization may approve a new beneficiary and the value threshold that requires two approvers.

Chinese business-license rules place identity fields such as the company name and USCC on the license. Review the official license-field provisions. Use those fields to anchor the supplier record, then connect them to the contract and payment parties. A website name or email signature is not a substitute for the registered identity.

Understand why a familiar thread is not enough

Business Email Compromise (BEC) can involve a spoofed address or a genuinely compromised mailbox. An attacker may observe real billing conversations and insert different account details at the moment a payment is expected. Correct names, amounts, product descriptions, and email history can therefore coexist with a fraudulent beneficiary.

The FBI describes BEC as a scheme that can redirect a payment intended for a familiar vendor and advises confirming transfers through direct voice communication and previously known contact details. Read the FBI's BEC guidance.

Do not ask the same email thread whether it was compromised. Do not use the phone number added to the changed instruction. The verification route has to come from your pre-existing record or another source independent of the message in question.

Seven triggers that should stop the release

These signals do not prove fraud. Each is a reason to pause until the change is explained and independently confirmed:

  1. New account or beneficiary. Any change from the approved baseline resets the payment check, even when the supplier says the old account is unavailable.
  2. New country, region, or unrelated company. The supplier asks a mainland contract party's funds to be sent to a Hong Kong company, export agent, individual, or another jurisdiction without an approved relationship file.
  3. Last-minute urgency. A discount, production slot, holiday, shipment release, or manager travel is used to bypass ordinary approval.
  4. Changed communication pattern. The sender switches domain, personal email, messaging account, phone number, or language and discourages use of the old route.
  5. Refusal to speak. The contact will communicate only by email or chat when bank details need confirmation.
  6. Document discontinuity. The beneficiary, invoice issuer, contract party, currency, or amount changes between versions without a clear amendment trail.
  7. Unusual secrecy or authority pressure. The requester says senior management approved an exception but does not allow the approver to be contacted directly.

FBI guidance identifies unexplained urgency, last-minute changes to wiring information, changes in communication channels, and refusal to use voice or video as warning signs. Review the official warning-sign list.

Run an independent callback

Call a known supplier contact using the number in the approved onboarding record. If the primary contact is the person whose mailbox may be compromised, include a second known contact. Do not reveal every expected answer first; ask the supplier to state the change in their own words.

A practical callback script is:

“We are holding payment reference [internal reference]. Please state the beneficiary legal name, bank country, currency, and last four account characters currently authorized for this invoice. If these differ from our approved record, explain which entity owns the account, why it is involved, when the change took effect, and who within your company authorized it. We will document the response and complete our own approval before release.”

Record the date, time, number dialed, people on the call, details stated without prompting, supporting document requested, and internal reviewer. A callback that merely asks “Is the email correct?” produces weak evidence.

IC3 recommends secondary channels or two-factor verification for account-information changes. See the IC3 prevention and response guidance.

Resolve the company-to-beneficiary relationship

A beneficiary mismatch is not automatically fraudulent. Chinese suppliers can use an export company, affiliated trading entity, group treasury company, or Hong Kong company for a documented commercial reason. The control is to establish who the separate entity is, its role, its authority to collect, and whether the contract and invoice support that arrangement.

Compare these names side by side:

  • registered Chinese company on the current record;
  • seller or contract party;
  • invoice issuer;
  • beneficiary legal name;
  • account-change authorizer.

If they differ, collect a written explanation, relationship evidence, amended transaction documents where appropriate, and an independently confirmed authorization. The guide to checking a Chinese supplier beneficiary covers this relationship in depth. For an invoice-name issue, use the separate invoice mismatch workflow.

Official U.S. Commercial Service guidance treats company existence, address, contact details, and red flags as part of an initial background check, while distinguishing that check from deeper in-country diligence. Read the background-check guidance. A supplier identity check and a bank instruction check support each other, but neither replaces the other.

Do not let weak controls create false comfort

A test payment

A small transfer confirms only that money can reach the account and perhaps that someone can observe it. It does not establish who controls the account, whether the relationship is authorized, or whether the next instruction will remain unchanged.

A bank letter or screenshot

A file can be altered, outdated, or issued for a different entity. Treat it as one item to compare, not as independent confirmation. Verify material account changes through the established contact and your own bank procedures.

A reply from the usual email address

A compromised mailbox can send and receive replies. Moving the same conversation to another message inside that account does not create an independent channel.

An urgent manager approval

Internal approval cannot cure missing external evidence. If the beneficiary changed, the verifier should close the change-control steps before an approver accepts the commercial risk.

Clock 2: the 30-minute release record

Immediately before release, save one compact record:

Control Release evidence Hold condition
Supplier identity Chinese name and USCC matched to the intended entity No reliable identity or wrong company
Transaction parties Contract, invoice, and beneficiary names compared Unexplained entity difference
Instruction continuity Current details equal approved baseline Any unverified change
Independent confirmation Known contact route, call note, second contact when required Only disputed email or new phone available
Internal authority Required approvers and exception owner recorded Pressure to bypass policy
Bank entry Maker and checker compare entered details with approved record Manual entry differs from approval packet

Use the operational wire-transfer release checklist for a routine unchanged payment. If the bank details changed, switch to the dedicated changed-bank-details procedure. The change should not be buried as one checked box in an otherwise normal payment.

Clock 3: the first hour after a suspected misdirection

If the team discovers that money may have gone to the wrong account, speed matters. Contact the originating financial institution immediately, state that the transfer may be fraudulent, and request its recall or reversal process. IC3 also advises asking the originating institution to contact the recipient institution; it notes that recovery is not guaranteed.

At the same time:

  1. stop any pending or scheduled payments using the disputed details;
  2. preserve the original emails with headers, attachments, chat messages, invoices, bank confirmation, and approval logs;
  3. notify your security, finance, legal, insurer, and management contacts under the incident plan;
  4. contact the genuine supplier through previously known channels without using the suspect thread;
  5. report through the applicable law-enforcement and cybercrime channels for your jurisdiction; U.S. victims can use IC3;
  6. protect potentially compromised mailboxes, review forwarding rules and sessions, and reset credentials through the security team.

Do not delete the suspicious conversation, negotiate with an unknown recipient, or delay the bank call while trying to prove exactly how the compromise occurred.

Make the next payment safer

After any attempted or actual diversion, review both sides of the process: supplier onboarding data, bank-change authority, email security, multifactor authentication, mailbox forwarding alerts, payment thresholds, maker-checker separation, and how staff find independent contact details.

For the full document packet, use the documents to collect before a supplier wire. For broader company and operating warning signs, use the supplier red-flags guide. Keeping those tasks separate prevents a clean registry result from being mistaken for authentication of a changed bank instruction.

This article provides general payment-control and incident-preparation information. It does not provide banking, legal, cybersecurity, insurance, or recovery advice for a specific transfer.