A familiar carrier email is not enough to approve new payment instructions. Use this short process to verify the change, document approval, and protect freight payments.
Why a familiar email is not enough
The load was delivered. The invoice matches. Then an email arrives: “Our bank details have changed. Please use the attached instructions for today’s payment.”
For an owner, office manager, or accounts-payable employee, that creates a separate decision: who authorized the change, and where will the money actually go? A correct invoice does not authenticate a new bank account.
The FBI’s business email compromise guidance explains that criminals can imitate trusted senders or gain access to legitimate billing conversations. An authentic-looking thread can therefore carry fraudulent instructions.
Pause whenever a carrier changes an ACH or wire destination, payee, remittance address, or factoring arrangement—or asks you to skip normal approval because payment is urgent. These changes can be legitimate, but email alone does not prove that.
The freight payment verification checklist
Use this process whenever carrier bank details, payee information, remittance instructions, or factoring arrangements change. The goal is to hold the change, independently verify it, and record who approved it.
- Hold the change. Flag the invoice and proposed vendor-record change. Keep the existing payment record until verification is complete.
- Call a known contact. Use a number from onboarding or an established business record—not the request, attachment, or follow-up message. Confirm what changed, why, when it starts, and which invoices it covers.
- Verify the payee and destination. Compare the legal payee, carrier record, invoices, effective date, and bank details through your approved secure process.
- Handle factoring changes separately. Review the notice of assignment, any release, and current payment obligations. Contact the carrier and factor independently. Escalate conflicts to the person responsible for contracts or legal review.
- Get a second approval. The reviewer should check the callback record, documents, payee, and destination before the payment is released.
- Keep the original payment instructions and change history available while investigating.
- Never use contact details supplied only by the new payment request.
- Compare carrier, invoice, payee, factoring, and payment records before approving the change.
- Escalate conflicts instead of choosing the account that seems most convenient.
A short callback script your team can use
“We received a request to change payment instructions for invoices [references]. Did your company request this change? Which invoices and effective date does it cover? We will verify the destination through our established process and obtain internal approval before releasing payment.”
An inbound call from someone claiming to confirm the change does not replace your independent callback. For related load, account, and dispatch checks, see Freight Broker Email Security: How to Verify Load and Payment Changes.
What if the payment has already been sent?
Contact your bank’s fraud team immediately. Explain the suspected payment diversion and ask about recall or recovery options and contact with the receiving institution. The FBI also recommends reporting business email compromise to IC3; recovery is not guaranteed.
Preserve the original messages, attachments, transaction references, and verification notes. Notify your internal incident lead and the legitimate business contact through a trusted channel. Have your IT provider or security team investigate suspected account compromise and follow applicable incident-reporting procedures. Do not wait for the technical investigation before contacting the bank.
Give staff a chance to practice before a real request arrives
A checklist helps only when people know when to use it. Walk through a fictional payment-change request and ask: who holds the change, where is the trusted number, and who approves release?
Managed Phishing Testing & Staff Training can reinforce recognition and reporting with controlled invoice or remittance-change scenarios. Your team still needs to practice the callback and payment-approval process.
What to record before releasing payment
Keep the verification record with the invoice or vendor-change request. Store full banking details only in the restricted payment system; general notes can reference that record without duplicating sensitive information.
| Check | Evidence to request | Suggested owner |
|---|---|---|
| Requested change | Carrier or payee, affected invoices, and effective date | Accounts payable coordinator |
| Independent contact | Person reached, role, and source of the callback number | Employee performing verification |
| Verification | Date, what was confirmed, and any unresolved discrepancy | Employee performing verification |
| Supporting evidence | Relevant carrier, factoring, assignment, release, and invoice documents | Accounts payable and contracts owner |
| Approval | Reviewer, decision, and approval date | Second approver |
| Payment check | Confirmation that the approved destination matches the payment being released | Payment approver |
Related resources
Want help deciding what to do next?
Start with the free Zero-Access Business Exposure Review to see what outsiders can observe about your business email, domains, and internet-facing services. If you need internal safeguards verified—such as Microsoft 365 identity, mailbox rules, MFA, backups, and logging—the $1,995 Business Security Baseline is the next step for businesses with up to 25 employees. For staff practice, ask about Managed Phishing Testing & Staff Training.
