Trace whether the supplier's email was hacked or whether you were spoofed.
What to do
- Compare the sender's email header (Return-Path / Received) with previous legitimate emails — look for one-character lookalikes
- Call the supplier on a phone number you already had — confirm whether they sent the changed bank details
- Check your own mailbox for any new forwarding rules, hidden filters or 'mark as read' rules
- Save the original email and any thread leading to the changed bank details
Was this guide helpful?
Know someone who needs this? Send them the guide.
JD
Written by
Jordan DicksonFounder, CyberSecurityGuides
Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.
Reviewed by CSG Security Engineers