K. Araya Suksawat
Head of Compliance & Investigations
Former economic-crime investigator specializing in cross-border trade fraud; leads due diligence and fraud-prevention engagements across ASEAN.
Short answer
Payment fraud in international trade centers on business email compromise (BEC) and invoice manipulation: attackers intercept or spoof supplier communications and divert payments to controlled accounts. The controls that work are procedural — out-of-band verification of any banking detail change, dual approval for payments above thresholds, whitelisted beneficiary accounts, and payment terms that favor escrow or LC instruments over open wire transfers. When diversion occurs, speed is everything: SWIFT recall requests within 24–48 hours are the primary recovery mechanism.
How Payment Diversion Attacks Work
- Business email compromise — attackers compromise the supplier's actual email account and send authentic-looking banking changes from a trusted address
- Lookalike domains — invoices from 'supplier-corp.com' when the real domain is 'suppliercorp.com'
- Invoice interception — attackers positioned in the email thread inject a modified invoice with their account details at payment time
- Internal spear-phishing — your own finance staff is tricked into believing the CEO or supplier has urgently changed accounts
- Malware-altered invoices — local malware rewrites PDF bank details on invoices as they are opened or saved
The common denominator: the payment instruction arrives through the same channel as everything else — email — and is accepted on channel authority rather than verified content. Attackers exploit the assumption that an email from a known address is trustworthy. In BEC cases, it genuinely is the known address; the account behind it is compromised.
Controls That Cut the Attack Surface
- Out-of-band verification: any banking detail change is confirmed by phone to a number sourced independently — never to a number in the change email itself
- Dual approval: payments above a threshold require two authorized approvers with independent verification
- Beneficiary whitelisting: payments execute only to pre-verified accounts; new beneficiaries require a documented verification workflow
- Payment instrument discipline: escrow and LC structures route payment through verified institutional channels rather than direct wires to changing accounts
- Email hygiene: external-sender banners, DMARC enforcement, and prohibition of payment instruction changes via email-only channels
- Rehearsed response: staff trained that urgency plus payment equals verification, not compliance
Payment Instrument Risk Ranking
| Instrument | Diversion Exposure | Why |
|---|---|---|
| Advance wire transfer | Highest — irreversible once credited | Funds move directly to beneficiary; recall depends on recipient bank cooperation |
| Open account settlement | High — recurring wires to potentially changed accounts | Multiple payment events multiply interception opportunities |
| Documentary collection | Moderate — banks channel documents and payment | Bank involvement adds identity friction but no payment guarantee |
| Letter of credit | Lower — payment against documents through bank channels | Beneficiary identity fixed in the credit; amendments require bank processing |
| Escrow | Lower — funds held by licensed institution, released on verified conditions | Beneficiary verified at onboarding; release conditions block diversion |
Instrument choice is fraud policy: every structure that interposes a verified institution between your payment instruction and the recipient's account reduces diversion exposure. This is an underappreciated argument for escrow and LCs — their value isn't only commercial risk allocation, it's payment channel integrity.
When Diversion Happens: Recovery Steps
- 1Notify your bank immediately and request a SWIFT recall (MT192) — recovery probability drops sharply after 48–72 hours
- 2Request the beneficiary bank to freeze the credited funds pending investigation — many jurisdictions honor this briefly on fraud notification
- 3File reports with police and cybercrime authorities in your jurisdiction and the recipient jurisdiction
- 4Preserve all communications and payment records as evidence
- 5Notify the genuine supplier — they may hold leverage with the recipient bank or local authorities
- 6Engage counsel in the recipient jurisdiction; asset preservation orders may be available within days
Recovery is a race against the fraudster's withdrawal speed, and honesty about odds matters: full recovery is uncommon, partial recovery through early freezes happens with reasonable frequency, and late notification almost guarantees total loss. The operational lesson is that response runbooks — drafted before any incident — compress the critical first hours.
Key takeaways
- BEC and invoice manipulation dominate payment fraud — the email channel itself is the vulnerability.
- Out-of-band verification of banking changes is the single highest-value control.
- Payment instruments with institutional channels (escrow, LC) structurally reduce diversion exposure.
- Dual approval and beneficiary whitelisting convert policy into enforced procedure.
- After diversion, SWIFT recall within 48 hours is the primary recovery lever — speed is everything.
Frequently asked questions
A fraud where attackers compromise or spoof a legitimate business email account — often the supplier's real account — and use its trust to redirect payments. Because the email comes from a genuine address with authentic history, content-based suspicion rarely triggers; only out-of-band verification reliably catches it.
Related services
Join the discussion
Questions about how this applies to your shipment or transaction? Our specialists read every inquiry.
Ask a specialist