Bank Account Detail Switch Scam
Verdict: Suspicious | Risk Score: 8/10 | Severity: high
Category: UPI, WhatsApp, Phishing
How Bank Account Detail Switch Scam Works
Overview: In this widespread business payment scam, criminals impersonate legitimate vendors and send messages to companies, claiming their bank account or UPI details have changed. The unsuspecting buyer then updates their records and sends future payments to the fraudster's account, resulting in major financial losses. This scam exploits trust, normal day-to-day accounting operations, and India’s reliance on quick digital payments. It is especially risky because staff often assume such requests are genuine, particularly during real-life bank mergers, system upgrades, or policy changes. How It Works: Step 1: Criminals gather information about the company and its suppliers from public sources, LinkedIn, or previous data breaches. Step 2: The fraudster contacts finance staff using an email with a similar domain or via WhatsApp, imitating the supplier’s official number. Step 3: The message claims that, due to a bank merger, policy change, or technical error, future invoice payments should be sent to a new account or UPI ID. Step 4: The victim, believing the request is legitimate, updates the vendor payment instructions and pays invoices to the fraudulent account. Step 5: By the time the real vendor follows up, payments are unrecoverable and the scammers have withdrawn the funds. India Angle: Designed for India’s business landscape, this scam is common in cities with heavy manufacturing, distribution, or logistics activity—like Chennai, Surat, and Kolkata. Fraudsters use WhatsApp, email, or even phone calls, claiming urgent transitions due to RBI rules or banking updates. The scam especially targets SMEs, which may lack rigorous verification processes. Real Examples: - A Mumbai SME received an email stating their supplier’s bank had merged with another bank, requesting all future payments be rerouted to a ‘new’ account. The email looked convincing, complete with digital signatures. - An accounts officer in Hyderabad got a WhatsApp message with a QR code and new UPI ID, supposedly from a trusted vendor contact, citing ‘technical issues’ with the old account. Red Flags: - Messages about new bank details without prior notice or face-to-face conversation. - Requests for immediate update of vendor payment records, especially for large sums. - Unverified QR codes or UPI IDs in WhatsApp/email from unfamiliar contacts. - Claims of ‘regulatory update’, ‘bank merger’, or ‘emergency situation’ demanding an urgent switch. Protective Measures: - Always confirm changes to bank or UPI details directly with the vendor using their official, pre-verified phone number. - Implement a mandatory dual-approval process for changes to vendor payment records. - Verify any new account details through a test payment and direct confirmation before major transfers. - Educate all finance team members about these scam patterns and the importance of verification. - Never update payment instructions solely based on email or WhatsApp messages. If Victimised: - Contact your bank instantly to request a transfer hold and begin the recovery process. - Collect all fraud-related messages, emails, and payment receipts. - File an official complaint with 1930 and upload evidence to cybercrime.gov.in. - Notify the real vendor and check if they are also compromised. Related Scams: - Fake Vendor Invoice Scam: Scammers send entirely fake invoices demanding urgent payment. - Phishing Payment Portal Fraud: Victims are tricked into transferring funds via fake, lookalike supplier portals. - Internal Collusion: Employees working with scammers update supplier records dishonestly.
How This Scam Works — Detailed Explanation
The Bank Account Detail Switch Scam is a fraud that exploits the trust businesses place in their suppliers. Scammers typically identify potential targets—companies that frequently make payments to vendors—through social media platforms like LinkedIn or through public business directories. Once a target is identified, the scammers either impersonate existing vendors using fake emails or WhatsApp accounts or create a fake vendor profile altogether. They send messages to the companies, claiming that due to a recent bank merger or a technical upgrade, the recipient's bank account or UPI details have changed. In an increasingly digital landscape where UPI transactions are common, this scam is particularly effective, leveraging the trust and urgency that businesses operate under.
To execute the scam effectively, fraudsters employ several psychological tactics. For instance, they instill a sense of urgency by claiming that immediate action is required to avoid disruptions in the service. They often cite a fabricated technical problem or an internal policy change, pressuring staff to act quickly without looking for proper verification. This tactic plays on the fear of business disruption, making employees feel they must comply to maintain business operations. In many cases, staff may assume such requests are legitimate, especially when they are in familiar settings, like using WhatsApp for communication.
Once the unsuspecting employee receives a message, they typically follow the instructions without conducting proper verification. For instance, in one noted case of a logistics company in Mumbai, an employee was fooled into switching payment details after receiving a WhatsApp message claiming the vendor's bank account had changed due to a merger. As a result, the employee routed a significant payment of ₹50 lakh to the fraudster’s account instead of the legitimate vendor's. Victims often realize too late that the money has vanished, typically only after receiving reminders or invoices for the unpaid services from the actual vendor.
The financial impact of the Bank Account Detail Switch Scam has been staggering. In India, such scams have resulted in losses amounting to ₹100 crore in recent years, according to reports from the Ministry of Home Affairs (MHA) and RBI. Cybercrime statistics from CERT-In also point out that incidents related to this type of fraud are on the rise, highlighting the urgent need for businesses to be aware and vigilant. The enforcement agencies are also expanding their capabilities to track such scams, but the responsibility ultimately lies with the businesses to protect their financial transactions.
Identifying legitimate communications as opposed to fraudulent requests is crucial. Always verify changes through a secondary channel—like a phone call to the vendor's known contact number—before making any updates to payment details. Look out for red flags, such as sudden requests for changes through email or WhatsApp or any pressure tactics insisting on immediate action. In addition, proper protocols like requiring dual confirmations or approval from management can help safeguard against falling prey to these types of scams.
Visual Intelligence:
BharatSecure's AI has identified this as a used in scams targeting Indian users.
Who Does Bank Account Detail Switch Scam Target?
General public across India
Red Flags — How to Identify Bank Account Detail Switch Scam
- Requests to update bank or UPI details via email or WhatsApp
- Claims of bank merger or technical upgrade requiring urgent payments
- Lack of verification or dual confirmation for account changes
- Pressure to reroute high-value transactions immediately
What To Do If You Encounter Bank Account Detail Switch Scam
- Report the incident immediately to the cybercrime helpline at 1930 or visit cybercrime.gov.in.
- Contact your bank's fraud department to freeze any ongoing payments and protect your account.
- Inform your organization’s management to ensure all staff are aware of the potential scam.
- Cross-check payment details with vendors before processing any transactions.
- Check with colleagues about any similar communication received regarding payment updates.
- Install security software on your devices to help detect potential phishing attempts.
How to Report Bank Account Detail Switch Scam in India
- Call 1930 — National Cyber Crime Helpline (24x7)
- File a complaint at cybercrime.gov.in
- Contact your bank immediately if money was lost
- Call RBI helpline: 14440 for banking fraud
Frequently Asked Questions
- What to do if I shared my bank account details with a scammer?
- Immediately contact your bank's customer service to block your account and report the incident. You can also call the cybercrime helpline at 1930 for further assistance.
- How to identify if this is a scam when I receive a message about changing bank details?
- Look for red flags like urgency, unsolicited communication, or lack of proper channels for verification. Always contact known representatives for confirmation.
- How do I report a Bank Account Detail Switch Scam in India?
- You can report the scam at the cybercrime helpline 1930 or file a report online at cybercrime.gov.in. Additionally, notify your bank about the fraudulent activity.
- Can I recover money lost in the Bank Account Detail Switch Scam?
- Recovery can be challenging but report the transaction to your bank immediately and to the cybercrime helpline. Provide them with all details for potential recovery actions.
Verify Any Suspicious Message
Check any suspicious message, link, or call for free at bharatsecure.app. BharatSecure uses AI to detect scams in real-time and protect Indian users.