Suspected Payment Fraud Response Checklist

Purpose

Use this checklist when the company suspects that money may have been redirected, a fraudulent payment may have been made, or an attacker may be attempting to manipulate a financial process.

Examples include:

  • Invoice fraud
  • Supplier impersonation
  • Business email compromise
  • Executive impersonation
  • Payroll diversion
  • Fraudulent refunds
  • Unauthorized bank-detail changes
  • Payment account compromise

Speed matters. Financial institutions may have a greater chance of stopping or recovering money when contacted quickly.

Incident Information

Incident ID: ____________________

Date/time discovered: ____________________

Reported by: ____________________

Finance incident owner: ____________________

Cybersecurity / IT owner: ____________________

1. Stop Further Payments

Immediately consider:

  • Hold related payments.

  • Stop pending transactions where possible.

  • Prevent additional payments to the suspicious account.

  • Temporarily restrict affected payment processes if necessary.

  • Alert appropriate finance personnel.

Do not continue normal payments while the destination or requester remains in doubt.

2. Contact the Bank or Payment Provider

If money has already been sent:

  • Contact the bank or payment provider immediately.

  • Use the official fraud or emergency contact channel.

  • Request recall, freeze, cancellation, or recovery action where available.

  • Provide transaction details.

  • Obtain a case/reference number.

  • Record instructions received.

Bank/provider: ____________________

Contacted at: ____________________

Contact person: ____________________

Reference number: ____________________

Action requested: ____________________

3. Verify the Genuine Party

Contact the legitimate supplier, employee, customer, or executive through previously trusted contact details.

Determine:

  • Whether they actually requested the payment or change.

  • Whether their email account may be compromised.

  • Correct payment details.

  • When legitimate communications last occurred.

  • Whether other fraudulent requests may have been sent.

Do not rely on contact details contained only in the suspicious communication.

4. Preserve Evidence

Preserve relevant:

  • Emails
  • Email headers where available
  • Attachments
  • Chat messages
  • Payment instructions
  • Invoices
  • Bank transaction records
  • Authentication logs
  • Mailbox audit logs
  • MFA records
  • Forwarding rules
  • Payment system logs
  • Approval records
  • Screenshots

Do not delete suspicious messages or accounts before evidence requirements are considered.

5. Secure Potentially Compromised Accounts

If account compromise is suspected:

  • Revoke active sessions
  • Reset compromised credentials
  • Verify MFA settings
  • Review MFA devices and recovery methods
  • Review mailbox forwarding rules
  • Review inbox rules
  • Review mailbox delegates
  • Review suspicious OAuth or third-party applications
  • Review recent logins
  • Review administrator changes
  • Search for similar activity on other accounts

Do not assume changing the password alone resolves the compromise.

6. Determine the Scope

Establish:

  • How many fraudulent messages were sent? ____________________

  • How many payments were affected? ____________________

  • Total potential exposure: ____________________

  • Confirmed loss: ____________________

  • Other recipients contacted by attacker: ____________________

  • Other accounts potentially compromised: ____________________

  • Other bank-detail changes: ____________________

  • Other suspicious transactions: ____________________

7. Notify Appropriate Parties

Depending on the situation, consider notifying:

  • Leadership
  • IT / MSP
  • Cybersecurity provider
  • Cyber insurer
  • Legal counsel
  • Affected vendor or customer
  • Payroll provider
  • Payment processo
  • Law enforcement or relevant fraud authority where appropriate

Record notifications in the Incident Communication Log.

8. Protect Other Transactions

Review:

  • Recent bank-detail changes
  • Pending payments
  • High-value payments
  • New suppliers
  • Payroll changes
  • Customer refunds
  • Other transactions involving the affected parties
  • Similar requests received by other employees

Warn relevant finance employees about the active fraud pattern without unnecessarily distributing sensitive incident details.

9. Record the Financial Impact

Transaction date: ____________________

Amount: ____________________

Currency: ____________________

Destination: ____________________

Bank reference: ____________________

Amount recovered: ____________________

Amount outstanding: ____________________

Insurance claim reference: ____________________

Other costs: ____________________

10. Correct the Control Failure

After immediate response, determine how the fraud succeeded or nearly succeeded.

Consider improvements such as:

  • Independent bank-detail verification
  • Stronger transaction approvals
  • Separation of duties
  • MFA improvements
  • Better email security
  • Mailbox monitoring
  • Finance staff training
  • Supplier verification procedures
  • Stronger payroll change verification
  • Executive impersonation procedures
  • Reduced account privileges

Action: ____________________

Owner: ____________________

Due date: ____________________

11. Complete Post-Incident Review

Once immediate financial and cybersecurity risks are controlled:

  • Complete the incident timeline
  • Confirm financial outcome
  • Document root cause
  • Identify failed controls
  • Assign improvement actions
  • Preserve required evidence
  • Review lessons with finance and leadership
  • Update relevant procedures

Practical Rule

If payment fraud is suspected, act immediately:

Stop the money, contact the bank, verify the genuine party, preserve the evidence, secure the accounts, and look for other affected transactions.