Suspected Payment Fraud Response Checklist
Purpose
Use this checklist when the company suspects that money may have been redirected, a fraudulent payment may have been made, or an attacker may be attempting to manipulate a financial process.
Examples include:
- Invoice fraud
- Supplier impersonation
- Business email compromise
- Executive impersonation
- Payroll diversion
- Fraudulent refunds
- Unauthorized bank-detail changes
- Payment account compromise
Speed matters. Financial institutions may have a greater chance of stopping or recovering money when contacted quickly.
Incident Information
Incident ID: ____________________
Date/time discovered: ____________________
Reported by: ____________________
Finance incident owner: ____________________
Cybersecurity / IT owner: ____________________
1. Stop Further Payments
Immediately consider:
-
Hold related payments.
-
Stop pending transactions where possible.
-
Prevent additional payments to the suspicious account.
-
Temporarily restrict affected payment processes if necessary.
-
Alert appropriate finance personnel.
Do not continue normal payments while the destination or requester remains in doubt.
2. Contact the Bank or Payment Provider
If money has already been sent:
-
Contact the bank or payment provider immediately.
-
Use the official fraud or emergency contact channel.
-
Request recall, freeze, cancellation, or recovery action where available.
-
Provide transaction details.
-
Obtain a case/reference number.
-
Record instructions received.
Bank/provider: ____________________
Contacted at: ____________________
Contact person: ____________________
Reference number: ____________________
Action requested: ____________________
3. Verify the Genuine Party
Contact the legitimate supplier, employee, customer, or executive through previously trusted contact details.
Determine:
-
Whether they actually requested the payment or change.
-
Whether their email account may be compromised.
-
Correct payment details.
-
When legitimate communications last occurred.
-
Whether other fraudulent requests may have been sent.
Do not rely on contact details contained only in the suspicious communication.
4. Preserve Evidence
Preserve relevant:
- Emails
- Email headers where available
- Attachments
- Chat messages
- Payment instructions
- Invoices
- Bank transaction records
- Authentication logs
- Mailbox audit logs
- MFA records
- Forwarding rules
- Payment system logs
- Approval records
- Screenshots
Do not delete suspicious messages or accounts before evidence requirements are considered.
5. Secure Potentially Compromised Accounts
If account compromise is suspected:
- Revoke active sessions
- Reset compromised credentials
- Verify MFA settings
- Review MFA devices and recovery methods
- Review mailbox forwarding rules
- Review inbox rules
- Review mailbox delegates
- Review suspicious OAuth or third-party applications
- Review recent logins
- Review administrator changes
- Search for similar activity on other accounts
Do not assume changing the password alone resolves the compromise.
6. Determine the Scope
Establish:
-
How many fraudulent messages were sent? ____________________
-
How many payments were affected? ____________________
-
Total potential exposure: ____________________
-
Confirmed loss: ____________________
-
Other recipients contacted by attacker: ____________________
-
Other accounts potentially compromised: ____________________
-
Other bank-detail changes: ____________________
-
Other suspicious transactions: ____________________
7. Notify Appropriate Parties
Depending on the situation, consider notifying:
- Leadership
- IT / MSP
- Cybersecurity provider
- Cyber insurer
- Legal counsel
- Affected vendor or customer
- Payroll provider
- Payment processo
- Law enforcement or relevant fraud authority where appropriate
Record notifications in the Incident Communication Log.
8. Protect Other Transactions
Review:
- Recent bank-detail changes
- Pending payments
- High-value payments
- New suppliers
- Payroll changes
- Customer refunds
- Other transactions involving the affected parties
- Similar requests received by other employees
Warn relevant finance employees about the active fraud pattern without unnecessarily distributing sensitive incident details.
9. Record the Financial Impact
Transaction date: ____________________
Amount: ____________________
Currency: ____________________
Destination: ____________________
Bank reference: ____________________
Amount recovered: ____________________
Amount outstanding: ____________________
Insurance claim reference: ____________________
Other costs: ____________________
10. Correct the Control Failure
After immediate response, determine how the fraud succeeded or nearly succeeded.
Consider improvements such as:
- Independent bank-detail verification
- Stronger transaction approvals
- Separation of duties
- MFA improvements
- Better email security
- Mailbox monitoring
- Finance staff training
- Supplier verification procedures
- Stronger payroll change verification
- Executive impersonation procedures
- Reduced account privileges
Action: ____________________
Owner: ____________________
Due date: ____________________
11. Complete Post-Incident Review
Once immediate financial and cybersecurity risks are controlled:
- Complete the incident timeline
- Confirm financial outcome
- Document root cause
- Identify failed controls
- Assign improvement actions
- Preserve required evidence
- Review lessons with finance and leadership
- Update relevant procedures
Practical Rule
If payment fraud is suspected, act immediately:
Stop the money, contact the bank, verify the genuine party, preserve the evidence, secure the accounts, and look for other affected transactions.