Home / Blog / The Account-Change Email

The Account-Change Email: Recovering Diverted Payments (BEC in China Trade)

The supplier's "new bank details" email looked perfect because it was — just not from the supplier. Business email compromise drains China-bound trade payments every week, and the first 24 hours decide whether the money comes back. Here is the playbook, the legal claims, and the prevention stack.

If you buy from China, assume someone is reading your supplier's inbox — or yours. The balance wire on a finished order is the single most attractive target in international trade: goods exist, inspection passed, the amount is large, and everyone is waiting for exactly one email. When that email arrives and says "our bank account has changed," you are thirty seconds away from funding a heist — unless your process stops it. Here is how the theft actually runs, what to do in the first 24 hours, and how to make sure you are never the buyer who pays it.

1. The Heist, Minute by Minute

The attack is patient and boring. The attacker compromises a mailbox — the supplier's sales manager's, sometimes yours — and then does nothing. For weeks. They read: the project names, the payment milestones, the tone your supplier uses, who approves wires, when the balance falls due. Silence costs them nothing.

How do mailboxes get compromised? Rarely by anything exotic: password reuse across services, a phishing login page for a webmail provider, malware on the bookkeeper's machine, or an auto-forwarding rule quietly added after one clever message. The supplier almost never knows until it is too late — which is why the attack reads so authentically. The words really are your supplier's; the intent is not.

Then, when the balance payment comes due, they send the email: "our bank has been changed, please note our new account for the remaining payment." The right thread, the right logo, the right signature block, a plausible reason — an audit, a tax check, an account upgrade. Sometimes the domain is one character off, and a careful eye catches it; more often the real mailbox is already owned, and no spoofing is involved at all.

The money's path is just as rehearsed: land in a receiving account, hop to one or two more layering accounts within hours, then out — withdrawn in cash, converted to crypto, scattered through payment platforms. By the time the real supplier asks where its money is — often days later, when the goods have not shipped — the trail is cold. This is business email compromise, and China-bound trade payments are a favorite target because the sums are large, the timing is predictable, and the two parties sit on different continents, in different time zones, trusting one mailbox.

2. The Golden Hours: What to Do First

Everything about this crime argues for speed. Layered funds are a legal problem; intercepted funds are an administrative one. The first 24 hours decide which kind you have. In order:

  1. Recall request through your bank — immediately. Give full beneficiary details — account name, account number, bank, amount, date — and designate the transfer as fraud. Chinese receiving banks can intercept funds still sitting in the receiving account, and your bank reaches theirs through formal interbank channels. Every hour the money sits still is an hour it can be stopped; once it hops, the odds collapse.
  2. Report to Chinese police — in the jurisdiction of the receiving bank. Use the fastest channel available, including the national anti-fraud reporting channels. A fraud report can trigger emergency stop-payment and freezing of the receiving and layering accounts — an administrative mechanism built for exactly this race, which lets police instruct banks to hold suspect funds fast. It exists because of the speed of the theft; use it because of the speed of the theft.
  3. Notify the supplier's bank through the supplier — and have the supplier's IT people kill the compromised mailbox's forwarding rules before anything else moves through it.
  4. Preserve everything before touching anything. Original emails with full headers, the wire confirmation, the contract, the chat history around the payment. Evidence hygiene: how to keep chat and email records that survive scrutiny.

Say it once more, because it is the whole article: the recall and the police report are hour-one actions, not day-after actions.

On paper, the law is clean. Whoever receives money without legal basis must return it: Article 985 of the PRC Civil Code is the unjust-enrichment rule, and Article 987 adds teeth for the bad-faith recipient — they return the benefit and compensate your losses. The account that took your diverted wire is, on paper, exactly that bad-faith recipient.

The problem is who the recipient usually is. Receiving accounts are sold and rented: a student, a farm worker, a retiree who handed over a bank card for a few hundred yuan. The account holder is a "sold" identity, and suing them produces a judgment against a person with nothing — the real controller stays invisible until police work surfaces them. That is why speed beats litigation in this crime: the emergency freeze in the first day reaches money that a lawsuit filed in the first month cannot. Where the criminal track runs, recovery comes through restitution in that process — the two tracks are compared here: civil claim or criminal report.

The bank's own liability is narrow in practice. A bank that executed an ordinary transfer on valid instructions rarely bears the loss; exceptions exist — actual knowledge, participation — but plan around the rule, not the exception. Commercially, the lesson is blunt: your claim is against the fraudster and whoever holds the funds now, not against the payment system, and that is a recovery race decided in hours, not months.

Where the perpetrator is prosecuted, recovery for victims runs through restitution within the criminal process — ordered against the fraudster out of whatever is recovered, subject to the victim-status mechanics compared in the article above. Treat it as a possibility, not a plan. The plan is the freeze.

4. The Prevention Stack

Every layer below has stopped real attacks. The stack works because no single layer needs to be perfect:

LayerWhat it looks likeWhy it works
Bank details as a chopped annexAccount name and number fixed in a contract annex stamped with the company chop; changes only by a re-issued, re-chopped annex delivered through a verified channelAn email "update" is simply not a valid instruction — the account is a contract term. The discipline: the account-name test
Dual-channel callbackAny proposed change → call the phone number in the original contract — never a number from the email — and confirm with a known personBreaks the attack's core premise: the attacker controls email, not the phone
Email-domain hygieneLook-alike domain checklist (rn/m, .co/.com, added hyphens); DMARC, DKIM and SPF enforced on your own domainCatches spoofing — and stops your own mailbox from being weaponized against your clients
Milestone sizingNo single wire large enough to fund a heist; more, smaller milestones sized to real progressCaps the maximum loss and buys the hours that save the money. Deposit and milestone logic: deposits and payment milestones
Supplier-side screeningTest payment-process discipline during onboarding; a supplier that resists the chopped annex or refuses callbacks is telling you somethingThe attacker needs a sloppy process; starve the attack of one: supplier verification

One more discipline that costs nothing: log every payment instruction as an event. When an "update" arrives, the question "does this match the last re-issued annex, and was that annex verified?" should take one minute to answer from your file — not one week of archaeology.

5. If You Already Paid the Wrong Account

The do-nots first, because both of them cost victims money every single week:

  • Don't email the hacked mailbox. If the supplier's mailbox is compromised, every update you send — including "we are reporting this to the police" — goes straight to the attacker, who adjusts accordingly. Switch to a channel you verify independently, and verify it against the original contract, not against instructions that arrive in the compromised thread.
  • Don't pay "release fees." Anyone who contacts you posing as customs, police, the bank or a "recovery department" and asks for money to unfreeze or release the funds is running the second wave of the same scam. Chinese authorities do not collect fees from victims through wires to individuals — ever.

The do-sequence:

  1. Assume compromise. Change passwords from a clean device, kill forwarding rules, lock down your own domain's email authentication.
  2. Run the golden-hours playbook — recall request, police report, evidence preservation — in that order, starting in minute one.
  3. Map the receiving account — holder name, bank, jurisdiction. That is the anchor for the police report and for any civil claim downstream.
  4. Decide tracks with counsel quickly. If a real recipient with assets can be identified, a civil claim exists — but price it honestly against what it can actually recover: what a China claim actually costs.
  5. Face the uncomfortable question early. Sometimes the "supplier" and the fraudster are the same people; sometimes the supplier was genuinely hacked. The distinction matters for what you claim and against whom — and it is established by evidence, not by whose story is more comfortable.

6. The Insurer Angle

Check your policies. Cyber and crime policies increasingly cover social-engineering and funds-transfer-fraud loss — sometimes under a specific endorsement you have to ask for; trade credit insurance generally does not touch this. Coverage turns on notification deadlines measured in days, which is one more reason the police report matters: insurers ask for it. If you pay Chinese suppliers on open account with any regularity, have the conversation with your broker this week, not after the next incident.

CH

Chen Hang, Attorney-at-Law

Shanghai Landing (Fuzhou) Law Office. Dual degrees in law and accounting (UIBE); LL.M., Universidad Pontificia Comillas (Spain). Over RMB 3 billion in financial and commercial matters handled. More about me →

This article is general information, not legal advice, and does not create an attorney–client relationship. Recovery of diverted funds depends on timing, jurisdiction and facts that no article can predict. Nothing here is a guarantee of results.

Is your next balance wire protected against this?

Send me your current contract and payment process, and I will show you where the account-change hole is — and hand you the chopped-annex clause that closes it. The fix costs less than one lost wire, and it starts with verifying who is really behind the mailbox.

Verify before the next wire
This page is general information, not legal advice.