The supplier's "new bank details" email looked perfect because it was — just not from the supplier. Business email compromise drains China-bound trade payments every week, and the first 24 hours decide whether the money comes back. Here is the playbook, the legal claims, and the prevention stack.
If you buy from China, assume someone is reading your supplier's inbox — or yours. The balance wire on a finished order is the single most attractive target in international trade: goods exist, inspection passed, the amount is large, and everyone is waiting for exactly one email. When that email arrives and says "our bank account has changed," you are thirty seconds away from funding a heist — unless your process stops it. Here is how the theft actually runs, what to do in the first 24 hours, and how to make sure you are never the buyer who pays it.
The attack is patient and boring. The attacker compromises a mailbox — the supplier's sales manager's, sometimes yours — and then does nothing. For weeks. They read: the project names, the payment milestones, the tone your supplier uses, who approves wires, when the balance falls due. Silence costs them nothing.
How do mailboxes get compromised? Rarely by anything exotic: password reuse across services, a phishing login page for a webmail provider, malware on the bookkeeper's machine, or an auto-forwarding rule quietly added after one clever message. The supplier almost never knows until it is too late — which is why the attack reads so authentically. The words really are your supplier's; the intent is not.
Then, when the balance payment comes due, they send the email: "our bank has been changed, please note our new account for the remaining payment." The right thread, the right logo, the right signature block, a plausible reason — an audit, a tax check, an account upgrade. Sometimes the domain is one character off, and a careful eye catches it; more often the real mailbox is already owned, and no spoofing is involved at all.
The money's path is just as rehearsed: land in a receiving account, hop to one or two more layering accounts within hours, then out — withdrawn in cash, converted to crypto, scattered through payment platforms. By the time the real supplier asks where its money is — often days later, when the goods have not shipped — the trail is cold. This is business email compromise, and China-bound trade payments are a favorite target because the sums are large, the timing is predictable, and the two parties sit on different continents, in different time zones, trusting one mailbox.
Everything about this crime argues for speed. Layered funds are a legal problem; intercepted funds are an administrative one. The first 24 hours decide which kind you have. In order:
Say it once more, because it is the whole article: the recall and the police report are hour-one actions, not day-after actions.
On paper, the law is clean. Whoever receives money without legal basis must return it: Article 985 of the PRC Civil Code is the unjust-enrichment rule, and Article 987 adds teeth for the bad-faith recipient — they return the benefit and compensate your losses. The account that took your diverted wire is, on paper, exactly that bad-faith recipient.
The problem is who the recipient usually is. Receiving accounts are sold and rented: a student, a farm worker, a retiree who handed over a bank card for a few hundred yuan. The account holder is a "sold" identity, and suing them produces a judgment against a person with nothing — the real controller stays invisible until police work surfaces them. That is why speed beats litigation in this crime: the emergency freeze in the first day reaches money that a lawsuit filed in the first month cannot. Where the criminal track runs, recovery comes through restitution in that process — the two tracks are compared here: civil claim or criminal report.
The bank's own liability is narrow in practice. A bank that executed an ordinary transfer on valid instructions rarely bears the loss; exceptions exist — actual knowledge, participation — but plan around the rule, not the exception. Commercially, the lesson is blunt: your claim is against the fraudster and whoever holds the funds now, not against the payment system, and that is a recovery race decided in hours, not months.
Where the perpetrator is prosecuted, recovery for victims runs through restitution within the criminal process — ordered against the fraudster out of whatever is recovered, subject to the victim-status mechanics compared in the article above. Treat it as a possibility, not a plan. The plan is the freeze.
Every layer below has stopped real attacks. The stack works because no single layer needs to be perfect:
| Layer | What it looks like | Why it works |
|---|---|---|
| Bank details as a chopped annex | Account name and number fixed in a contract annex stamped with the company chop; changes only by a re-issued, re-chopped annex delivered through a verified channel | An email "update" is simply not a valid instruction — the account is a contract term. The discipline: the account-name test |
| Dual-channel callback | Any proposed change → call the phone number in the original contract — never a number from the email — and confirm with a known person | Breaks the attack's core premise: the attacker controls email, not the phone |
| Email-domain hygiene | Look-alike domain checklist (rn/m, .co/.com, added hyphens); DMARC, DKIM and SPF enforced on your own domain | Catches spoofing — and stops your own mailbox from being weaponized against your clients |
| Milestone sizing | No single wire large enough to fund a heist; more, smaller milestones sized to real progress | Caps the maximum loss and buys the hours that save the money. Deposit and milestone logic: deposits and payment milestones |
| Supplier-side screening | Test payment-process discipline during onboarding; a supplier that resists the chopped annex or refuses callbacks is telling you something | The attacker needs a sloppy process; starve the attack of one: supplier verification |
One more discipline that costs nothing: log every payment instruction as an event. When an "update" arrives, the question "does this match the last re-issued annex, and was that annex verified?" should take one minute to answer from your file — not one week of archaeology.
The do-nots first, because both of them cost victims money every single week:
The do-sequence:
Check your policies. Cyber and crime policies increasingly cover social-engineering and funds-transfer-fraud loss — sometimes under a specific endorsement you have to ask for; trade credit insurance generally does not touch this. Coverage turns on notification deadlines measured in days, which is one more reason the police report matters: insurers ask for it. If you pay Chinese suppliers on open account with any regularity, have the conversation with your broker this week, not after the next incident.
This article is general information, not legal advice, and does not create an attorney–client relationship. Recovery of diverted funds depends on timing, jurisdiction and facts that no article can predict. Nothing here is a guarantee of results.
Send me your current contract and payment process, and I will show you where the account-change hole is — and hand you the chopped-annex clause that closes it. The fix costs less than one lost wire, and it starts with verifying who is really behind the mailbox.
Verify before the next wire