An email from a supplier says its bank account has changed and asks you to send the next invoice payment to a new account. Would you call the number in that email, or use contact details your company already has on file?
Use the number you had verified before the request arrived. A payment-detail change affects real money. Do not update the vendor record or release payment based on one message, even when the sender’s name, document layout or wording looks familiar.
In a report published on October 8, 2026, OpenAI described two operations that created false-front identities or organizations while using its models alongside more traditional methods. The groups OpenAI attributed to Russia and Iran used models for several tasks, including drafting articles, social media comments and internal reports. Some activity also involved fake documents or audio. Read OpenAI’s report
OpenAI cautioned that the operators’ internal claims about their impact could not be taken at face value, and that some content they claimed to have placed was not found in open-source research. The report concerns covert influence operations. It is not a vendor-payment case or evidence of an incident in Thailand, and it does not show that every suspicious payment request involves AI.
It does show why a familiar name or convincing wording should not be treated as proof of who made a request. Businesses can prepare a separate verification process for requests that change payment details.
Verify a bank-detail change before updating the record
FBI Internet Crime Complaint Center (IC3) guidance for emails impersonating executives and requesting wire transfers recommends verifying through a separate channel. For a vendor or supplier payment change, call a number from the contact list you already hold, not a number provided in the same message. It also recommends dual approval for higher-risk transfers, such as new accounts or new trading partners. Read IC3’s guidance
A business can turn that guidance into a short procedure:
- Pause the record change and payment until the request is verified. A reply in the same email thread is not independent confirmation.
- Call an established contact using the vendor record or a contact list maintained by the responsible team. Do not use a number or link in the message requesting the change.
- Have another person review and approve new vendors, changed account numbers or payments over the company’s threshold. The person editing the vendor record should not be the only person releasing payment.
- Record how verification happened, including who was contacted, the channel, date, reviewer and approver, so Finance can investigate questions later.
Set the verification contact when onboarding a supplier. Review it when the supplier’s contact person changes, and rehearse the procedure with Procurement, Finance and payment approvers. A callback is not a guarantee if the original contact list is stale or can be changed without review.
In an ERP system, these steps should appear in vendor-record permissions and the approval workflow, rather than relying on an employee’s memory. A system can retain the change history and require an additional approver, but the access rules and responsibilities still need to match how the business works.
Take the most recent vendor bank-detail change your team handled and ask: if the sender was not who they claimed to be, who would make the verification call, and who could stop the payment?
Sources: Disrupting AI-enabled “false front” operations, OpenAI, October 8, 2026, Increase in W-2 Phishing Campaigns, FBI Internet Crime Complaint Center, February 21, 2018
AI-generated illustration of an office employee checking a request and calling a contact already on file. It does not depict actual Enersys staff, customers or an incident.
Talk to Enersys about finance systems and approval workflows
