Cybersecurity Reach Foundation
All partner resources

Draft — pending CSRF review. This is source copy. It has not been through editorial, safety, and link review, so do not print or distribute it to a community yet.

Email copy

When payment details change, for staff

An internal note to anyone who pays invoices, approves expenses, or handles donations.

For
Nonprofits, Faith organizations, Housing and financial wellness, Universities
Status
Draft, pending review
Version
Set at review

Subject line

Before you change any payment details, please read this

A common fraud aimed at organizations like ours works like this. An email arrives that looks like it is from a supplier, a colleague, or someone senior. It says bank details have changed, or asks for a payment to go out quickly and quietly.

The details are usually right, because the sender has read real emails. The urgency is the part that is fake.

So our rule is: any change to payment details gets confirmed by phone, on a number we already had — never a number from the message asking for the change. Every time, no exceptions, no matter who appears to be asking.

If someone senior seems to be asking you to skip that step, that itself is the warning sign. Nobody here will ever be annoyed with you for making a phone call, and nobody will be in trouble for slowing a payment down. If something feels off, bring it to [NAME OF THE PERSON WHO APPROVES PAYMENTS].

Paste it into your newsletter or email and edit it freely.

Still to fill in: [NAME OF THE PERSON WHO APPROVES PAYMENTS]. Replace it before you send this.

Before you send it: Fill in a real name. A named person makes it far more likely someone actually asks.

Before you distribute this

  • Use it: Staff email, volunteer briefings, and finance team onboarding.
  • Replace every bracketed placeholder with your organization's own details.
  • Open every web address yourself before printing it.
  • Current warnings live at watchout.report. Check the date on anything time-sensitive.
Use your browser's print dialog to save this as a PDF.

Cybersecurity Reach Foundation · cybersecurityreach.org · Current warnings: watchout.report

General safety information. CSRF is not a crisis, legal, banking, safeguarding, or law-enforcement service.