Cybersecurity Reach Foundation
All partner resources

Email copy

When payment details change, for staff

For anyone who pays invoices, approves expenses, or handles donations.

For
Nonprofits, Faith organizations, Housing and financial wellness, Universities
Status
Reviewed
Version
2026-09-01

Subject line

Before you change any payment details, please read this

A fraud aimed at organizations like ours: an email that looks like a supplier, a colleague, or someone senior says bank details have changed, or asks for a payment to go out quickly and quietly.

The details are usually right, because the sender has read real emails. The urgency is the fake part.

Our rule: confirm any change to payment details by phone, on a number we already had. Never a number from the message asking for the change. No exceptions, whoever appears to be asking.

If someone senior asks you to skip that step, that is the warning sign. Nobody here minds a phone call, and nobody is in trouble for slowing a payment down. If something feels off, bring it to [NAME OF THE PERSON WHO APPROVES PAYMENTS].

Paste it into your newsletter or email and edit it freely.

Still to fill in: [NAME OF THE PERSON WHO APPROVES PAYMENTS]. Replace it before you send this.

Before you send it: Fill in a real name. A named person makes it far more likely someone actually asks.

Before you distribute this

  • Use it: Staff email, volunteer briefings, and finance team onboarding.
  • Replace every bracketed placeholder with your organization's own details.
  • Open every web address yourself before printing it.
  • Current warnings live at watchout.report. Check the date on anything time-sensitive.
Use your browser's print dialog to save this as a PDF.

Cybersecurity Reach Foundation · cybersecurityreach.org · Current warnings: watchout.report

General safety information. CSRF is not a crisis, legal, banking, safeguarding, or law-enforcement service.