How Do You Verify a Supplier Bank Account Before Sending a China Supplier Payment?

19 min read
How Do You Verify a Supplier Bank Account Before Sending a China Supplier Payment?

How Do You Verify a Supplier Bank Account Before Sending a China Supplier Payment?

Every china supplier payment you send is the single riskiest moment of an import transaction: money leaves your country, crosses into a foreign banking system, and lands in an account you may know very little about. If that account belongs to a fraudster instead of your factory, recovery odds shrink with every passing hour. This guide lays out the verification routine experienced importers use before releasing funds — a step-by-step checklist, a small test payment protocol, corporate account cross-checks, and company name consistency checks — so your money reaches the real supplier and never a criminal’s account.

How Do You Verify a Supplier Bank Account Before Sending a China Supplier Payment?

Why China Supplier Payment Fraud Is Exploding

Wire fraud against importers has become an industrialized business. The FBI’s Internet Crime Complaint Center consistently ranks business email compromise among the costliest cybercrimes in the world, with reported losses running into the billions of dollars each year, and cross-border trade deals are a favorite hunting ground. China-bound orders are especially attractive targets for three reasons: the payment amounts are large, the relationships are often brand new, and the buyer and supplier are separated by language, time zones, and an ocean. A fraudster who inserts themselves at the payment moment can walk away with a life-changing sum in minutes, and the trail runs cold almost immediately.

The most dangerous thing about this crime is that it rarely looks like fraud from the outside. The scammer does not hack your bank, forge your signature, or brute-force anything. Instead, they slip quietly into an ordinary conversation you were already having, then change exactly one detail: the bank account number. Everything else about the transaction — the product, the price, the invoice, the shipping schedule — stays perfectly normal. That is why smart buyers treat the payment step as its own controlled process, with checks that do not depend on email at all.

There is also a hard asymmetry at the heart of this crime that every importer should internalize before their next order. A fraudster needs to succeed exactly once to walk away with months of your profit margin, while you need to be right every single time, across every supplier, every order, and every account change. Verification routines exist precisely to correct that imbalance: they convert a one-time judgment call made under deadline pressure into a repeatable process that works even when you are tired, traveling, or distracted.

The Anatomy of a Business Email Compromise Attack

Nearly every “account change” scam follows the same five-stage playbook:

  1. Access. The attacker gains entry to a mailbox — sometimes the supplier’s, sometimes yours, sometimes a freight forwarder’s — through a phishing email, a reused stolen password, or a malware-laden attachment.
  2. Monitoring. They read silently for days or even weeks, learning your invoice numbers, shipment schedules, payment deadlines, negotiation history, and the tone of the relationship.
  3. Hijack. At the precise moment a payment is expected, they intervene: they either take over the real mailbox or register a lookalike domain that differs from the genuine one by a single invisible character.
  4. Substitution. A convincing email arrives with “updated bank details,” usually backed by a doctored bank letter and an explanation that sounds administrative rather than suspicious.
  5. Pressure. The message stresses urgency — goods will not ship, the deposit deadline will pass, the production line stops today — so you wire first and think later.

Why the “Updated Bank Account” Email Feels So Legitimate

Scammers succeed because the request fits the situation perfectly. It arrives exactly when you already expect to pay. It references real order numbers, real proforma invoices, and real names of people you have actually spoken with. It often comes from a mailbox that has been part of the conversation for weeks. And the stated reason — a tax review, an account upgrade, a subsidiary restructure — is precisely the kind of boring administrative detail nobody bothers to question.

The single best defense is a verification routine that does not rely on email for any final confirmation. Buyers who build that routine into their procurement process from day one — ideally with support from a Reliable manufacturing and procurement partner China that already knows which documents to demand and which answers to distrust — rarely fall for these schemes, because the routine makes every deviation obvious within minutes.

The China Supplier Payment Verification Checklist: 7 Steps That Work

Below is the complete pre-payment routine. Run it for every new supplier, every first payment, and every account change request — no matter how long the relationship has lasted, and no matter how trustworthy the supplier has been in the past. Fraudsters specifically exploit long relationships, because established trust is the thing they cannot fake and therefore must steal.

Step 1: Match the Beneficiary Name to the Legal Company Name

Open the bank details and read the account holder name character by character. It must match the legal entity name on your contract and proforma invoice — for example, “Shenzhen Brightstar Electronics Co., Ltd.” — with no missing suffixes, no trading-name shortcuts, and no unrelated third party of any kind.

Why it matters: legitimate suppliers are paid into accounts registered to their own legal entity. A beneficiary name that reads like an individual, a different company, or a “finance subsidiary” you have never heard of is the clearest warning sign in the entire process, and the check takes thirty seconds.

Step 2: Demand a Bank-Issued Account Certificate

Ask the supplier for an account opening certificate or bank book cover issued by their bank, showing the account name, account number, and bank branch. Request the original stamped document, not a screenshot pasted into an email thread, and keep a copy in your supplier file permanently.

Why it matters: any buyer can type fake bank details into an email, but fabricating a stamped, bank-issued document is far harder. If a supplier resists this request, ask yourself why a real factory would refuse a routine compliance step. Teams running Bulk product sourcing from China wholesale suppliers treat this certificate as a standard onboarding document, collected once from each supplier and archived forever.

Step 3: Cross-Check Against Your Contract and Proforma Invoice

Lay three documents side by side: the signed contract, the proforma invoice, and the bank details just provided. The company name, account number, and bank name must be identical across all three. If the proforma invoice predates a “new” account, treat the situation as an account change request and re-verify from scratch using the full checklist.

Why it matters: fraud depends on small, isolated changes that no one compares. When documents must agree with each other, a substituted account cannot hide; the inconsistency surfaces immediately, even if every individual document looks convincing on its own.

Step 4: Verify Through a Second, Independent Channel

Never confirm bank details using the same channel that delivered them. If the details arrived by email, verify by phone using a number you found independently — the number printed on the stamped contract, the official company website, or a business license lookup — not a number or contact listed inside the suspicious email itself.

Why it matters: if the attacker controls the mailbox, every reply inside that thread reaches the attacker too. An independent channel breaks the loop, because a scammer cannot intercept a phone call to a number they did not plant. A China sourcing agent for cross border ecommerce who speaks the supplier’s language and already holds verified contact details can complete this callback in minutes and remove the guesswork entirely.

Step 5: Run a Small Test Payment

For every new account — a brand new supplier, or an existing supplier’s “new” account — send a small amount first, typically one to two percent of the invoice value, and confirm receipt with the supplier by phone before releasing the balance.

Why it matters: a test payment proves the account actually exists, accepts international wires, and is controlled by someone genuinely in contact with your real supplier. If the account is fake, you lose a few hundred dollars instead of a full order value. Genuine suppliers understand this practice completely; fraudsters resist it, stall, or suddenly develop mysterious “banking problems.”

Step 6: Confirm Receipt With the Account Holder — By Phone

After the test payment lands, call your usual contact at the factory and have them confirm the exact amount and value date in their own banking system. Ask them to read back the account holder name exactly as their bank displays it.

Why it matters: money that arrives is not the same as money that arrives correctly. A live confirmation closes the loop and creates a second human checkpoint between your funds and a stranger’s account, and it gives your supplier an early heads-up if anything looks wrong on their side too.

Step 7: Archive Every Verification Record

Save the bank certificate, your phone call notes with dates and times, the email headers of any account change request, and the SWIFT confirmation of the test payment in a single supplier file that anyone on your team can access.

Why it matters: if fraud ever does occur, a documented verification trail dramatically strengthens your bank recall request, your police report, and any insurance claim. It also protects you in audits and payment disputes, and it makes the next china supplier payment faster, because the verified baseline is already on record.

[Video suggestion: “Inside a BEC Attack”] Insert a 3-minute screen-recorded walkthrough here showing an anonymized account-change email, its lookalike domain, and the email header details that exposed it. Readers remember what they see far longer than what they read.

Small Test Payment vs. Full Wire: A Practical Comparison

Factor Small Test Payment First Full Wire Immediately
Typical amount 1-2% of invoice value 100% of invoice value
Loss if account is fake A few hundred dollars Entire order value
What it proves Account exists and supplier controls it Nothing at all
Added delay 1-3 banking days None
Fraudster reaction Often stalls, vanishes, or invents excuses Money moved within hours
Bank recall odds Recall rarely needed Very low after 24-48 hours

The table explains itself, but one nuance deserves emphasis: the test payment is not merely a financial hedge, it is a behavioral probe. A legitimate supplier confirms receipt cheerfully and often thanks you for being careful. A fraudster, whose entire scheme depends on receiving the full amount in one shot, tends to push back — the test “failed,” the bank is “holding” it, please send the full amount so production is not delayed. Any of those responses should freeze the payment process instantly and trigger a full re-verification through an independent channel.

This is also where disciplined sourcing operations differ from casual buyers. Teams that handle Bulk product sourcing from China wholesale suppliers at volume build the test payment into their standard payment workflow, so no individual employee ever has to argue with a supplier about it — the process, not the person, delivers the unwelcome news.

Legitimate Account Change or BEC Scam? The Side-by-Side Comparison

Suppliers do occasionally change banks — mergers, account upgrades, and regional branch reorganizations are real events. The trick is distinguishing an ordinary administrative change from a hijacked conversation. Compare the two profiles:

Signal Legitimate Account Change BEC / Account-Change Fraud
Sender domain Same domain used for months Lookalike domain or a free email address
Timing Announced weeks before the deadline Arrives hours before your payment deadline
Stated reason Documented, verifiable, boring “Tax audit,” “frozen account,” vague urgency
Account holder name Identical legal company name Individual, third party, or unknown entity
Account location Same city or province as the factory Different province or a Hong Kong shell
Response to callback Welcomes verification Discourages calls, cites urgency
Supporting documents Original stamped bank certificate Blurry scans, edited PDFs, screenshots

If even two rows in the right-hand column describe your situation, stop the payment and escalate. No genuine supplier has ever lost money because a buyer asked one extra verification question, but thousands of buyers have lost everything because they were afraid of offending a supplier they thought they knew.

[Image suggestion: “Spot the Difference”] Add a side-by-side screenshot pair here: a genuine invoice email versus a spoofed one, with the lookalike domain character, the mismatched reply-to address, and the urgency language circled in red annotations.

Company Name Consistency: The 5-Point Match for Payment Safety

Company name consistency is the quiet backbone of every check above. Before any china supplier payment leaves your account, the legal entity name should match across five documents:

  1. The business license the supplier shared during onboarding.
  2. The bank account certificate issued by the supplier’s bank.
  3. The signed contract and proforma invoice.
  4. The export documents attached to a previous shipment, such as the bill of lading or the customs declaration.
  5. The company website and email domain in everyday use.

When all five agree, you are almost certainly dealing with the real company. When any two disagree, you have found either a sloppy supplier or an active fraud, and both outcomes deserve the same response: pause the payment and resolve the discrepancy in writing, through an independent channel. Experienced importers who work with a Reliable manufacturing and procurement partner China often have this five-point match performed on every new supplier before a single dollar is committed, because a mismatch discovered before payment costs nothing, while one discovered after payment costs everything.

Three specific mismatch patterns deserve special attention. First, payments requested to a personal name are a serious red flag — real factories invoice through corporate accounts, and an individual account means either a middleman you have no contract with or an outright scammer. Second, be careful with accounts belonging to a “sister company” or “group finance subsidiary” that you cannot find in the business license; ask for the corporate registration documents linking the two entities before proceeding. Third, treat Hong Kong accounts operated by a mainland factory as a reason for extra diligence rather than automatic rejection — many are entirely legitimate for trade settlement, but they deserve the full checklist and a test payment without exception.

Case Study: A $47,250 China Supplier Payment Gone Wrong

In February, a Chicago-based importer of commercial LED lighting — call them Northlight Trading — placed a $68,400 order with a Shenzhen factory they had worked with twice before without any problems. The 30% deposit of $20,520 was sent on February 12 to the factory’s verified account, collected properly during onboarding. Production ran for six weeks, and the balance of $47,880 fell due before shipment on March 25.

On March 24, one day before the scheduled wire, Northlight’s purchasing manager received an email from the factory’s “export manager” — same name, same signature block, same writing style — but the domain contained a capital “I” where a lowercase “l” belonged, invisible at a glance on a phone screen. The email explained that the factory’s account was “under review by the local tax authority” and that the balance should be sent to a “group settlement account” at a different bank. The account holder name was an individual, with a company name slightly different from the factory’s legal entity.

The email arrived at 4:47 PM Chicago time, twelve hours before the payment deadline the factory had emphasized all week. The manager was traveling, approved the wire from his phone, and $47,250 was sent the next morning — a $630 late-payment discount had been negotiated earlier, which explains the slightly lower figure.

Six days later, the freight forwarder asked for the SWIFT copy to book the shipment, and the real factory replied that no balance had ever been received. By then, the money had left the receiving account within hours of arrival and been dispersed onward through a chain of mule accounts.

Northlight’s bank filed a SWIFT recall immediately, and because $9,400 was still sitting in the first beneficiary account when the receiving bank froze it, that portion was eventually returned — five months later. The remaining $37,850 was never recovered. Their cyber insurance declined the claim because the policy excluded social engineering events that lacked dual-authorization controls.

The brutal arithmetic: the verification routine described in this article would have taken roughly twenty minutes and cost nothing. The Step 4 callback alone would have ended the scam with one phone call to the number printed on the stamped contract. Today, Northlight routes every first payment and every account change through the full checklist, uses a Bulk product sourcing from China wholesale suppliers workflow that enforces dual approval on any wire above $10,000, and has not had an incident since.

What to Do If You Already Sent Money to a Fraudster

Speed is everything, because the first 24 hours determine most of the outcome.

  1. Call your bank immediately and request a SWIFT payment recall. Ask them to contact the beneficiary bank directly and to freeze the receiving account. Fraudsters empty accounts with astonishing speed, so every hour counts.
  2. File a report with your national cybercrime authority — the FBI’s IC3 in the United States, Action Fraud in the UK, or your local equivalent. Financial institutions and regulators coordinate cross-border freezes through these channels.
  3. File a police report locally, then notify the supplier’s local police jurisdiction through your embassy’s commercial section if the amount justifies it.
  4. Notify your real supplier through a verified channel so they can check whether their systems, or a partner’s, were compromised, and so they can warn their other buyers.
  5. Notify your insurance broker the same day, even if you are unsure of coverage; late notification alone can void an otherwise valid claim.

Even with a perfect response, recoveries are rare — which is exactly why the pre-payment checklist is worth its weight in gold. Prevention costs minutes; recovery costs months and usually fails anyway. Buyers using a China sourcing agent for cross border ecommerce gain an extra layer here as well, because a local agent can walk into a bank branch or police station in person, in the right language, while the trail is still warm.

China Supplier Payment FAQ

1. Is it normal for a Chinese supplier to change bank accounts?
It happens, but rarely without warning. Genuine changes are announced early, documented by the bank, and keep the account under the same legal company name. Any change announced hours before a deadline, or routed to a new entity name, should be treated as fraud until it has been verified through an independent channel.

2. Can I trust the bank certificate image the supplier emailed me?
Only as a starting point. Documents can be edited or faked, so treat the certificate as one data point and verify the account through a phone call using a number taken from the signed contract or the official website. The certificate’s real value is that it forces the supplier to put a bank-stamped document on record that can be cross-checked later if anything goes wrong.

3. Why do suppliers refuse PayPal or credit cards for large orders?
Fee math. On a $50,000 order, card or platform fees of 3-4% cost the supplier $1,500-2,000, which wipes out most of a factory’s margin. Wire transfer is the standard for B2B trade, which is precisely why fraudsters love it — wires are fast and hard to reverse. The answer is not to demand consumer payment methods; it is to verify the receiving account properly before sending anything.

4. The bank account is under a personal name. Should I pay?
No. Real factories receive payments through corporate accounts that match their business license. A personal account means either an undisclosed middleman — with whom you have no contract and no legal recourse — or a fraudster. Ask for a corporate account or walk away from the deal.

5. How large should a test payment be?
One to two percent of the invoice value, usually between $200 and $600 — enough to prove the account is live and controlled by your supplier, but small enough to lose without pain. Confirm receipt by phone, then release the balance. Keep the amount high enough to trigger a normal bank posting fee, because some fraudsters use micro-deposits below fee thresholds to probe whether buyers actually check anything.

6. Does a video call with the supplier help verification?
It helps with identity, but not with bank details. A scammer who hijacked a real mailbox is not the person on the video call, and modern deepfake filters make even that assumption shakier every year. Video calls complement the checklist; they never replace the independent callback and the name-matching checks.

7. Is paying into a Hong Kong account risky?
Not automatically. Many mainland manufacturers hold Hong Kong accounts for trade settlement, and they are legal and extremely common. The risk profile changes only in that recovery is harder if something goes wrong, so apply the full checklist without shortcuts — name match, bank certificate, independent callback, and a test payment every single time. A China sourcing agent for cross border ecommerce can also verify the account registration locally when the stakes justify it.

8. Will my bank reimburse me if I am scammed?
Usually not for authorized wire transfers, because you — not the bank — instructed the payment. Some banks offer partial goodwill refunds in fast-reported cases, and a few insurance policies cover social engineering fraud, but the default outcome is a loss. This is exactly why verification before payment is the only reliable protection.

Final Word: Make Verification a Habit, Not a Reaction

BEC fraud does not reward cleverness at the moment of attack; it punishes the absence of routine. The buyers who never lose a china supplier payment are not paranoid geniuses — they simply run the same boring checklist every single time: name match, bank certificate, document cross-check, independent callback, test payment, phone confirmation, records archived. Twenty minutes of discipline stands between your money and a scammer who needs exactly one distracted afternoon. Build the routine into your procurement process, train your team on the red flags, and work with a Reliable manufacturing and procurement partner China that treats verification as standard operating procedure rather than an optional extra. Your future self, staring at a confirmed receipt instead of a police report, will be grateful.

Tags: supplier verification, bank account fraud, business email compromise, wire transfer safety, import payments, trade fraud prevention, supplier due diligence, payment security, China sourcing, BEC scam

Ready to Source from China?

Tell us what you need — get a free sourcing proposal and competitive quote within 24 hours.

Request a Quote