How to Verify Bank Details After a Hacked Email Thread: the Best Way to Pay Chinese Suppliers
The best way to pay chinese suppliers after you have been burned once is not a clever new instrument. It is a verification habit that survives a compromised inbox. Business email compromise works in this trade because the money move looks routine: a changed bank account, a beneficiary name altered by two letters, a request timed to the day your balance is due. This guide is for the mid-market importer running three to eight orders a year between $15,000 and $80,000 who has already lost between $4,000 and $60,000 and now needs a protocol: how to verify bank details before the wire, how to re-verify after a hack, what to do when a supplier asks for Western Union or a personal account, and which instrument set limits the damage.

Suggested visual: A side-by-side screenshot of a legitimate proforma invoice bank block and the spoofed version, with the three altered characters highlighted and an arrow showing where the email thread was hijacked.
Suggested visual: A one-page “Verification Card” infographic listing the five checks a buyer runs before releasing any balance: second channel, legal name match, corporate account, callback to a number on file, and a $100 test wire.
Suggested visual: A 90-second screen recording of a callback verification: the buyer dials the number saved before the order, asks one scripted question about the account holder name, and logs the answer in the payment file.
Why the Best Way to Pay Chinese Suppliers Is Now a Fraud-Control Decision
Business email compromise is not a dramatic hack. In the China trade cases that reach us, it is usually dull: an attacker gets into a mailbox, sits quietly for two to six weeks reading the thread, learns the order value and the production stage, and then sends one message at the moment the buyer is most likely to pay without thinking. The message is short, apologetic and time-pressured. Our bank account is under audit. Our account was frozen by the tax bureau, please use the new one. We updated our remittance details, see the revised proforma invoice attached. Nothing in the email looks wrong, because most of it was copied from messages the attacker read.
Both sides of the trade get hit. A supplier’s sales mailbox is the most common entry point, but buyer-side compromise is just as common and just as costly, because the attacker can then reply inside a genuine thread from a genuine address. Lookalike domains do the rest: a single letter swapped in the domain, a hyphen added, or a display name that reads identically in the inbox. The buyer sees a known contact, a plausible reason, and a deadline. That is the whole trick.
The reason the loss usually lands on the buyer is settlement speed. A telegraphic transfer to a mainland corporate account settles in one to two business days; a transfer into an offshore mule account can be broken up and moved within hours of credit. By the time anyone notices, the money has passed through three or four accounts in two or three jurisdictions, and recall is a request, not a right. Practical recovery rates on cross-border BEC wires are low, and the cases that do recover tend to be the ones reported within twenty-four hours.
What makes this a payment-design problem rather than an IT problem is that every instrument you could choose handles a hijacked instruction differently. A wire to a corporate account in the supplier’s legal name fails slowly and visibly; a cash pickup transfer is unrecoverable by design; a letter of credit shifts the check to a bank’s document examiners. Once you accept that your inbox is a hostile channel, the question stops being “which bank is cheapest” and becomes “which instrument still protects me when the instruction is fake.” This is also where a Reliable manufacturing and procurement partner China changes the maths, because a partner with staff on the ground can walk into the factory and confirm a bank change in person instead of guessing over email.
There is a second reason the fraud problem and the instrument problem are the same problem. Instrument choice dictates how much of your money is exposed in a single event. A buyer who wires 70 percent of $60,000 as one balance payment has made a single $42,000 bet on the authenticity of one email. A buyer who splits that exposure across a deposit, a document-linked payment and a post-arrival retention has made three smaller bets, two of which can still be stopped after problems appear. Structuring for fraud control and structuring for quality leverage turn out to be the same discipline.
How to Verify Bank Details and Choose the Best Way to Pay Chinese Suppliers After a Hack
Step 1. Freeze the thread and open a second channel.
The moment any bank detail changes, stop replying to the thread. Do not forward, do not quote, and do not ask “is this correct?” in the same conversation, because if the mailbox is compromised the attacker answers. Start a fresh message to an address you collected before the order, or better, open WeChat, WhatsApp or the phone. Treat the email thread as evidence, not as a channel.
Why this works: an attacker can only control the channel they are inside. Moving the conversation to a channel established before the compromise restores the one thing you lost: an independent witness.
Step 2. Match the beneficiary name to the legal entity, character by character.
Open the supplier’s business licence, the contract, and the previous proforma invoice side by side. The account holder must be the exact legal entity name that appears on those documents, spelled identically. “Shenzhen Xingyuan Trading Co., Ltd.” and “Shenzhen Xingyuan Trade Co. Ltd.” are not the same payee, and a mismatch in one syllable is the single most common tell.
If you buy through a Bulk product sourcing from China wholesale suppliers programme, ask for the licence scan and the bank account page in the same request, so both documents arrive from the same source at the same moment.
Why this works: a fraudster can copy an account number perfectly but cannot easily fake a name that matches the licence, so name-matching converts a judgement call into a document check.
Step 3. Confirm you are paying a corporate account, not a person.
Legitimate Chinese factories and trading companies receive export payment into a corporate account held in the company’s own name. If the beneficiary is an individual’s name, a “finance manager,” or a company with no connection to your supplier, stop. No legitimate exporter needs your $30,000 routed through a private account to save tax, avoid a quota, or help a cousin.
Why this works: a personal beneficiary breaks the legal link between your payment and your supplier, which means that if the goods never arrive you have paid a stranger and have no contractual counterparty to sue.
Step 4. Call a number you already had, and ask one scripted question.
Use the mobile number saved in your CRM before this order, or the number on the original contract, never the one in the signature of the suspicious email. Ask a question the attacker cannot answer from the old thread: “Confirm the exact account holder name for our invoice ending 4471.” Keep it closed, log the date, time and answer.
Why this works: telephone verification defeats mailbox compromise completely, because the fraudster controls the email account and not the supplier’s phone, and a logged call is the evidence your bank will ask for later.
Step 5. Send a $100 test wire and confirm the value received.
Before any five-figure payment, send a small transfer to the account and ask the supplier to confirm the exact amount, currency, value date and sending name. Then wait for that confirmation on the verified second channel. It costs one wire fee and one day.
Why this works: a test wire proves the account exists, belongs to someone who is actively watching it, and can receive foreign currency, which quietly eliminates both typo accounts and fabricated details.
Step 6. Cap the blast radius: no single wire should be able to ruin the quarter.
Set a rule that no single payment exceeds a fixed ceiling, typically $15,000 to $25,000 for a mid-market importer, and split anything larger across a deposit, a document-linked payment and a retention tranche. Write the retention into the proforma invoice as 20/60/20 rather than fighting over the deposit percentage. A China sourcing agent for cross border ecommerce can hold that retention locally and release it only after inspection passes, which keeps your leverage without asking the factory to trust a stranger.
Why this works: splitting converts one catastrophic exposure into three recoverable ones, and the retention tranche is the only money that is still yours when a fraud or a defect becomes visible.
Step 7. Match the instrument to the risk, not to habit.
For a verified supplier with three or more clean orders, a bank wire to the confirmed corporate account, released against copy bill of lading plus a passed inspection, is the best way to pay chinese suppliers on cost and speed. For a first order above $50,000, an unverified counterparty, or a supplier whose mailbox has just been compromised, use a letter of credit at sight. Never use Western Union, MoneyGram, a personal account, a crypto transfer, or a third-country beneficiary for any trade payment.
Why this works: each instrument has a different failure mode, and choosing by risk means the instrument that fails most expensively is only used where you cannot avoid it, which in practice is nowhere.
Step 8. Write the verification policy into the purchase order and re-run it every quarter.
Add one clause to every PO: bank details may only change by written notice confirmed by telephone, payment is made only to the account holder named in the contract, and any change resets the verification sequence. Then re-verify standing suppliers’ details every ninety days even when nothing has changed.
Why this works: a written policy removes the discretion that fraud depends on, because a salesperson under deadline pressure no longer gets to decide whether a callback is necessary.
Payment Instruments Compared: Fraud Exposure and Reversibility
The table below scores each instrument on a $30,000 balance payment, using typical mid-market terms for a European or North American importer banking in USD.
| Instrument | Fraud exposure | Reversibility after a hijacked instruction | All-in cost on $30,000 | When a burned buyer should use it |
|---|---|---|---|---|
| Bank wire (T/T) to verified corporate account | Medium; fails visibly if the name does not match | Low, but a recall within 24 hours has a real chance | $35 to $95 total | Default for verified suppliers with history |
| Letter of credit at sight | Low; a bank checks documents before paying | High; non-conforming documents stop payment | 0.15% to 0.5% plus $150 to $350 | First orders over $50,000 or any unverified entity |
| Platform escrow or trade assurance | Low while funds sit in escrow | High before release, zero after | 1% to 5% of order value | Small orders and marketplace-sourced suppliers |
| Documentary collection (D/P) | Medium; relies on the presenting bank | Medium; payment happens before you inspect | $120 to $300 | Established suppliers where an LC is refused |
| Western Union or MoneyGram cash pickup | Extreme; anonymous collection | None; irreversible by design | 1% to 6% plus poor FX | Never, for any trade payment |
| Personal account or third-country beneficiary | Extreme; breaks the legal payment link | Near zero across jurisdictions | Same wire fee, total legal loss | Never, regardless of the explanation |
Bank Detail Verification Protocol: Before, During and After
Run this checklist once before the deposit and again before every balance release. Any “no” answer stops the payment.
| Check | When to run | How to verify | Pass criterion |
|---|---|---|---|
| Beneficiary name matches licence | Before every payment | Compare account holder to business licence and contract | Identical spelling, including Ltd. and punctuation |
| Account is corporate, not personal | Before every payment | Ask the bank for the account type; check the payee field | Payee is the contracting legal entity |
| Country of beneficiary matches supplier | Before every payment | Read the bank country and SWIFT prefix | Mainland, Hong Kong or a declared group entity only |
| Callback on a pre-order number | After any change, and quarterly | Closed question about the account holder name | Verbal confirmation logged with date and time |
| $100 test wire confirmed | Before first payment to a new account | Ask for amount, currency, value date | Supplier confirms all three on a second channel |
| Payment split across three tranches | At the proforma invoice stage | Read the payment schedule on the PI | No single tranche exceeds your ceiling |
Case Study: A $47,800 Order, a Latvian Account, and a Second Attempt That Failed
Daniel Ferreira runs a fourteen-person outdoor furniture brand outside Porto. In March 2025 he placed a $47,800 order for cast aluminium bistro sets with a Foshan factory he had used twice before. The deposit of $14,340 went to the factory’s verified corporate account without incident. Production finished on 12 May, and on 13 May a message arrived inside the existing thread: the factory’s account was under annual audit, please remit the balance to an updated account in Riga, Latvia, held by “Foshan Jinyuan Metal Products Ltd” with a slightly different address line.
Ferreira’s controller noticed the third-country beneficiary and asked for confirmation by reply. The reply came in eleven minutes, in the same thread, with a scanned letter on letterhead. The balance of $33,460 went out that afternoon. The real factory chased the payment nine days later. The recall request produced nothing: the funds had moved through two intermediary accounts within thirty-one hours of credit, and the Latvian bank had already closed the relationship. Ferreira recovered zero, re-made the goods at a 22 percent price increase, and lost the summer season. Total damage was roughly $47,000 including the re-make. He later consolidated four of his remaining factory relationships under a single Bulk product sourcing from China wholesale suppliers arrangement, which cut the number of bank blocks his controller had to police from five to one.
Fourteen months later the same factory’s mailbox was compromised again. This time the protocol was in place. The change notice went straight to a WeChat voice call with the sales manager whose number had been saved since the first order in 2024; the manager had no idea what the email said. Ferreira ran the name check against the business licence on file, saw that the “new” payee in Lithuania was not the contracting entity, and sent a $100 test wire to the original verified account, which the factory confirmed within four hours. The attempted theft was for $41,920 on a $52,400 order. Nothing was lost, the order shipped on schedule, and the factory stayed on the panel.
The difference was not technology and it was not a bigger bank. It was a saved phone number, a licence on file, and a payment structure that no longer put 70 percent of the order behind a single email. Ferreira’s instrument set today is 20 percent deposit to the verified corporate account, 60 percent against copy bill of lading plus a passed inspection, and 20 percent retention released thirty days after arrival, with a letter of credit at sight for any new supplier above $50,000.
Alternatives If You Cannot Verify the Account Yourself
Use a letter of credit at sight instead of a wire.
Pros: the bank examines documents before releasing funds, so a hijacked instruction cannot redirect payment; non-conformity gives you a defensible reason to stop. Cons: 0.15 to 0.5 percent of invoice value plus $150 to $350 in fees, three to seven extra days of processing, and strict document discipline that trips up small factories. Best for first orders above $50,000 and for any supplier whose mailbox has recently been compromised.
Route payment through a platform escrow or trade assurance.
Pros: funds sit with a third party until you confirm shipment or receipt, and the interface is familiar to small suppliers. Cons: fees of 1 to 5 percent, coverage limits that often cap well below a container value, and dispute processes that favour the platform’s own rules. Best for orders under $15,000 and for suppliers found on a marketplace.
Have a China-based entity pay the factories for you.
A Bulk product sourcing from China wholesale suppliers arrangement lets one verified local counterparty hold the supplier relationships and receive your money under a single, repeatedly verified account. Pros: one account to verify instead of eight, staff who can physically confirm a bank change, and local-language access to the business registry. Cons: you must diligence that entity as carefully as any supplier, you add a margin line, and you become dependent on their controls. Best for importers with more than four active suppliers and no staff in Asia.
Use a specialist cross-border payment provider with beneficiary pre-approval.
Pros: you whitelist beneficiary accounts inside the provider’s system, so a changed account simply cannot be paid; FX spreads are usually 0.3 to 0.8 percent against 1.0 to 1.8 percent at a retail bank. Cons: onboarding takes one to three weeks, suppliers may dislike receiving from a non-bank name, and cover varies by corridor. Best for importers running eight or more payments a year.
Ask for net terms once the relationship is proven.
Pros: paying thirty to sixty days after arrival removes deposit exposure entirely and is the strongest possible position. Cons: very few factories will grant it before two or three years of clean trade, and it usually comes priced into the unit cost. Best as a destination, not a starting point. A China sourcing agent for cross border ecommerce can bridge towards it by vouching for your payment record with factories that would never extend terms to an unknown foreign buyer.
Frequently Asked Questions
What is the best way to pay chinese suppliers if I have already lost money to a scam?
Rebuild around two rules rather than one instrument. First, no payment leaves without a second-channel confirmation using contact details collected before the order. Second, no single payment can exceed a ceiling you set yourself, typically $15,000 to $25,000, which forces a split into deposit, document-linked payment and retention. On top of that, use a letter of credit at sight for first orders above $50,000 and any supplier whose email has been compromised. The instrument matters less than the fact that a single compromised message can no longer move most of your money.
How do I verify a Chinese supplier’s bank details safely?
Match the account holder name to the business licence and contract, character for character, and confirm the account is corporate rather than personal. Then callback on a phone number saved before the order and ask one closed question about the account holder name for the specific invoice. Send a $100 test wire and have the supplier confirm the amount, currency and value date on a verified channel. Log every check with a date. Never accept a change that arrives only inside an existing email thread, and never accept a scanned letter as proof.
What should I do if a supplier asks for Western Union or a personal account?
Treat it as a stop, not a negotiation. Western Union and similar cash pickup services are anonymous, instant and irreversible, which is exactly why no legitimate exporter needs them; the “our corporate account is frozen” story is the standard script. A personal account breaks the legal link between your payment and the company you contracted, so if the goods fail you have no counterparty. Reply on a second channel asking the real contact to reissue corporate details, and if they insist, walk away from the order. Where you need continuity of supply while you investigate, a Reliable manufacturing and procurement partner China can re-source the item and hold payment until the replacement factory’s account has passed the same five-check sequence.
Is a Hong Kong or third-country beneficiary account always a red flag?
Not always, but it always requires a documented reason before you pay. Legitimate cases exist: a Hong Kong or Singapore treasury entity inside the same group, a factory using a declared export agent, or a group that banks offshore for currency reasons. What makes it legitimate is that the entity was named in the contract or proforma invoice from the start and can be evidenced in the business registry. What makes it fraud is a change introduced mid-thread, under time pressure, to a country that has nothing to do with the supplier.
Can I recover money sent to a fraudulent account?
Sometimes, but speed decides almost everything. Contact your bank’s fraud desk the same day and ask for an MT103 recall and a message to the beneficiary bank; within the first twenty-four hours there is a real chance funds are still sitting in the receiving account. Provide the SWIFT reference, the fraudulent instruction and your verification log. After that the odds fall steeply, because mule accounts move money across borders in hours. Also file a police report, since banks and insurers will ask for a case number.
Should I use a letter of credit after being defrauded?
Use it selectively. An LC makes a hijacked email much less dangerous, because your bank pays against documents rather than against an instruction, and non-conforming documents give you a defensible reason to stop payment. But it costs 0.15 to 0.5 percent plus $150 to $350, adds three to seven days, and requires document discipline that small factories struggle with. A sensible compromise is to reserve LCs for first orders above $50,000 and for any supplier whose mailbox has been compromised, and use verified wires plus retention for everyone else.
How often should I re-verify bank details?
Every ninety days for standing suppliers even when nothing has changed, and immediately after any of four triggers: a change in the bank block on a proforma invoice, a gap of more than six months since the last order, a change in the salesperson handling your account, or any sign of unusual email behaviour such as delayed replies or a new signature block. Re-verification takes about fifteen minutes when the licence and the phone number are already on file, and it should be logged in the same payment file as the original check.
Do I need a China sourcing agent to pay suppliers safely?
No, but it reduces the number of accounts you have to protect. If you buy from six factories directly, you have six bank blocks, six salespeople and six mailboxes that can be compromised. Working through a China sourcing agent for cross border ecommerce collapses that to one counterparty you can diligence once and verify face to face, which is the reason many burned buyers consolidate payment even when they keep sourcing decisions in house. The cost is a margin line and the need to diligence the agent as strictly as any factory.
Conclusion
Fraud control and payment design are the same discipline now. The buyer who lost money did not lose it because the bank was wrong; they lost it because a single email could move most of the order, and because nothing in the process forced a second opinion before the wire went out. Fixing that does not require a new bank, a blockchain pilot or an expensive platform.
It requires four habits: verify the beneficiary against the licence every single time, confirm any change on a channel established before the order, split every order so no single payment is fatal, and match the instrument to the risk instead of to habit. Do those four things and the best way to pay chinese suppliers becomes a process your team can run without adrenaline, even on a Friday afternoon when the balance is due and the thread looks completely normal.
For buyers rebuilding after a loss, a Reliable manufacturing and procurement partner China supplies the part email can never supply: someone who can stand in the factory and confirm, in person, that the account you are about to pay is the account that belongs to the company making your goods.
Tags: best way to pay chinese suppliers, supplier payment fraud, business email compromise, verify chinese supplier bank details, western union supplier scam, letter of credit china, payment verification checklist, third country beneficiary, china sourcing fraud prevention, secure supplier payments
