The short list
Five rules for every change request
- Hold the change until a named company owner approves it.
- Verify through a contact route that was stored before the request arrived.
- Keep the requester, verifier, and approver clear in the record.
- Send a small test only when company policy allows and the owner approves it.
- Stop and alert the incident contact when any detail feels wrong.
Treat a changed destination as a new instruction
A familiar name, logo, email thread, or chat account does not prove that a change is real. Someone may copy a message, take over an account, or send a new phone number that leads back to the same scam.
The FBI Internet Crime Complaint Center recorded 21,442 Business Email Compromise complaints in 2024, with $2,770,151,146 in reported losses. Those are reports submitted to a U.S. system, not a count of all fraud and not a measure of Filipino workers.
The same 2024 report recorded 193,407 phishing or spoofing complaints. It also listed 1,421 reported fraudulent wire transactions with the Philippines named as an international destination, but that number does not show who sent the request, who received it, or whether outsourced staff were involved.
Swipe or use arrow keys to see the full chart.
Methods note: The chart uses three 2024 counts from the FBI IC3 report. The bars use a square-root scale so the smaller values remain visible; the categories have different meanings and must not be added or used to estimate fraud in Philippines outsourcing.
Use one verification table for the team
The table should tell the worker what to hold, whom to contact, and what proof to keep. Put it beside the task guide so a rushed message does not become a rushed approval.
Swipe or use arrow keys to reach the last column.
| Request | Worker does first | Company owner verifies | Use this known route | Record before approval |
|---|---|---|---|---|
| Vendor bank change | Hold the edit and open the approved vendor record | Legal name, account ending, reason, and effective date | Stored vendor number or known account manager | Requester, callback, verifier, and approval |
| Worker payroll change | Move the request to the protected staff process | Identity and the specific destination change | Known staff portal or stored contact | Time, owner, old ending, and new ending |
| Customer refund destination | Stop and send the case to the customer owner | Customer identity and company refund rule | Approved customer account route | Order, case, verifier, and decision |
| Reimbursement account | Hold the form and check the employee record | Employee identity and supporting expense | Company directory or known manager | Claim, contact route, and approval |
| Urgent transfer request | Do not enter or send it from chat alone | Business reason, owner authority, and destination | Stored executive contact and second approver | Full request and both approvals |
Verify outside the message that asked for the change
If the request came by email, do not reply and call the number in the signature. Open the approved vendor file, staff directory, or customer record and use the contact route that was there before the change arrived.
The check should name the exact change: the person or business, the account ending, the effective date, and the reason. A general question such as "Did you email us?" is easier to misunderstand than a direct confirmation of the new instruction.
Keep the worker's job simple if the contact does not answer. The request stays on hold, the worker records the attempt, and the company owner decides whether another approved contact may be used.
Exact source quote
Use another channel to check the change
"Use secondary channels and/or two-factor authentication to verify requests for changes in account information."
FBI Internet Crime Complaint Center, Business Email Compromise public service announcement, September 11, 2024.
Give the worker a short callback script
A fixed script helps the worker ask the same questions every time. It also makes it clear that the call is a normal company control, not an accusation.
Verification call: We received a request to change the destination details for [vendor, worker, customer, or claim]. I am calling the number already held in our record. Please confirm whether you requested the change, the last four characters of the new destination, the effective date, and the company contact who approved it. We will keep the request on hold until our approval owner completes the check.
The worker should never read a full bank number aloud or ask the caller for a password or sign-in code. Only the minimum detail needed for the match belongs in the verification note.
Use a four-step change path
The worker logs the request and holds the edit. A known contact confirms the change, a company owner approves it, and another person checks the first completed action against the approval record.
Swipe or use arrow keys to see all four steps.
Keep a small record that another person can follow
Save the original request, the known contact route used, the time of the check, the person reached, the details confirmed, and the approval owner. Mask full account information so the control record does not create another sensitive file.
The person checking the first completed action should compare the destination ending and amount with the approved record. If they do not match, stop the action and use the incident path rather than editing the note to make it fit.
Access to the change log should be limited to people who need it. The Philippine National Privacy Commission has warned that fraudulent messages and sites may seek personal and banking information, so do not copy extra identity or bank data into chat.
Make urgency a reason to slow down
A message may claim that payroll will fail, a supplier will stop work, or an executive is in a meeting and cannot talk. The control should stay the same: hold, confirm through the known route, and wait for the named approval owner.
The FTC received more than 330,000 business-impersonation reports and nearly 160,000 government-impersonation reports in 2023. Some reports were counted in both groups, and the figures describe reports to U.S. systems rather than the Philippines staffing market.
In 2024, the FTC said imposter scams accounted for $2.95 billion in reported losses. That figure gives broad U.S. consumer context; it does not tell a company how often its vendors, staff, or customers will face a false change request.
Move fast after a suspected wrong transfer
Contact the financial institution at once and ask about its recall or recovery process. Alert the company incident owner, preserve the email, chat, call notes, approval record, and transaction details, then follow the reporting steps set by the company.
The FBI said its Recovery Asset Team sent 3,020 complaints involving $848.4 million in attempted theft through its Financial Fraud Kill Chain in 2024. It reported that $561.6 million was frozen, but those results apply to the referred cases and do not promise recovery in a new case.
Do not ask the Philippines-based worker to confront the suspected sender, trace the money, or decide whether a crime or privacy breach occurred. They can preserve the request, record what they did, and support the company owner who handles the response.
Run a ten-minute change drill
Send a harmless sample request with one warning sign, such as a new phone number or pressure to skip the normal check. Ask the worker to hold it, find the stored contact, write the verification note, and send it to the approval owner.
Watch for small gaps: an old vendor number, no backup approver, a form that exposes a full account, or a chat message that lets one person request and approve the same change. Fix the weak step and run the drill again with a different request.
Repeat the test when staff, bank instructions, company tools, or approval owners change. The goal is a boring, repeatable check that still works when the message sounds urgent.
Common questions
Payment change verification FAQ
Can a Philippines-based staff member enter a bank-detail change?
They can collect the request and enter a pending change if the company allows it. A named company owner should verify and approve the change through a known contact route before any money moves.
Is a reply from the usual email address enough proof?
No. An email account or message thread can be copied or compromised, so confirm the request through a stored phone number, a known company directory, or another approved route.
Should the worker call the number inside the change request?
No. Use a number already held in an approved record or found through a trusted company source, because the request itself may contain a false contact number.
What should happen after a suspicious transfer?
Contact the financial institution at once, alert the company incident owner, preserve the request and approval record, and report the event through the company plan. The outsourced worker should not investigate or contact the suspected sender alone.
Sources
- 1. FBI Internet Crime Complaint Center: 2024 IC3 Annual Report
- 2. FBI IC3: Business Email Compromise, The $55 Billion Scam, September 11, 2024
- 3. FTC: Reported fraud losses in 2024, March 10, 2025
- 4. FTC: Impersonation scams, April 1, 2024
- 5. CISA: Phone scammers impersonating CISA employees, revised June 18, 2024
- 6. Philippine National Privacy Commission: Preventive data privacy practices against smishing