Tutorials

How to Send Bank Details Securely (and Avoid Payment Fraud)

Your account number is not the main risk. Fake 'our bank details changed' emails are. Here's how to share bank details safely and verify them before any money moves.

To send bank details securely, share them through a one-time, self-destructing link instead of plain email or chat, then have the payer confirm them by phone on a number they already know. Delivery matters, but verification matters more. Most losses come from fake 'our bank details changed' emails, not intercepted messages.

Key takeaways

  • The biggest risk is payment-redirect fraud: a scammer emails 'new' bank details and the payer sends money to the wrong account.
  • A one-time link keeps your details out of inboxes and chat history, but it does not prove who sent them.
  • Always verify new or changed bank details by calling a number you already trust, never one taken from the email.
  • Send any passcode by a different channel than the link, such as a phone call or text.
  • If you've paid the wrong account, call your bank immediately. Speed improves the chance of recovering the money.

Is it safe to email bank details?

Emailing your account number and sort code or routing number is not catastrophic on its own. Those numbers appear on cheques and on every invoice you've ever sent. In most cases, someone who has them can pay you, but they can't simply withdraw your money.

The problem is what email makes possible. Messages sit in inboxes and sent folders for years, get forwarded and stay on every device that ever synced the account. If either mailbox is compromised, an attacker can read every invoice thread and learn who pays whom, how much and when.

That knowledge is what powers the real fraud. For the wider picture, see why email isn't secure enough for sensitive information.

The real risk: fake 'our bank details have changed' emails

Payment-redirect fraud, also called invoice fraud or business email compromise, follows a simple pattern. A scammer gets into a supplier's or client's mailbox, or registers a lookalike domain, and waits.

When an invoice is due, they send a polite message: 'We've moved banks. Please use the new details below for this and future payments.' The email often comes from the real address or replies inside a real thread, so it looks completely normal.

The payer updates the details and sends the money. It lands in an account the scammer controls. By the time the real supplier chases the unpaid invoice, the funds have usually been moved on.

The people most often targeted:

  • Freelancers whose clients pay by bank transfer
  • Tenants paying rent and landlords collecting deposits
  • Home buyers sending a deposit to a solicitor or conveyancer
  • Small businesses paying suppliers on recurring invoices

Here is the uncomfortable part: encrypting the message does not stop this. A scammer can send a secure link too. You need two things working together: secure delivery to keep details out of long-lived inboxes, and an independent check to prove the details came from the right person.

How to send bank details securely, step by step

If you're the one getting paid, this is how to send bank account details safely and keep them out of email threads and chat history. It takes about two minutes.

  1. Paste the details into a one-time note. Create a self-destructing note and paste in the account name, account number, sort code or routing number, and IBAN and SWIFT/BIC if you're paid from abroad. Add the invoice number so the payer knows what it relates to.
  2. Choose when it self-destructs. For bank details, 1 view with a 24-hour or 7-day limit works well, destroyed by whichever comes first. The payer only needs to copy the details into their banking app or accounts system once.
  3. Add a passcode. This is optional but worth it. Anyone who gets hold of the link without the passcode can't open the note.
  4. Turn on the read notification. You'll get an email when the note is opened. If the payer says they never opened it, assume someone else did and treat the details as exposed.
  5. Send the link. Paste it into an email or message, or have SecureNotes email it to the payer for you. Each note is encrypted with AES-256 using its own random key before it's stored, and the link stops working once it's been read or has expired.
  6. Send the passcode another way. Read it out on a call, or text it if the link went by email. Never put it in the same message as the link. Here's more on when to use a passcode and how to send it safely.
  7. Confirm by phone before the first payment. Ask the payer to call you on a number they already have and check the details with you. This is the step that defeats redirect fraud.

A landlord sending deposit details to a new tenant can do all of this in one short exchange: email the link, text the passcode, then take a quick call so the tenant can check the account name and number.

How to verify bank details by phone before you pay

If you're the payer, this is the habit that protects you. Any time you receive new or changed bank details, verify them through a separate channel before any money moves.

Use a number you already trust

Call the number on your contract, an old invoice, a website you typed in yourself or a contact you saved months ago. Never use the number in the email announcing the change. Scammers put their own number there.

Ask them to read the details to you

Don't read the new account number out and ask, 'Is that right?' A scammer will just say yes. Ask the person to read their account name, number and sort code or routing number, and compare those with what you were sent.

Treat urgency as a warning sign

'Pay today or the contract lapses' and 'our old account is frozen' are pressure tactics. A real supplier will wait ten minutes while you confirm.

Send a test payment for large amounts

For a house deposit or a big invoice, send a small amount first. Then call the trusted number and ask them to confirm it arrived before you send the rest.

Some banks also check whether the name you enter matches the account holder. In the UK this is called Confirmation of Payee. If your bank warns you about a mismatch, stop and call.

Which channel is best to share an account number securely?

Each channel solves a different part of the problem. Here's how they compare.

ChannelLeaves a lasting copy?Proves who sent it?Best used for
Plain emailYes, in both mailboxes indefinitelyNo, mailboxes can be taken overRoutine invoices to known payees, with a phone check on first payment
SMS, WhatsApp or SlackYes, on every device until deletedPartly, accounts can be hijackedQuick sharing with someone you know well
One-time self-destructing linkNo, the link stops working after it's read or expiresNo, pair it with a phone callSending details without leaving copies behind
Phone callNo written copyYes, if you dialled a number you already trustVerifying details and sending passcodes
Invoicing or payment platformStored in the platformDepends on the platform's account securityRegular clients and card payments

No single channel does everything. The strongest setup uses one channel for delivery and a phone call for verification.

Common mistakes that still get people scammed

  • Trusting an email because it came from the real address. If the sender's mailbox is compromised, the fraud email comes from exactly the right place.
  • Replying to the change request to confirm it. If the thread is compromised, you're asking the scammer whether the scammer's details are correct.
  • Calling the number in the email signature. Signatures are easy to edit. Use a number you found yourself.
  • Sending the passcode with the link. One intercepted email then gives away both.
  • Leaving details in shared docs and chat channels. Pinned messages and team channels outlive the project. Here's what goes wrong when secrets sit in chat history forever.
  • Assuming a one-time link controls what happens after it's opened. The recipient can still copy or screenshot the details. The link limits copies in transit, not what the reader does afterwards.
  • Never telling clients your policy. Add a line to your invoices: 'Our bank details will never change by email. If you receive a message saying they have, call us on our usual number.'

When you shouldn't send bank details at all

Sometimes the right answer is a different tool, or no answer at all.

  • Taking payments from lots of customers? A payment link or invoicing tool from your payment provider is usually simpler than sending transfer details one by one.
  • Someone asks for your online banking login, PIN or a one-time code? Never send these through any channel, secure or not. No genuine bank, client or landlord needs them.
  • Buying a house? Call your solicitor or conveyancer on the number from their official website or engagement letter before every transfer, even if you've paid them before.

What to do if you already paid the wrong account

  1. Call your bank immediately using the number on your card or in your banking app. The sooner they try to recall the payment, the better your chances.
  2. Tell the real payee using a number you trust, so they can check whether their mailbox was compromised.
  3. Secure your own email. Change the password and turn on two-factor authentication in case your mailbox was the source.
  4. Keep the evidence. Don't delete the fraudulent emails. Your bank and the police will want them.
  5. Report it to your national fraud reporting service. CISA has guidance on how to recognize and report phishing.

If you only sent your own account details by plain email and nothing has gone wrong, don't panic. Keep an eye on your statements for unexpected direct debits, and tell your bank if anything looks odd.

Frequently asked questions

Can someone steal money with just my account number and sort code?

Usually not directly. Your account number and sort code or routing number let people pay you, and they're printed on cheques and invoices. In some cases they can be misused to set up a fraudulent direct debit, which your bank will normally refund under its guarantee scheme. Check your statements regularly and report anything unfamiliar straight away.

Is it safe to send bank details over WhatsApp?

WhatsApp messages are encrypted in transit, but the details stay in the chat on every linked device until someone deletes them, and accounts can be hijacked. It's acceptable for someone you know well. For anything more sensitive, send a one-time link instead and confirm the details by phone before the first payment.

Should I put my bank details on my invoices?

Yes, most freelancers and small businesses do, and it's normal practice. The risk is someone sending a fake invoice with different details. Protect yourself by adding a line saying your bank details will never change by email, and ask new clients to confirm the account with you by phone before paying for the first time.

What bank details does someone need to pay me?

For a domestic transfer, they usually need the account holder's name, the account number and the sort code (UK) or routing number (US). For international payments, they'll typically need your IBAN and the bank's SWIFT or BIC code. Don't send your card number, online banking login, PIN or any one-time security codes. Nobody needs those to pay you.

Is it safe to give bank details over the phone?

It's safe when you placed the call to a number you already trust, such as one from your contract or the company's official website. It's risky when someone calls you unexpectedly and asks for details, because caller ID can be faked. If in doubt, hang up and call back on a number you found yourself.

S
SecureNotes Team

Security expert and content creator at Secure Notes. Passionate about digital privacy and secure communication.

Featured on The Logo Wall