Secure information handling Current
Requesting bank account details securely from a client
A practical approach to collecting sensitive financial details.
Bank account details are a common target for business email compromise and payment redirection fraud. This guide sets out practical steps for collecting them more securely. It is general information, not a substitute for your firm's own cyber security policy or advice.
Action plan
1 Avoid collecting bank details over plain email Plain email is a common target for interception and impersonation.
Bank account details sent as plain text in an email are relatively easy to intercept or spoof, and are a common target for business email compromise scams. Where practical, use a structured, authenticated form or secure portal instead of asking a client to type account details directly into an email.
- Prefer a structured intake form or secure portal over free-text email
- If email must be used, avoid sending or requesting full account numbers in the message body alone
- Treat any late change to previously provided bank details as a red flag requiring extra verification
Done when: A structured or authenticated channel is used instead of plain email for bank detail collection
ACSC: preventing business email compromise2 Verify new or changed bank details out of band Confirm bank details through a separate channel before acting on them, especially if they have changed.
Before acting on a new or changed bank account, confirm the details through a separate, previously known channel, such as a phone call to a number you already have on file, not a number supplied in the same message. The Australian Cyber Security Centre gives this same advice for requests to change payment details: verify by calling the sender on a known and verified phone number, not one supplied in the request itself.
- Call the client on a number already on file to confirm new or changed bank details
- Never rely on contact details supplied in the same message as the bank detail change
- Document how and when the verification call took place
Done when: New or changed bank details have been confirmed through a separate, previously known channel
ACSC: preventing business email compromise3 Limit access to stored bank details Store bank account details securely and restrict who can view or change them.
Once collected and verified, bank account details should be stored securely and access limited to staff who genuinely need it, consistent with a baseline cyber security approach such as the Australian Signals Directorate's Essential Eight. Vertical Flows can structure the intake and evidence workflow this relies on; it does not set your firm's cyber security policy.
- Restrict access to stored bank account details to staff who need it
- Apply your firm's baseline cyber security controls to systems storing this information
- Review access periodically, especially after staff changes
Done when: Stored bank account details have restricted access consistent with your firm's security baseline
See how structured intake and review works