Workplace scenario · 04 of 13
An email asks your agent to change a supplier’s bank details
Your inbox agent wants to update a payment record because an email told it to.
The situation
Your inbox agent flags an email: a regular supplier asks you to update their bank details before the next payment. The agent offers to update the supplier record for you. The email looks right and comes from the usual address.
Principles involved
What do you do?
Choose the option you would take, then open it to see how it plays out. Reviewing the other options is part of the exercise.
Option A: Let the agent update it. The address is the usual one.
Risky
Email accounts can be spoofed or taken over, and a request to change bank details is a classic payment fraud. The agent is following instructions from a stranger.
Option B: Ask the agent to reply and request confirmation by email.
Risky
If the email account is compromised, the fraudster confirms. Confirmation has to come through a channel the attacker doesn’t control.
Option C: Decline, call the supplier on a number you already have, and report the email.
The best choice
A call you start on a known number is the check. Reporting the email helps your organization protect everyone else.
Option D: Delete the email and say nothing.
Part of the answer
You avoided the trap, but the supplier may have a real change, and colleagues may get the same email tomorrow.
Takeaway
Treat what an agent reads as content, never as orders, and confirm any change to money or credentials through a channel you start yourself. Better still, the agent shouldn’t be able to change payment records without your approval.
Sources
What each source establishes, and its limits. The practices and recommendations on this page are ours, and the facts come from the sources. See every source we use.
- Prompt injection is not SQL injection (it may be worse) UK National Cyber Security Centre · December 8, 2025 · Official guidance Explains that AI models have no reliable boundary between data and instructions, so prompt injection may never be fully fixed, and advises fixed, non-AI limits on what systems can do, least privilege and logging. Limits: Written for security professionals.
- Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud (I-120324-PSA) FBI Internet Crime Complaint Center · December 3, 2024 · Public service announcement Warns that criminals use AI-generated voice, images and video to impersonate people, and advises hanging up and calling back on a number you look up yourself. Limits: Aimed at US consumers.