Payment fraud and your supplier contracts: what to agree before it happens
When a supplier payment is redirected, someone loses the money. Here's what travel businesses should agree with their suppliers and agents in writing, before it happens.
Travel Ledger ยท 6-minute read ยท Updated October 2026
Why contracts are part of fraud prevention
At Xeinadin's Travel Leaders Summit in October 2026, an officer from the Metropolitan Police's Cyber Education Team warned travel businesses that, statistically, around half of small and medium-sized businesses could suffer a cyberattack in the next 12 months. He said most attacks start in the supply chain, urged businesses to make their third-party contracts โwatertightโ, and advised verifying anything unusual through a separate channel.
For travel businesses, the supply chain is also the payment chain. Agents pay suppliers, suppliers pay other suppliers, and every one of those relationships runs on invoices and bank details exchanged by email. A weakness on either side can cost both.
As reported by Travel Weekly (opens in a new tab), 8 October 2026.
The question nobody asks until it's too late
A fraudster gets into a supplier's email, alters the bank details on a genuine invoice and sends it to an agent. The agent pays. The supplier hasn't been paid, and the agent says it has.
Who carries the loss? Without clear terms agreed in advance, the honest answer is often: it depends, and it ends in a dispute that damages a good trading relationship. The time to agree the answer is before it happens.
Six points to agree in writing
These are points to discuss with your suppliers or agents, and with your own legal adviser. They are not template clauses.
- How payments are made. Agree the payment route and the account details in one place, and agree that nothing changes unless the agreed process below is followed.
- How bank-detail changes are handled. Agree that changes are never accepted by email alone, and how they will be confirmed: for example, by a call between named contacts using numbers already on file.
- Named contacts. Agree who on each side can request or approve changes to payment arrangements, and keep the list up to date.
- A duty to report quickly. Agree that each side tells the other promptly if it suspects its email or systems have been compromised, so the other can pause payments.
- Who bears the loss. Agree how a loss will be handled if a payment is redirected, including where the compromise happened on one side's systems. Clarity here protects the relationship as much as the money.
- Basic security expectations. Agree reasonable minimum standards on both sides, such as multi-factor authentication on email, and discuss whether either side should hold cyber insurance.
Know your supply chain
You can't protect a payment chain you can't see. Make a simple list of every business that can send you an invoice or payment instruction, and every business you send them to. For each one, record:
- the agreed payment route and when it was last confirmed;
- the named contacts and a phone number you trust;
- whether the points above have been agreed.
AI is making impersonation easier: convincing emails, and even cloned voices on the phone. A call from โyour supplierโ is only reassuring if you made it, to a number you already hold.
Have a payment-fraud plan, and practise it
If a payment goes to a fraudster, the first hour matters. Write down who does what: who calls the bank, who reports it, who secures email, who contacts the real supplier. Make sure everyone who handles payments knows where the plan is, and run through it once a year.
Our guide to spotting invoice and bank-detail fraud includes a first-hour checklist you can use as a starting point.
Where Travel Ledger fits
Many of these conversations get simpler when both sides settle through Travel Ledger. On the Travel Ledger Network, Trade Buyers and Trade Sellers agree how they settle, between both parties, inside their secure accounts. Connected suppliers are paid through TL Pay without bank details being entered from emails or invoices, and both sides work from one shared record of payment status and accepted balances.
That means one agreed payment route, no bank details to change by email, and a shared record to refer to if anything is ever questioned. For eligible suppliers outside the network, TL Virtual Cards give each payment its own card with set limits and validity.
This guide is general information, not legal advice. Speak to your legal adviser before changing your contracts or terms of business.
