How to Send Bank Details Securely (The Risk Isn't What You Think)
Your account number isn't really a secret — it's on every invoice you send. The danger is someone changing it in transit. How to send and receive them safely.
Almost every guide to this question gives the same advice as for a password: encrypt it, use a secure link, make it expire. That advice is mostly beside the point, because bank details are not really a secret.
Your account number and sort code (or routing and account number) are printed on your invoices. They’re on the bottom of your cheques. You give them to your employer, your clients and anyone who pays you. Treating them like a password is a category error.
The real risk runs the other way. It isn’t that someone reads your bank details. It’s that someone changes them.
The fraud this is actually about
It’s called invoice redirection, or business email compromise. It works like this:
- An attacker gets into somebody’s email — yours, your client’s, or your supplier’s. Often just one mailbox with a reused password.
- They sit and read. They learn who pays whom, how much, and in what tone.
- When a real invoice goes out, they send a follow-up: “Apologies — we’ve changed banks, please use the details below for this payment.”
- The money goes to them. Often nobody notices for weeks.
The email is genuine, from a genuine address, in a genuine thread, at exactly the right moment.
Nothing about encrypting the original attachment would have stopped it. Business email compromise has for years been among the costliest categories of cybercrime reported to the FBI’s IC3, far ahead of the things people worry about more.
So the property you need isn’t confidentiality. It’s authenticity — the payer needs to know the details really came from you and really weren’t altered.
If you’re sending your details (to get paid)
- Send them the normal way. Email is fine. Put them on the invoice, as you always have.
- Say, in the invoice itself, that your details will never change by email. One sentence: “Our bank details will never change. If you receive a message saying they have, call us on the number you already have before paying.” This single line does more than any encryption.
- Never send them as an editable attachment if you can send a PDF. It’s a small thing; a Word document is trivially altered in transit.
- Protect the mailbox itself. Nearly every case starts with a compromised email account. Turn on two-factor authentication — ideally a hardware key or an app, not SMS — and check for forwarding rules you didn’t create. That is the highest-value thing on this page.
If you’re receiving details (to pay someone)
- Verify out of band, always, on the first payment and on any change. Phone them on a number from your own records or their official website — never one in the email. Read the last four digits to them and have them confirm.
- Treat “our details have changed” as hostile by default. Legitimate suppliers change banks rarely; fraudsters claim it constantly. A real supplier will not mind you checking.
- Use name-checking where you have it. In the UK, Confirmation of Payee checks the account name against the account before you send. If it says the name doesn’t match, stop. Many countries have equivalent schemes.
- Send a small test payment first for a large or first-time transfer, and confirm receipt by phone before sending the rest.
- Watch for urgency. “Before end of day”, “the director is in a meeting”, “don’t call, just process it” — pressure to skip the check is the attack.
What must never be shared
Separate these from the account number, because they are genuinely secret:
- your online banking username and password;
- one-time passcodes your bank texts or pushes — no legitimate bank employee will ever ask for one;
- your card number, expiry and security code together (a different problem, covered in How to Send Credit Card Details Securely);
- answers to your security questions.
If something you send would let someone move money rather than receive it, the rules from How to Send a Password Securely apply instead — use a channel that expires, and split the pieces.
Where a tool helps, and where it doesn’t
For a finance team handing over account details, a payment reference or a client’s banking contact, WaxSeal fits the authenticity problem rather than the secrecy one. The secret is encrypted on the sender’s device for the named recipients’ devices, whose keys live in the Secure Enclave; the organisation’s vault stores ciphertext it cannot read; and what travels through email or WhatsApp is an ordinary photo carrying only an invisible reference. Because it opens only on a device you authorised, a forwarded copy opens for nobody — so “this came from our finance team, unaltered” is something the recipient can actually rely on. The sender can set it to open once, to expire, or to need a PIN given by phone, and can revoke it afterwards.
Two honest limits. WaxSeal carries text — a set of details, a reference, a credential — not documents or PDFs; there’s no file attachment. And no tool removes the phone call: if someone tells your payer your details changed, the thing that saves the money is a human confirming it on a number they already had.
The short version
- Your account number isn’t a password — stop protecting it like one.
- Verify every new or changed set of details by phone, on a number you already had.
- Put “our details will never change by email” on your invoices.
- Secure the mailbox — that’s where these attacks begin.
- Keep logins, card security codes and one-time passcodes in a different category entirely: those never get sent at all.
Frequently asked questions
Is it safe to send bank details by email?
What can someone do with my bank account number and sort code?
Someone emailed me that their bank details have changed. Is it a scam?
What is the safest way to send bank details?
StegoSafe hides AES-256-encrypted secrets inside ordinary photos — in a deniable format with no header or marker — and can split them across several photos with Shamir Secret Sharing. Runs fully offline on iPhone, iPad and Mac; one universal purchase. For organisations that must send a secret and control it afterwards, see WaxSeal
Get StegoSafe →