policy

Payment Redirection Scams: How to Verify Where Your Tuition Is Actually Going

How payment redirection fraud works, why emailed bank details alone are not enough, and what to verify against an official source before paying.

EduPay Editorial ·

Payment redirection fraud targets exactly the situation international students are in: a large, urgent, cross-border payment to an institution whose real bank details you have never seen in person. A scammer intercepts or mimics communication, swaps the account details, and your tuition lands in their account. The defence is simple to state and easy to skip: verify the destination against an official source before you pay, never from the email that gave you the details. This guide explains how.

How redirection fraud works

The typical pattern:

  1. You receive an invoice or payment instruction — often by email — with bank details for the university.
  2. The details have been altered, or a follow-up email “from the finance office” gives new details, citing urgency or a system change.
  3. You pay to the fraudulent account, believing it is the university.
  4. The real university never receives it; by the time the deadline passes, the money is gone or unrecoverable through normal channels.

The fraud succeeds because the instruction looks legitimate and the deadline creates pressure to act without checking.

Which details must be verified

Before any tuition payment, verify at minimum:

  • The beneficiary name — must match the university exactly, not a near-variant or a personal name.
  • The account number / IBAN and SWIFT/BIC — these are the details a scammer changes.
  • The payment reference — the university-assigned reference that ties the funds to your student ID.

None of these should be trusted solely because they arrived in an email.

Why emailed details should never be trusted on their own

Email is easy to spoof and easy to intercept. A detail sent by email could have been altered in transit or sent from a look-alike address. The verification rule is: cross-check the destination against a channel the university actually controls and that the scammer cannot alter — the official invoice portal, the university’s official website, or a number you obtained independently from the university’s published contact details.

If the email details and the official-source details differ, the email loses. Do not pay until they match from the trusted source.

How to verify against an official source

  • Open the payment instruction from the university’s official student portal, not from an email attachment.
  • Compare the account details on the portal to what you were about to use.
  • If you must use emailed details, confirm them by calling the university on a number from its official website, not a number in the suspicious email.
  • Be suspicious of any “updated details” email arriving close to a deadline, especially one urging secrecy or speed.

What to do if a payment has already been sent

If you have already paid to details you now doubt:

  1. Contact your sending bank immediately. If the transfer has not fully settled, they may be able to recall or hold it. Speed matters; once the recipient side releases the funds, recovery is much harder.
  2. Contact the university’s official payments team using a verified number, tell them the reference and amount, and ask whether the credit reached their account. If it did not, the destination was wrong.
  3. Report the fraud to the relevant authorities in your country and, if you are already in Australia, to Australian authorities. Keep every message as evidence.
  4. Do not pay again to “fix” it until you have verified the correct details through the official source; a second payment to the same bad details doubles the loss.

This is a payments-security issue, not a normal delay — do not run the standard missing-payment diagnostic first (see the troubleshooting guide); go straight to your bank and the university on verified channels.

Worked example: a last-minute “new details” email

A student received an email two days before his deposit deadline, purporting to be from the finance office, saying the bank details had changed and urging payment to a new account “to avoid delay”. The email looked convincing. Instead of paying, he opened the university portal, where the beneficiary details were unchanged. He called the number on the university’s official website — not the number in the email — and confirmed the details had not changed. The email was a scam.

Had he paid to the new account, the money would have left his control with no university credit, and recovery would have depended on how fast his bank could act. The verification step — checking the official portal and calling a verified number — cost five minutes and prevented a total loss.

Common questions

  • The email looks official — isn’t that enough? Email is easy to spoof. Verify against the official portal or a website-listed number, never the email itself.
  • What if the portal shows the same new details? Then the portal, not just the email, changed — still confirm by calling the official number before paying, especially if it is near a deadline.
  • I already paid to the emailed details — now what? Contact your bank immediately to attempt a recall and the university on a verified number to check receipt. Do not pay again.
  • Can a scammer spoof the portal? Use the portal URL you bookmarked or reached from the official site, not a link in the email. A look-alike domain is a common trick.
  • Why target tuition payments? Because they are large, urgent, and cross-border — exactly the conditions that make a recipient act without checking. Awareness is the defence.

Before you pay: a verification checklist

  • Open the payment instruction from the university’s official portal, not an email attachment.
  • Copy the beneficiary name, account, SWIFT, and payment reference from that official source.
  • If an email gives different details, trust the portal; call the university on a website-listed number.
  • Bookmark the official portal URL; never follow a link inside a payment email.
  • Treat any “updated details” email near a deadline as a red flag, not urgency.
  • Confirm the beneficiary name matches the university exactly, not a near-variant or person.
  • Verify the payment reference is your assigned one, not a generic instruction.
  • If you have already paid to unverified details, call your bank to attempt a recall now.
  • Report the fraud to the relevant authorities, keeping every message as evidence.
  • Set a rule: bank details come only from the official source, never from email.

Verification is the whole defence; this list makes it a habit, not a reaction.

After you paid and now doubt the details

If you have already paid and only afterwards wonder whether the details were genuine, act on two fronts at once:

  • Contact your bank immediately. If the transfer has not fully settled, they may be able to recall or hold it. Speed matters; once the recipient side releases the funds, recovery is much harder.
  • Contact the university on a verified number — from its official website, not the suspicious email — and ask whether the credit reached its account. If it did not, the destination was wrong.
  • Preserve every message about the payment as evidence, including the suspicious email and any replies.
  • Report the fraud to the relevant authorities in your country, and, if you are already in Australia, to Australian authorities.
  • Do not pay again to “fix” it until the correct details are confirmed through the official source; a second payment to the same bad details doubles the loss.

Doubt after payment is a payments-security emergency, not a normal delay. The bank and the university on verified channels are where recovery starts.

A note on urgency as a tactic

Scammers rely on urgency to skip your verification. Recognise the pattern:

  • A deadline pressure: “pay today or lose the offer” — real universities give stated deadlines you can verify on the portal, not a panic demand by email.
  • A change of details: “our bank details changed, use these” — verify against the official source, never the email.
  • A request for secrecy: “don’t tell the university, just pay” — legitimate payments are never secret.
  • A near-perfect copy: a look-alike domain or a forged letterhead — check the URL and the letterhead against the official site.

The presence of any of these is a reason to slow down, not speed up. Verification takes minutes; a wrong payment is a total loss. Treat urgency itself as the warning sign, and the scam loses its lever.

What to do next

Before your next tuition payment, open the university’s official portal and copy the beneficiary name, account, SWIFT, and payment reference from there — not from email. If an email gives different details, trust the portal and call the university on a website-listed number to confirm. Set a rule for yourself: bank details are only ever taken from the official source, never from an email, no matter how urgent. If you have already sent money to unverified details, call your bank now to attempt a recall and contact the university on a verified number to check receipt.

scam payment-redirection invoice-fraud verify-details security