# Vendor Payment Change Phishing Remediation Mini-Course

A free Jericho AI Studio giveaway package for security awareness, GRC, L&D, MSP, and vCISO teams.

Use this as a reviewable starter course for employees who may receive invoice, vendor, or payment-change requests. Replace placeholders with your approved finance workflow, reporting channel, and policy language before publishing.

**Attribution landing page:** https://contentstudio.jerichosecurity.com/campaigns/course-giveaway-phishing-remediation

**CTA for teams:** Start free at https://contentstudio.jerichosecurity.com/signup?lp=course-giveaway-phishing-remediation&utm_source=owned&utm_medium=giveaway&utm_campaign=phishing_remediation_course_giveaway&utm_content=mini_course_download&utm_term=vendor_payment_change

---

## Course snapshot

- **Title:** Vendor Payment Change Requests: Pause, Verify, Report
- **Audience:** Finance, operations, procurement, executive assistants, office managers, client-service teams, and anyone who can influence payments or vendor records
- **Format:** 5-7 minute micro-course
- **Recommended delivery:** LMS assignment, finance team refresher, new-hire add-on, or remediation after phishing simulation themes
- **Human review required:** Finance owner, security owner, L&D/training owner, and compliance/legal reviewer if the module references regulated data, contracts, or customer commitments
- **Primary learner decision:** When a vendor asks to change payment details, do not approve or act from the message itself. Verify through the approved vendor/payment-change process and report suspicious requests.

## Learning objectives

By the end of this short course, learners should be able to:

1. Recognize common warning signs in vendor payment-change and invoice-update requests.
2. Explain why familiar names, logos, and urgent language do not prove a request is safe.
3. Choose the approved verification path before changing payment details or sending funds.
4. Report suspicious or uncertain requests without shaming themselves or coworkers.

## Opening lesson copy

Vendor payment-change requests are attractive to attackers because they sit inside normal business pressure. A real vendor may send invoices. A real manager may ask for speed. A real finance team may be trying to close the month.

That is why the safest response is not based on whether the message looks polished. The safest response is based on process.

If a message asks you to change bank details, reroute a payment, approve an unusual invoice, or treat a vendor request as urgent, pause before acting. Verify the request through the approved process using a trusted contact or system already on file. Do not rely on the phone number, link, attachment, or reply address in the message itself.

If something feels off, report it through **[INSERT APPROVED REPORTING CHANNEL]**. Reporting early helps the security and finance teams investigate while the request is still fresh.

## Scenario 1: The familiar vendor

You receive an email from a vendor your company has used for years. The sender display name looks familiar. The email says the vendor recently changed banks and asks you to update payment details before the next invoice is processed.

The message includes a PDF on company letterhead and a phone number to call if you have questions.

**Decision point:** What should you do first?

A. Reply to the email asking for confirmation.

B. Call the phone number in the email because the vendor provided it for questions.

C. Verify the request through the approved vendor-change process using trusted contact information already on file.

D. Update the payment details because the vendor is familiar and the document looks official.

**Best answer:** C

**Teaching feedback:** Familiar names and official-looking documents are not enough. Attackers can spoof display names, compromise real accounts, and copy logos. For payment changes, use the approved vendor-change process and trusted contact information already on file, not contact details supplied inside the request.

## Scenario 2: The executive pressure message

A senior leader forwards an invoice thread and writes, “Can we get this handled today? The vendor says service may be delayed if we miss the cutoff.” The thread includes a new routing number and an updated remittance form.

You are busy, and the request looks connected to an existing project.

**Decision point:** What is the safest next step?

A. Process the change because a senior leader forwarded it.

B. Verify the payment-change request through the approved workflow, even if the request appears urgent.

C. Ask the vendor to resend the form from a personal email address.

D. Mark the message unread and wait until tomorrow.

**Best answer:** B

**Teaching feedback:** Urgency and senior-leader pressure are common ingredients in payment fraud. The safer action is not to ignore the request. It is to follow the approved verification process before changing payment details or approving payment.

## Scenario 3: The suspicious attachment

An invoice-update email includes an attachment named `Updated ACH Details.pdf`. The sender says the new banking information is in the file. The email also asks you not to use the old payment portal because it is “being migrated.”

**Decision point:** Which cue deserves the most attention?

A. The attachment has a PDF extension.

B. The message tries to move you away from the approved payment portal.

C. The email includes a signature block.

D. The vendor name is spelled correctly.

**Best answer:** B

**Teaching feedback:** File type, signatures, and spelling do not prove a request is safe. A request that tries to bypass the approved portal or normal workflow deserves extra scrutiny. Use the approved process and report the message if the request seems unusual.

## Knowledge check

### Question 1

A vendor asks you to change bank details and says the update must happen before close of business. What should you do?

- A. Update the details if the logo and signature look correct.
- B. Reply to the email and ask whether the request is real.
- C. Verify through the approved vendor-change process using trusted information already on file.
- D. Forward the message to a coworker and ask what they think.

**Answer:** C

**Feedback:** The key habit is process-based verification. Do not rely on the message itself to prove the request is legitimate.

### Question 2

Why is replying to the email not enough to verify a payment-change request?

- A. Email replies are always blocked by security tools.
- B. The sender account or reply address may be spoofed or compromised.
- C. Vendors never use email.
- D. Finance teams should ignore all payment-change requests.

**Answer:** B

**Feedback:** Attackers may control the reply path. Use an approved verification method that does not depend on the suspicious message.

### Question 3

What should you do if you are unsure whether a request is legitimate?

- A. Act quickly so the vendor is not delayed.
- B. Delete the message so nobody clicks it.
- C. Report or escalate through **[INSERT APPROVED REPORTING CHANNEL]** and follow the approved payment-change process.
- D. Use the contact details included in the message.

**Answer:** C

**Feedback:** Uncertainty is a reason to report or escalate, not a reason to guess. Reporting helps the right team review the request.

## Remediation note for simulation follow-up

If this course is used after a phishing simulation, keep the tone respectful. Do not call out individual learners in the course. Focus on the missed decision pattern, such as trusting sender display names, following urgent payment instructions, using contact details from the message, or skipping the vendor-change workflow.

A safe remediation introduction:

> Recent training activity showed that vendor payment-change requests are a useful area for extra practice. This short lesson reviews how to pause, verify through the approved process, and report suspicious or uncertain requests. The goal is practical reinforcement, not blame.

## LMS packaging notes

Recommended LMS metadata:

- **Course title:** Vendor Payment Change Requests: Pause, Verify, Report
- **Description:** A short cybersecurity awareness lesson that helps employees identify and safely handle suspicious vendor payment-change requests.
- **Estimated duration:** 5-7 minutes
- **Completion:** View lesson and answer all knowledge-check questions
- **Passing guidance:** Set according to your LMS and training policy
- **Accessibility:** Include captions/transcripts for any audio or video version
- **Export target:** SCORM, xAPI, HTML, or PDF as supported by your environment

## Review checklist before publishing

- [ ] Approved finance/vendor-change workflow added
- [ ] Reporting channel added
- [ ] Tool names, portals, and contacts checked
- [ ] Examples match the learner audience
- [ ] Quiz feedback teaches the safer action without shaming learners
- [ ] Compliance-sensitive statements reviewed if needed
- [ ] Captions/transcripts included for media versions
- [ ] LMS completion and reporting settings confirmed

## Jericho AI Studio prompt to recreate or adapt the course

Paste this into Jericho AI Studio as a starting prompt, then review the generated draft:

> Create a 5-7 minute cybersecurity awareness micro-course for finance and operations employees on vendor payment-change phishing. Include a short lesson, three realistic scenarios, three quiz questions with teaching feedback, a respectful remediation note for phishing simulation follow-up, captions/transcript guidance, and LMS export notes. The key behavior is to verify payment-change requests through the approved vendor-change process using trusted contact information already on file. Mark assumptions for human review and avoid claims that training guarantees compliance or prevents fraud.

## Proof-safe usage note

This giveaway is designed to support awareness, review, remediation, and LMS delivery workflows. It does not provide legal advice, guarantee compliance, prevent fraud, or prove behavior change. Review and adapt it to your organization’s approved policies before assigning it.
