Your bank and brokerage accounts are prime targets for social engineers and account-takeover attacks. One simple, high-impact safeguard is to block new payees, external accounts, and outgoing transfers by default. This creates a hard pause: even if someone tricks you or briefly accesses your account, funds can’t leave until you approve a change through a secure path. This guide explains how these settings work, how to turn them on, and the habits that keep them effective.
Why Blocking New Payees and External Links Works
Most financial fraud succeeds at the “last mile,” when money moves out to an attacker-controlled destination. By default-blocking new payees and links to external accounts, you stop that last mile. Even if a criminal:
- Convinces you to share a one-time code
- Phishes your login and slips past basic MFA
- Installs malware that creates a transfer in your browser session
they still run into a policy wall: your account refuses to add or send to new destinations without a second, stronger approval route. That friction is what saves accounts in real life.
Know the Features to Ask For
Banks and brokers use different names for similar protections. Look for (or ask support about) these terms:
- Block new payees/beneficiaries by default: Requires extra approval before creating a new payee.
- External transfer lock or disable external ACH: Prevents linking or sending to new external bank accounts.
- Wire transfer suppression or wire disabled: Blocks all outgoing domestic and international wires until re-enabled.
- International transfer disabled: Stops cross-border payments entirely unless temporarily lifted.
- Standing whitelist (allowlist): Only previously approved payees can receive funds; everything else is blocked.
- Dual approval / step-up verification: Adds an out-of-band verification (e.g., calling support from a known number, or a physical token) to approve new payees.
- Transfer limits and cooling-off periods: Low daily caps and a delay before the first payment to a new payee.
- Profile lock: Prevents changes to contact details (phone/email), reducing SIM-swap and recovery-hijack risks.
Where to Find These Settings
Start in your bank or broker’s “Security,” “Payments,” or “Transfers” settings. If you don’t see these controls, use secure chat or call the number on the back of your card to request enrollment. Many institutions can add a server-side lock that’s stronger than an app toggle.
- Retail banks and credit unions: Look under Zelle/Pay Anyone, External Transfers, ACH, and Wire Transfer settings.
- Brokerages: Check Transfers & Payments or Funding. Ask for restrictions on outgoing ACH and wires from your brokerage and retirement accounts.
- Neobanks/fintechs: If the app lacks granular controls, ask support for an “outbound transfer disable” and a “new payee approval requirement.”
Recommended Default Settings (Baseline)
For most individuals, these default settings offer strong protection with minimal daily friction:
- Block all new payees/beneficiaries by default.
- Disable linking to new external accounts (ACH) unless approved via a separate channel.
- Disable outgoing wires unless you explicitly re-enable them for a single transaction.
- Enable a whitelist for a few trusted payees you use often. Everything else requires re-approval.
- Set low transfer limits (e.g., $0–$100) for new payees and increase only case-by-case after a cooling-off period.
- Require step-up verification for any profile change (email, phone, address) and for new device logins.
- Enable alerts for attempted new payees, profile changes, and failed login attempts.
How to Approve a New Payee Safely
When you truly need to pay someone new or link a new bank, follow a process that avoids the shortcuts criminals exploit:
- Initiate from a known device and network: Use your own device on your home network, not public Wi‑Fi.
- Verify the request out-of-band: If someone asked you to add a payee, confirm by calling a known number you trust (not one they provided).
- Use the bank’s secure channel: Approve inside the official app or website you navigated to yourself. Avoid links in texts or emails.
- Apply a cooling-off period: If your bank offers it, set a 24–48 hour delay before the first payment to a new payee.
- Keep limits low for first payments: Start with the minimum amount required. Only raise limits after independent verification.
Extra Layers That Make These Controls Stronger
- Hardware security keys: Add a FIDO2/WebAuthn key as your primary second factor where supported to resist phishing and session hijacking.
- Remove weak recovery methods: Turn off SMS-based recovery where possible; require strong MFA for password resets and device enrollment.
- Lock profile changes: Some banks can require phone support plus additional verification to change email/phone on file.
- Device approvals: Require manual approval for any new device, with alerts for each attempt.
- Statement-only mode for dormant accounts: If you rarely move money from a specific account, ask for outbound transfers to be permanently disabled.
Social Engineering Red Flags Around Payees and Transfers
Criminals try to rush you past your safeguards. Stop and reassess if you encounter:
- Urgency and fear: “Your account is under attack—move funds now to a ‘safe’ wallet.”
- Support impostors: Unsolicited calls or chats asking you to approve a new payee or read back codes.
- Refund or prize hooks: Requests to link your account or reverse a mistaken transfer.
- Third-party remote tools: Pressure to install screen-sharing apps to “help” with verification.
- Unverified invoices: Instructions to wire or ACH to a changed account number without independent confirmation.
What to Do if Your Account Attempts a New Payee Without You
Act quickly and methodically:
- Do not approve anything. Ignore prompts and hang up on unsolicited callers.
- Call the bank using a trusted number (card back or website you type yourself). Report “unauthorized payee setup attempts.”
- Request a full outbound lock on wires and external ACH until reviewed.
- Rotate credentials: Change your password from a clean device; revoke unrecognized devices and sessions.
- Tighten alerts: Turn on notifications for payees, profile changes, new devices, and failed logins.
- Review statements and dispute any unauthorized transactions immediately.
Business and Joint Accounts: Extra Considerations
Shared accounts introduce more risk pathways. Add governance:
- Dual control: Require two distinct approvers for new payees and any transfer above a threshold.
- Role-based access: Limit who can create payees versus who can submit payments.
- Vendor whitelists: Approve only known vendor accounts; add a mandatory cooling-off period for changes to vendor banking details.
- Audit alerts: Send payee-change alerts to at least two owners or admins.
How This Fits Into Broader Identity Protection
Financial safeguards stop money from leaving, but you also want early warning if your identity is being used elsewhere. Layer your bank and broker protections with credit and identity monitoring to catch new accounts, inquiries, and changes tied to your name. If you want a single place to watch for credit report changes and activity that could signal account takeover or identity misuse, consider a dedicated monitoring tool such as SmartCredit.
Step-by-Step: Turning On Safeguards (Typical Flow)
Every institution is different, but this general flow works across most platforms:
- Log in from a trusted device and navigate to Security or Transfers.
- Disable outgoing wires and international transfers by default.
- Enable “require approval for new payees/beneficiaries.”
- Disable external account linking (ACH) or set it to “approval required + cooling-off.”
- Create a whitelist of 2–5 trusted payees you use often.
- Set low per-transaction and daily limits; add a 24–48 hour delay for first payments to any new payee.
- Turn on alerts for payee additions, profile changes, failed logins, and new devices.
- Contact support to request any server-side locks not visible in the app (outbound transfer lock, wire suppression, ACH disable, profile lock).
- Document your process: Keep notes on how to temporarily lift a lock when you truly need to, and how to verify support calls.
Common Obstacles and How to Solve Them
- My bank doesn’t show these options: Ask support to add server-side restrictions. Use exact terms like “outbound transfer lock” or “wire suppression.”
- I need to pay new people often: Keep a whitelist but require step-up verification and a low first-payment cap for any new payee.
- My partner needs access: Use joint approval or role-based permissions instead of sharing passwords or bypassing safeguards.
- Traveling internationally: Keep international transfers disabled and temporarily lift them for a single transaction via a verified call.
- Fintech app limitations: If the app is too permissive, route large payments through a traditional bank account with tighter controls.
Maintenance: Keep Safeguards Effective
Security settings lose value if they drift. Build light, regular habits:
- Quarterly review: Reconfirm that wires and external links are disabled by default and that alerts still fire.
- Whitelist hygiene: Remove dormant or one-time payees after use.
- Device inventory: Revoke access for old phones, browsers, or computers you no longer use.
- Recovery channel check: Ensure your email and phone are current and protected with strong MFA.
- Breach response: If any of your credentials appear in a breach, change passwords and re-evaluate transfer locks immediately.
Quick Reference: Settings to Turn On Now
- Block new payees/beneficiaries by default
- Disable external account linking and outgoing ACH by default
- Disable outgoing wires; enable per-transaction reactivation only
- Enforce low new-payee limits and a cooling-off period
- Require step-up verification for profile changes and new devices
- Enable alerts for payee additions, transfers, profile changes, and failed logins
- Ask support for server-side outbound locks and profile locks
Conclusion
Blocking new payees and external links by default removes the “easy exit” that fraudsters rely on. Pair these bank and broker settings with strong authentication, tight alerts, and careful approval habits, and you transform your accounts from soft targets into hardened ones. Take fifteen minutes to enable the controls outlined here—add a whitelist, set cooling-off periods and limits, and request server-side locks from support. When money can’t move without deliberate, verified action, your financial identity becomes far harder to exploit.
Good to Know
If your bank or broker doesn’t advertise a “block new payees” option, ask support to enable a hard “outbound transfer lock,” a “wire suppression,” or “external ACH disable” on your profile; many institutions offer these controls on request even if they’re not visible in the app.