Skip to content
Security and contact

How can I recognise official 2PayApp communications?

Official 2PayApp contact reaches you through the platform, through your account manager or from support@2payapp.com. Treat any unexpected message that asks you to change beneficiary or settlement details, disclose credentials or act urgently as suspicious, and verify it through a channel you already had. A correct-looking sender name, logo or domain is not proof of identity.

Last reviewed: 2026-09-09

Article facts

FieldVisible value
Support addresssupport@2payapp.com
Other official routesThe platform and your account manager
Will 2PayApp ask for a password or live code?No
Will 2PayApp ask you to move money to a "safe" account?No
Is a matching domain proof?No
Highest-risk requestA change of payment or settlement details
Last reviewed2026-09-09

The one attack that matters for a business

Business email compromise. Someone who can read or imitate your mail sends a plausible message asking you to update beneficiary details, a settlement instruction or an invoice payment address. The message is well written, arrives in a real thread and refers to real work.

The defence is procedural, not visual: a change to payment details is confirmed through a channel established earlier, never through the message that requested it. Call the number you already had. Do not use contact details supplied in the message.

2PayApp will not ask you to

  • disclose a password or a live one-time code;
  • install remote-access software;
  • move funds to a "safe" or "verification" account;
  • pay a fee to release a payment through an unofficial channel;
  • send company documents to a personal social-media or messaging account;
  • bypass the platform to complete a payment.

Warning signs

  • unexpected urgency, or a threat that an account will close unless you act now;
  • a lookalike sender domain, or a reply address that differs from the display name;
  • a change of bank or settlement details, especially late in a payment cycle;
  • an attachment or QR code you did not expect;
  • a link whose destination does not match its text;
  • a request that asks you to keep the matter confidential from colleagues.

How to verify a message

  1. Do not use the link, phone number or address in the suspicious message.
  2. Open the platform directly, or contact your account manager on the details you already held.
  3. Ask whether the message is genuine, quoting the time and sender address.
  4. Do not forward live authentication codes to anyone.
  5. If details were already changed, treat it as an incident and contact us immediately.

Reporting

Report suspicious messages to support@2payapp.com, with the sender address, the time and a screenshot. Report an actual or suspected compromise straight away rather than after investigating internally — timing matters for payments still in flight.

Frequently asked questions

Is an email from the right domain safe? Not on its own. A sender name and domain can be imitated.

Someone changed our settlement details by email. What now? Contact us immediately and treat it as a security incident.

Will an account manager ever ask for a code? No. Do not disclose a live code to anyone.

Can we set an internal rule for this? Yes, and you should: verify every change of payment details by voice on a number held in advance.

An email domain alone is not proof of identity. Verify through a separate channel you established earlier.

More answers