This is why all staff, whether at a corporation, nonprofit or government that handle money should be put through a two hour anti-phishing training course. There's lots of good free training material out there. There are also services which you can hire. You give them a list of staff emails, and they send test phishes to everyone. Those who respond or click on links (there's a GUID in each phish) can be sent for furth…
While I think everyone should be aware of phishing, I don't think any amount of education can reliably prevent this sort of fraud. I see this fundamentally as a process problem, as I assume email was a common way of changing payment information. Email needs to be taken out of the loop.
The (possibly remedial) education isn't to prevent the fraud, it's to make your population more resistant to it.
At some point in the far future if it's part of basic education courses, then we may create herd inoculation effect where phishing fraud may become unprofitable enough to further depress likelihood (like highway banditry of days yore).
Email will never go away - it will always be some part of the payment process even if it's just remittance. It's too ubiquitous.