A company will spend four months on diligence, three law firms on the purchase agreement, and about eleven seconds on the bank account the money lands in. The wiring instructions arrive by email. Someone forwards them to accounting. The transfer goes out.
Most payment fraud in a business transaction has nothing to do with a fake counterparty. The counterparty is real. The deal is real. The invoice is real, down to the PO number and the correct remaining balance. One field in that document is false, and it is the only field nobody checks against an independent source.
Every other number in the transaction gets verified by somebody. The purchase price gets three sets of eyes. The closing date gets calendared twice. The account number gets copied and pasted.
The account number changes late, and on purpose
Fraud that works this way starts weeks before the wire. Someone gets into a mailbox, usually through a credential harvested from a phishing page or bought from a prior breach, and then does nothing. They read. They learn who signs off on payments, how the CFO writes, what the vendor calls the project, when the closing is scheduled.
Then they wait for the right thread and reply inside it. Same subject line, same signature block, same quoted history underneath. The message asks accounting to note updated banking details because the company changed institutions, or because the usual account is under review, or because of a treasury consolidation. The tone is bored. Real vendors are bored when they send banking updates.
Two mechanics do the heavy lifting. The first is an inbox rule that moves any message containing “invoice,” “wire,” or “payment” into RSS Subscriptions and marks it read, so the real vendor’s confused replies never surface to the account owner. Building that rule in Microsoft 365 takes two clicks, and it is the first artifact worth pulling from the audit log when a compromise is suspected. The second is a lookalike domain registered days before the request, where rn stands in for m or a .co replaces a .com, close enough that a reader scanning at speed sees the company they expect.
Timing does the rest. The request lands when everyone is busy, near a closing or a quarter end, when a delay costs somebody something and a question feels rude.
A callback to the number in the email is not a callback
Ask any controller whether they verify banking changes and most will say yes, they called. Ask where the number came from and the answer is the email, the signature block, or the invoice footer.
That is not verification. It is a confirmation of the thing you already believed.
An attacker who can edit the account number can edit the phone number sitting four lines below it. Some of them staff the line. A calm voice answers with the vendor’s name, confirms the last four digits, and thanks you for checking. The call becomes the strongest evidence in the file that the payment was authorized, which is exactly what it was built to be.
A number qualifies as independent when it existed before the request. The signed master services agreement. The vendor record created at onboarding. The main line published on the counterparty’s site, reached by typing the domain rather than clicking a search result, because the paid slot above the organic listing can be bought by anyone. A number you dialed successfully six months ago and still have in your call history.
Anything sourced from the message that prompted the check is part of the message.
What verification looks like when it actually works
The control is procedural, cheap, and boring, which is why it gets skipped.
Call the number on file and make the counterparty read the account details to you. Do not read them the digits you have and wait for a yes. People confirm what they are handed, and a fraudster on the line will agree with anything you say.
Send a penny ACH credit ahead of the wire when the receiving account accepts one, and get the arrival confirmed on that same callback. A two-cent test settling into the wrong account is a cheap way to learn something expensive.
Look at where the receiving bank actually is. A Tampa title company taking closing funds into an institution with no branch presence in Florida and no relationship history in the file deserves a question before the funds move, not after. Same for a payee name that arrives as a d/b/a nobody in the deal has seen written down.
Know that most banks post incoming wires on the account number alone. The beneficiary name is frequently not matched at all, which is the single mechanic that makes the whole scheme function. Sending money to “Acme Manufacturing” at an account belonging to a shell formed in June does not bounce.
Put dual approval above a dollar threshold you set in advance, and require that the second approver be someone who did not receive the original email. A single compromised mailbox should not be able to move money by itself.
Run the arithmetic against your own volume before deciding the process is too slow. A firm sending forty outbound wires a month at an average of $85,000 moves $3.4 million through a control that costs one two-minute phone call per payment. Eighty minutes of staff time a month. One diverted wire at that average pays for the next thirty years of it.
The first few hours decide whether the money comes back
Recovery is a clock problem. Funds landing in a domestic receiving account get pulled or forwarded to a second and third account fast, often within the same business day, and each hop makes the trace longer and the return less likely. A Friday afternoon wire discovered Monday morning is usually a Monday morning loss.
Call the originating bank first and use the words “fraudulent wire, request recall.” The relationship manager is the wrong person for that call. Reach the wire room or the fraud desk directly, by phone, immediately. Then file with the FBI’s Internet Crime Complaint Center, which is also where you can pull the annual reporting on business email compromise and see how your own exposure compares against the reported national totals. For international transfers, the FBI’s Financial Fraud Kill Chain can freeze funds when a wire meets a dollar threshold and gets reported inside a tight window. Confirm the current threshold and the current window with your local field office now, while nothing is on fire.
Preserve the mailbox before IT cleans it. Full headers, the audit log, the sign-in records, the inbox rules, the registrar record for any lookalike domain. Deleting the malicious rule and resetting the password feels like remediation and destroys the record of how long the intruder had been reading, which is the question your insurer and your counterparty’s lawyer will both ask.
Law firms and title companies carry the worst exposure
An attorney holding closing funds sits at the intersection of a public schedule, a known dollar amount, and a client who has never wired money before and does not know what normal looks like. Real estate closings get advertised by the transaction itself. Court records, lien filings, and county recordings publish the timeline for free.
The client on the other end is the soft target. They receive instructions from a firm they have emailed twice, on a matter where every step has felt slightly confusing, and they have no baseline for what a legitimate change request sounds like. Sending wiring instructions to a buyer without a separate voice conversation setting expectations beforehand is handing someone a document they cannot evaluate.
The exposure runs past the money. Bar complaints, malpractice notice, an insurer asking what controls existed, a client whose down payment is gone.
After a loss, the investigative work looks different from the accounting work. Message headers and registrar records establish when the intrusion started and who registered the lookalike domain. The receiving account gets traced through the entity that opened it, and that entity usually has a corporate registration, a registered agent, and an incorporation date that lands suspiciously close to the transaction. This is the same discipline that confirms an operating address instead of accepting the one on the letterhead, and the same one that asks where the money actually came from rather than whether it exists. Applied before a transfer, it prevents the loss. Applied after, it builds the record for recovery and for the insurance claim.
It also has a shelf life. A vendor verified at onboarding two years ago is a vendor verified two years ago, and the same decay that makes a background report go stale applies to banking details, authorized signers, and who still works there.
Run this check on your own operation this week
Ask whoever approves your outbound payments what happens when a vendor emails new banking details. Listen for whether the answer names a person or names a procedure. If it names a person, you have the finding. Then ask a second question: can that person execute the change alone, and where would the record of the old details live afterward.
Most firms discover the control exists in somebody’s head, was never written down, and has been quietly bypassed whenever the request looked urgent enough.
Farsight Intelligence works on the counterparty side of transactions like these, before the wire and after it: verifying who is actually on the other end, tracing where funds went, and building the documentation that holds up when the insurer and opposing counsel start asking. If you are moving money to someone you have only met by email, or you have already sent it and the account went quiet, start at brettfl.com, book time at meet.brettfl.com, or write to [email protected].
Call the number on file.