Wire Fraud in Construction: The Fake Payment Email That Costs Firms Six Figures
A scammer has been quietly reading your project email, and now a message just landed asking you to send the next draw to a new bank account. It looks like it came from your sub. The money leaves, and it rarely comes back.

The email lands right on time. It is from a sub on a live project, or the GC, or a supplier you have used for years. Their banking changed, here is the new account, please send the next payment there. The project is real. The timing lines up with the draw. So accounting sends the wire.
Days later, the real vendor calls asking where their money is. You already sent it, and it went to a criminal. This is wire fraud, and it can cost a construction firm six figures in one email.
Here is the short version. Wire fraud in construction is a scam where criminals get into or imitate an email about a payment and send you fake wiring instructions, so your money goes to them instead of the real vendor. Construction is a favorite target because the payments are large, many parties pass money around, and verification is usually loose. It works because the email looks completely real. The defense is one hard rule: verify every payment change by phone, using a number from your signed paperwork, before you send a dime. Two things most firms learn too late. You will probably still owe the real vendor. And your insurance may not cover it unless you bought the right add on.
What wire fraud in construction actually looks like
This is not a clumsy scam with bad spelling. It is patient, and it hides inside your normal business.
Criminals either break into an email account (yours, a vendor’s, or a partner’s) or imitate one with a lookalike address. Then they insert themselves into a real conversation about a real payment. They wait for the moment a draw is expected and send new wiring instructions that fit right into the thread. It rides on a genuine project at genuine timing, so it does not raise alarms. Your accounting person updates the account and pays.
They do not break your firewall. They break your trust, by wearing the face of someone you already pay.
A few tells show up over and over. The reply to address does not match the from address. The domain is off by one character, like a lowercase L standing in for a capital I. The instructions arrive as a PDF on vendor letterhead, a tidy little “bank change form,” because a form feels official. And the request shows up right before a payment you know is due.
Why construction is a favorite target
The payments are large. A single draw can be tens or hundreds of thousands of dollars. One diversion is a huge score for a criminal and a brutal loss for a firm.
The money changes a lot of hands. It flows from the owner to the GC, to the subs, to the suppliers. Every handoff is an email about a payment, and every one is a chance to slip in. Add deadline pressure, because a rushed payment is a poorly checked payment.
And in our experience, verification is loose. Most small firms have no written rule for confirming a bank change. They just update it and pay.
The formal name for this is business email compromise, or BEC. In its 2024 alert, the FBI put worldwide exposed losses from BEC at more than $55 billion since 2013.
A realistic example, step by step
For example, let’s say you are three months into a job and your framing sub is due a large draw. A criminal has quietly been reading the email between your office and that sub. Two days before the draw, an email arrives that looks like it came from your contact there. “Heads up, we switched banks. Please send this draw to the new account below.” The logo is right. The tone is right. It even names the project.
Your bookkeeper updates the account and wires the draw. Everything looked normal and the deadline was tight. Nobody called to check, because there has never been a rule to call. Three days later the sub calls, confused, because they never got paid.
The money is gone. The sub still needs paying. Nobody did anything obviously wrong. That is what makes it dangerous.

The one rule that stops it: verify by phone
Any request to change payment details, or any unexpected wire instruction, gets confirmed by phone before you send anything.
But the rule only works if you get the number right, and this is where firms go wrong. Do not use the number in the email. Do not use the number in the new instructions. And do not use the number in the vendor’s email signature, because if their mailbox is compromised, that signature can be edited too.
Use a number from paperwork the criminal never touched. The signed subcontract. The W9. The prequal packet. The certificate of insurance. Those numbers were verified when the relationship started, and they live outside email.
You call that number and ask one question. “Did you change your bank account?” That call kills this version of the scam, because the criminal cannot answer that phone.
This is what we call a callback rule. It has to be written policy, not a judgment call, with no exceptions for urgency. Urgency is the reddest flag there is.
One honest caveat. The callback rule is very good, not magic. Criminals sometimes call your staff first to prime them, and voice cloning is cheap now. That is why you place the call instead of taking one.
More on the related scams in our post on the phishing emails targeting AEC firms.
Back the rule up with controls that do not rely on memory
A rule that lives in someone’s head fails on the busiest week of the year. Put a few controls behind it:
- Require two people to approve a bank change — one updates the vendor record, a second approves it, so a criminal has to fool two people.
- Add a cooling off period — no payment goes out on a newly changed account for 24 hours, because fraud is built on speed.
- Pay by ACH instead of wire when you can — a wire is final the moment it lands, while ACH moves slower and has a limited return window.
- Ask your bank about callback verification and positive pay — most will call you before releasing a wire over a set amount, often free.
If you are a small firm, here is your version. A three person office cannot split duties the way a 60 person GC can. So pick a dollar threshold, say $5,000, and make every payment over it require a callback, even for the owner. Then write each vendor’s trusted phone number into your accounting system at onboarding. Proactive is better than reactive, and this takes an afternoon.

Other defenses that help
Turn on MFA, and pick the right kind. Multifactor authentication (MFA, a second step to log in beyond a password) blocks a lot of email break ins, and you should have it on. But here is what most articles will not tell you. Regular MFA can be beaten. Criminals run fake login pages that pass your code through to Microsoft in real time and steal your session cookie, the pass your browser holds after you log in. You do everything right and they still get in. Microsoft documented these attacks again in 2026. The fix is phishing resistant MFA, meaning passkeys or hardware keys instead of texted codes. CISA recommends it. More in our post on what small firms get wrong about passwords.
Lock down your email domain, and know what it does. Email authentication (the records called SPF, DKIM, and DMARC) stops criminals from sending fake email that looks like it came from your firm. But know the limit. It does nothing about email from a vendor’s hacked mailbox or from a lookalike domain, and those are the two ways this scam reaches you. For that you want impersonation filtering on, plus a banner marking outside email as outside. More in our post on why your emails are landing in spam.
Train the people who touch money. The firms that get burned are the ones where nobody felt they could question a rushed request.
Check your insurance before you need it
Many cyber and crime policies do not cover this loss by default.
The reason is a clause called voluntary parting. Your employee sent the money on purpose, even though they were tricked, so the policy treats it as money you gave away rather than money that was stolen. Carriers and courts do not all read it the same way, and you do not want to find out during a claim.
What you want is an add on, usually called a social engineering fraud or funds transfer fraud endorsement. Ask your agent two things. First, the dollar cap, because these often carry a sublimit around $100,000 to $250,000, well below a real draw. Second, the conditions, because many will only pay if your staff called the vendor back at a verified number.
Read that last part again. Your insurance may require the exact callback rule we just described. More in our post on answering a cyber insurance questionnaire.

If money already went out: the first hours are everything
Speed decides whether you see the money again. The window is brutally short.
Call your bank first. Ask them to recall the funds, and ask what indemnification paperwork they need, because the FBI notes banks usually require it. Be clear on what a recall is. A wire is not “reversed” on demand. Your bank asks the receiving bank to freeze and return it, and that bank can say no.
Report to the FBI at ic3.gov the moment you suspect it, not later that day. File no matter how small the amount. The FBI’s Recovery Asset Team can start what they call the financial fraud kill chain and ask the receiving bank to freeze the account. It works. In 2024 that team froze about $469 million on domestic cases and $93 million on international ones, with a 66 percent success rate.
Two honest notes on that number. Frozen is not the same as returned, since release is a separate process. And the rate covers cases reported fast enough to act on. The practical window is about 72 hours, and domestic money often moves in hours. So 72 is the far edge, not a cushion.
Save the evidence before you clean anything up. Do not delete the fraudulent email. Save it with full headers. Have your IT provider pull the Microsoft 365 sign in and audit logs right away, because how far back those logs go depends on your license. Your insurer and the FBI will want them.
Lock the mailbox down properly, not just the password. Changing the password is not enough, and this is where firms get hit twice. Microsoft’s own guidance is clear. Sign in sessions have to be revoked, or the criminal stays logged in with a stolen token. Hidden inbox rules have to be found and deleted, because attackers use rules that auto forward or auto delete the vendor’s replies so you never see the truth. App passwords have to be reset, since they survive a password change.
Warn the vendor, and tell them why. Do not just say the money did not arrive. Tell them their mailbox may be the compromised one. If it is, every other firm on that project is being worked right now.
Then loop in your attorney and your carrier the same day.
Expect to still owe the money
This is the piece almost nobody writes about, and it turns a bad week into a bad year.
Paying a criminal usually does not pay your sub. They did the work and never got paid. They can still demand the draw, and on a live project they can file a lien. So the loss is often double. You lose the wire, and you still owe the payment.
Who eats the loss depends on your contract, your state’s law, and who was careless. That is a real legal fight, not a simple answer, and it is why you call your attorney on day one instead of week three.
What if your email is the one that got hacked
Flip the scam around, because this is the bigger exposure for a lot of Architecture, Engineering, and Construction firms. If a criminal gets into your mailbox and sends fake wiring instructions to your client, the money leaves their account, not yours. Now you have a client who lost six figures on your letterhead, a relationship to save, a possible duty to notify people, and possible liability.
Same controls, different stakes. Phishing resistant MFA on every mailbox. Alerts on new inbox forwarding rules. And an IT provider who is watching, not waiting for you to call.
Frequently asked questions
We will help you shut the door on wire fraud
One fake email should never cost your firm a year of profit. The fixes are mostly habits and a few settings. A written callback rule with trusted numbers. Two person approval on bank changes. Phishing resistant MFA. A locked down email domain. An insurance policy you have actually read.
That is what we set up for construction and AEC firms around Knoxville. If your firm sends or receives large payments and has no verification rule, give us a call. So your money goes where it is supposed to, and your team can focus on building, not on second guessing every invoice.
Key takeaways
- Wire fraud in construction is a criminal imitating a payment email and sending fake wiring instructions. It rides on a real project at the right time, and it can cost a firm six figures.
- The best defense is a callback rule using a trusted number from the signed subcontract, W9, or COI, never from the email. Back it up with two person approval, a 24 hour hold, and phishing resistant MFA, since regular MFA can be bypassed.
- If money went out, call the bank, report at ic3.gov immediately, save the evidence, and have the mailbox fully locked down, not just the password changed. Then plan for two hard facts. You will probably still owe the vendor, and your insurance may not cover it.
Could one fake email divert a six figure payment at your firm?
We set up the callback rule, phishing resistant MFA, and email protections that stop wire fraud before a criminal tests them. No obligation, no sales pitch.
Sources: Business Email Compromise (FBI); Business Email Compromise: The $55 Billion Scam (FBI IC3, 2024); 2024 IC3 Annual Report; Respond to a compromised email account in Microsoft 365 (Microsoft); Multi stage AiTM phishing and token compromise (Microsoft Security); Phishing Resistant MFA is Key to Peace of Mind (CISA); Domestic Financial Fraud Kill Chain Process (DOJ); Social Engineering Fraud and Your Crime Policy (Ward and Smith)




