Pay applications and lien waivers are routine paperwork in construction, and routine is exactly what a fraudster wants. Project accounting teams process large numbers of similar documents on a tight schedule, and the payment amounts can be substantial. A convincing fake that fits the pattern can move money before anyone realizes something is wrong.
This post describes common variations of the scam and the controls that make them much harder to pull off. The scenarios are illustrative, not reports of specific cases.
Why this part of construction is attractive to fraudsters
- Payments are large and recurring.
- Many parties are involved: owners, general contractors, subcontractors, suppliers, lenders.
- Documents move by email, often among people who have never met.
- Deadlines are tied to funding and lien rights, so there is pressure to act quickly.
- Public records, such as permits and bid results, reveal who is working on what.
Variation one: the changed remittance
A subcontractor's pay application arrives with a note: "Please send payment to our new account." The email address is almost identical to the real one, or it is the subcontractor's real mailbox, compromised by an attacker.
Red flags: a banking change delivered with a pay application, urgency, a request to confirm by email only, or an account in a different name or location.
Variation two: the fabricated pay application
An attacker who has studied a real project, perhaps through a compromised mailbox, submits a pay application on behalf of a real subcontractor for a plausible amount, with a believable schedule of values and a payment address of their choosing.
Red flags: amounts that do not match progress or the contract schedule, a new contact person, or a submission outside the usual channel.
Variation three: the altered lien waiver
A lien waiver is returned with altered terms, a different payee, or a changed amount. A hurried reviewer signs off on the visible parts and misses the rest.
Red flags: a form that differs from the standard template, a mismatch between the waiver and the payment, or signature and notary details that look off.
Variation four: the impersonated owner or lender
Someone claiming to represent the owner or lender sends instructions to redirect a draw or to confirm payment to a third party.
Red flags: new payment instructions that arrive outside the loan documents, and requests to keep the matter confidential.
Controls that work
Verify payee changes independently
Any change to remittance details requires a call to a known contact at the payee, using a phone number already on file. Document who confirmed it, when, and what was said.
Match every payment to the contract
Before releasing a payment, confirm that the payee matches the subcontract, the amount fits the schedule of values and progress, and the lien waiver matches the payment.
Use standard templates and channels
Require use of a standard pay application form and a defined submission method, such as the project management platform, instead of loose email attachments. Deviations trigger review.
Separate duties
The person who receives and codes the pay app is not the person who changes vendor details, and neither releases payments alone. Large payments get a second approver.
Protect the mailboxes
Require multi-factor authentication, enable alerts for forwarding rules and unusual sign-ins, and use email security that flags lookalike domains and impersonation.
Watch for conversation hijacking
If a message arrives inside an existing email thread but contains new payment instructions, treat it with the same scrutiny as a brand-new request. Attackers who control a mailbox can reply inside legitimate conversations.
Educate subcontractors
Tell your subs and suppliers how you verify banking changes, so legitimate requests are expected to take an extra step. Many appreciate it, since they are also targets.
Build verification into the schedule
Verification takes time. Adjust internal deadlines so accounting can complete checks before payment is due, rather than skipping steps when the clock runs short. Make it clear that a delayed payment due to verification will be supported by management.
If you suspect fraud
- Contact your bank immediately and ask for a recall or hold.
- Notify your controller, owner, and IT.
- Preserve emails, forms, and logs.
- Contact the legitimate payee by a known number.
- Report to the FBI's IC3 and to your insurer.
- Review with counsel any impacts on lien rights or contractual obligations.
Make it routine
A short pay-application checklist, taped near the desk and built into your workflow, does more than a long policy that nobody opens. Train the project accounting team on the variations above, and refresh the training once a year.
Where Ironfield Cyber fits
Ironfield Cyber helps construction companies pair email security and monitoring with practical payment verification workflows. If you would like a review of how pay applications and vendor changes flow through your office, we can map it with your team and point out the weak spots.