Five Payment Fraud Myths That Cost Contractors Money

Many contractors trust assumptions that fraudsters rely on. Here are five common myths about payment diversion and wire fraud, and what to do instead.

3 min readBy Ironfield Cyber Team

Payment diversion fraud thrives on assumptions. Teams believe they would spot a fake, that fraud only hits big companies, or that their bank would catch it. The FBI's Internet Crime Complaint Center has long identified business email compromise as a costly category of crime, and it continues to affect organizations of all sizes. Contractors and energy firms are attractive targets because they handle large, irregular payments to many vendors.

Let us take five common myths and replace each with something more useful.

Myth 1: "We are too small to be targeted"

Reality: Fraudsters often favor smaller companies because controls are lighter and one person may handle payables, vendor setup, and approvals. Attackers do not need to single out your company. Automated tools gather vendor lists and bid information, and criminals work through them. A subcontractor's compromised email can lead to fake invoices that go to many customers at once.

What to do: Treat every payment-instruction change as a possible fraud attempt regardless of company size.

Myth 2: "We would recognize a fake email"

Reality: Modern fraud emails are often well written, reference real projects, and arrive inside genuine email threads from compromised accounts. The sender address might be exactly right because the vendor's mailbox was taken over. Spotting typos is no longer a dependable defense.

What to do: Rely on process, not instinct. Verify banking changes by calling a known number from your records, never one in the email.

Myth 3: "If the email comes from a vendor we know, it is safe"

Reality: A known vendor can be compromised without realizing it. Attackers watch conversations, then insert a banking change at the moment an invoice is due. Lookalike domains, with a single character changed, also look correct at a glance.

What to do: Verify the request, not the sender. Be especially skeptical of changes timed around large pay applications, final payments, or retainage releases.

Myth 4: "Our bank will catch it"

Reality: Banks have fraud tools, but a payment you authorize is generally treated as an authorized transaction, even if the instructions were fraudulent. Banks may help attempt a recall, but recovery is not guaranteed and speed matters. They cannot know that the account number you were given belongs to a criminal.

What to do: Use bank features that reduce risk, such as dual approval, payee verification, and positive-pay for checks, but do not treat them as a substitute for verifying vendor instructions.

Myth 5: "Fraud is an IT problem"

Reality: Most diversion schemes succeed through business process gaps, not technical hacking. They exploit how vendor details are changed, who approves payments, and how urgent requests are handled. IT can secure mailboxes and filter email, but finance and operations own the process.

What to do: Put accounting, project management, and IT in the same conversation. Share responsibility for the controls and for reviewing them.

A short list of controls that work

  1. Callback verification for every new vendor and every banking change, using phone numbers already on file.
  2. Separation of duties: the person who edits vendor records cannot release payment.
  3. Waiting period before the first payment to changed instructions.
  4. Dual approval for payments above a threshold you define.
  5. Vendor change log reviewed regularly by someone other than the person who made the changes.
  6. Multi-factor authentication on email and banking portals.
  7. Clear escalation: a staff member who pauses a payment for verification is supported, not blamed.

Build verification into the culture

Fraud works because of pressure. The email says the vendor needs paying today, the owner is traveling, and the crew is waiting. Make it normal to say, "I will confirm this and get back to you." A legitimate vendor will understand a short delay for a verification call.

Revisit the myths annually

Controls decay. People forget, staff turns over, and old habits creep back. Once a year, test the process: have someone submit a fake change request, and see whether it is caught. Use the result for coaching, not punishment.

How Ironfield Cyber helps

Ironfield Cyber works with finance and operations teams to build verification processes, secure the email accounts behind them, and train staff on current tactics. If you want a simple review of your payment controls, we can help you see where the gaps are.