Payment diversion is one of the most expensive scams a construction or energy company can face. The attacker does not break into a bank. They convince someone in accounts payable to send a legitimate payment to the wrong account. The FBI's Internet Crime Complaint Center has long identified business email compromise as a major source of losses, and contractors are attractive targets because they pay large invoices on tight schedules to many subs and suppliers.
Here is how an attempt typically unfolds, using a hypothetical mid-sized specialty contractor, and where a good process breaks the chain.
Stage one: quiet research
The attacker learns who your vendors are. Sources are plentiful: public bid results, press releases, project signage, LinkedIn, and sometimes a compromised mailbox at a vendor or at your own company. They learn who approves invoices and who releases payments.
Warning sign: none yet. This stage is invisible, which is why controls must not depend on spotting the attacker early.
Stage two: access or impersonation
There are two common paths:
- Mailbox compromise. The attacker phishes a password from an employee at your company or a vendor, signs in, and reads the email. They may create hidden forwarding rules so they see everything.
- Lookalike domains. The attacker registers a domain that differs from the vendor's by one letter or a swapped extension, and emails you as the vendor's accounting contact.
Warning signs: unexpected sign-in alerts, forwarding rules that nobody created, and email addresses that look right at a glance but are off by a character.
Stage three: the change request
The attacker waits for a real invoice, then sends a message such as "Our bank has changed, please use the attached form for future payments." It often includes a professional-looking letter on the vendor's letterhead and a voided check.
Warning signs:
- Urgency or pressure ("the next payment is due Friday").
- A request to change banking details by email only.
- A new account at a bank in a different city or state than the vendor.
- A request to keep the change confidential or to contact only one person.
Stage four: the payment
Accounts payable updates the vendor record and the next payment goes to the attacker. Wires and ACH are hard to reverse, especially after a few days.
Stage five: discovery
The real vendor calls asking about their unpaid invoice. By then, funds have usually been moved. If you act the same day, contact your bank immediately, ask them to initiate a recall, and file a report with the IC3. Speed matters more than anything else at this point.
Controls that break the chain
Verify by callback, every time
Any change to bank details must be confirmed by calling a phone number you already had on file, not one in the email. Record who you spoke to and when.
Separate duties
The person who changes vendor banking details should not be the person who approves or releases payments. A second person reviews every change.
Hold new details briefly
Where cash flow allows, delay the first payment to changed bank details by a few business days and send a small confirmation before the full amount.
Protect the mailboxes
Require multi-factor authentication on all email accounts, disable legacy sign-in methods, and alert on new forwarding rules. Email security that flags lookalike domains helps too.
Train the people who touch money
Accounts payable, controllers, and project managers who approve pay applications should know this exact story. A fifteen-minute walkthrough of a hypothetical like this one is more effective than a generic annual video.
What to do if you suspect a diversion
- Call your bank right away and request a recall or hold.
- Preserve the emails; do not delete anything.
- Reset passwords and review mailbox rules for the accounts involved.
- Report to the FBI's IC3 and notify your insurer.
- Warn the real vendor, since their mailbox may be compromised.
Next steps
Ironfield Cyber helps contractors and energy companies build these controls into their email, accounting workflows, and training. If you would like a short review of how your vendor banking changes are handled today, we are glad to walk through it with your finance team.