Construction billing runs on documents: pay applications, schedules of values, lien waivers, certified payroll, insurance certificates and change orders. Everyone in the chain expects these documents to move by email on a regular rhythm, often under deadline pressure. That predictability is useful to the business and equally useful to a fraudster who has learned the pattern.
Payment diversion in construction rarely looks like a random scam message. It often looks like routine billing correspondence, with one detail changed. Understanding where the process is vulnerable helps you place controls where they count.
Why billing paperwork is attractive to attackers
- Regular timing. Pay applications arrive monthly. An attacker who has read access to a mailbox can see the rhythm and strike just before payment.
- Large amounts. Progress payments on commercial projects can be significant, so a single diversion has a high payoff.
- Many parties. Owners, general contractors, subcontractors, suppliers and lenders all touch the process, and each is a possible weak link.
- Documents trusted by habit. People tend not to question a form they have seen dozens of times.
- Email dependence. Many billing steps still rely on attachments and email threads.
Where the openings are
A compromised mailbox in the chain
If a subcontractor's or supplier's email account is taken over, the attacker can send realistic messages from the real address, replying within existing threads. They may add forwarding rules to hide replies from the real owner. From your side, nothing looks unusual, because it is not a fake address.
Altered remittance instructions on a pay application or invoice
A familiar document arrives with new bank details, or a "corrected" invoice replaces the original. The change is small and easy to miss.
Fake waiver or W-9 requests
Requests for lien waivers, tax forms or banking confirmations may be used to collect information for later fraud, or to appear as a legitimate reason for a banking change.
Look-alike domains
A message from an address that differs by a single character appears to be from the owner, lender or subcontractor, often inserted into a legitimate conversation.
Impersonating a project executive
A message styled as an urgent request from a principal or project executive asks accounting to expedite a payment or make an exception to normal procedures.
Controls that fit the billing workflow
- Lock the vendor master. Bank details are changed only after verification by calling a known number, with a second person's approval, and documentation of the call.
- Compare to the prior payment record. Before releasing funds, confirm that remittance information matches what was previously verified. Flag any differences for review.
- Verify changes outside the thread. If an email in an existing thread mentions new payment details, treat the thread itself as unreliable and verify through a separate channel.
- Use portals where possible. Payment and document portals with authenticated users reduce reliance on attachments sent by email, although portal accounts need their own protection.
- Standardize billing forms and communication. If everyone knows what a legitimate request looks like, deviations stand out. Tell subs and suppliers that you will never change payment instructions by email.
- Protect email accounts. Use multi-factor authentication, review mailbox rules for hidden forwarding, and monitor for unusual sign-ins. This protects your side and makes you a safer partner.
- Dual control on releases. Require separate people to prepare and approve payments, with extra scrutiny for new payees and large amounts.
Communicate with your partners
Share your verification policy with subcontractors and suppliers in writing. Explain that you will call to verify any bank change and that they should do the same for you. Include a statement in contracts or vendor onboarding packets.
If a payment may have been diverted
Contact your bank right away to attempt a recall, notify your IT or security provider, preserve the messages, and file a report with the FBI's IC3. Notify the legitimate vendor through a known phone number and review how the request was approved.
Improve gradually
You do not need a perfect process on day one. Start with vendor bank changes, add mailbox protection, then refine approvals and partner communication.
Ironfield Cyber helps contractors and energy companies protect billing workflows, from email security to written procedures and staff training. If you would like a review of your pay application process, we can walk it through with your accounting team.