Pay App and Lien Waiver Fraud: Questions Contractors Ask

Q&A on how criminals exploit pay applications, lien waivers and retainage in construction, and the controls that make those schemes harder to pull off.

3 min readBy Ironfield Cyber Team

Construction payment workflows are layered and document-heavy: applications for payment, schedules of values, lien waivers, certified payroll, retainage releases and change orders. That structure helps manage risk between owners, general contractors and subcontractors. It also gives fraudsters plenty of material to imitate and many handoffs to exploit.

Below are questions contractors commonly ask about this problem, with practical answers.

How do criminals target pay applications?

A typical scheme starts with access to someone's email, often through a stolen password. The criminal watches conversations about upcoming draws, learns who approves what and when payments are expected. They then step in with a convincing message, such as a revised payment instruction that appears to come from a subcontractor or from the project accountant.

The FBI's Internet Crime Complaint Center has described this broad pattern as business email compromise, and construction is among the industries where it causes major losses.

Why do these schemes work so well in construction?

  • Payment amounts are large, so one successful fraud is very profitable.
  • Many parties are involved, and nobody knows every email address and phone number.
  • Deadlines are tight, and delays are costly.
  • Documents move by email and attachments look routine.
  • Subcontractors may be small firms with limited security, so a compromise of their mailbox is plausible.

What is a fake lien waiver problem?

Lien waivers confirm that a party has received payment and waives lien rights up to a point. Forged or altered waivers may appear in several ways. A criminal might send a waiver that appears legitimate but contains altered payee details, or someone might fabricate paperwork to obtain payment. Separately, a subcontractor that was never paid because funds were redirected may later assert lien rights, leaving the prime to pay twice.

What is the most important control?

Verify any change to payment instructions by phone, using a number you already have on file, before releasing funds. It sounds simple, and it stops a large share of attempts. Put it in writing as a rule that cannot be waived by seniority or urgency.

What other controls should be in place?

  1. Dual approval for payments above a threshold you set.
  2. Vendor master file protection. Restrict who can edit banking details, and report every change to a reviewer.
  3. Standardized forms for waivers and payment instructions, so unusual formats stand out.
  4. A single channel for pay applications, such as a project platform, rather than email attachments from arbitrary senders.
  5. Cooling-off period for the first payment after any bank change.
  6. Bank features such as dual authorization for wires and account name matching where offered.

What about our subcontractors?

Share your payment verification rules with subs and suppliers at the start of the job. Tell them that you will never change payment instructions by email alone and ask them to call you if they receive a message that claims otherwise. Encourage them to enable multifactor authentication on their email. Include a statement in your subcontract package that bank changes require callback verification.

What warning signs should staff watch for?

  • A request to change payment details just before a scheduled draw
  • A new email address or a slightly different spelling of a familiar domain
  • Pressure to bypass the usual process
  • A request to send payment to a personal account or an account in a different name
  • Attachments that ask you to sign in to view them
  • Changes in tone or phrasing from a familiar contact

What if we think we paid the wrong account?

Act immediately. Call your bank and ask for a wire recall or a fraud dispute, report the incident to the FBI's IC3 and notify your insurance carrier and counsel. Early reporting increases the chance that funds can be frozen. Then secure any compromised mailboxes, reset credentials and review rules that forward or hide messages.

How can we practice?

Run a short tabletop exercise with accounting and project management. Present a fictional email changing bank details on a large draw and walk through how your team would respond. Look for places where the process depends on one person or assumes the email is genuine.

Does cyber insurance cover this?

Coverage varies widely. Some policies include social engineering or funds transfer fraud only with sublimits or conditions, such as a requirement for callback verification. Read your policy with your broker so you know what is covered and what you must do to keep that coverage.

How Ironfield Cyber helps

Ironfield Cyber helps contractors protect the email accounts and approval workflows that these schemes depend on, including multifactor authentication, mailbox monitoring and payment verification procedures. If you want your pay application process reviewed for weak points, we can walk through it with you.