Phishing in the Trades: Fake Bid Invites and Plan Room Links

Attackers disguise phishing as bid invitations, plan room links, and lien waivers. Learn the patterns estimators and project managers should recognize.

3 min readBy Ironfield Cyber Team

Phishing aimed at construction companies does not look like the clumsy messages from years ago. It looks like your day. A bid invitation from a general contractor you know. A link to a plan room to download drawings. A request to sign a lien waiver or review a change order. People in estimating, project management, and accounting click such messages dozens of times a week, and attackers have noticed.

Understanding the patterns is more useful than a generic "don't click suspicious links" warning, because the dangerous messages are built to look unsuspicious.

Why construction is a good target

  • Companies exchange documents with many outside parties, so unfamiliar senders are normal.
  • Deadlines are tight, so people act quickly.
  • Large payments move regularly, which makes payment diversion scams lucrative.
  • Staff work from phones in the field, where it is harder to inspect a link.
  • Email often serves as the primary record of the project.

Pattern one: the bid invitation

A message arrives inviting you to bid on a project, with a link to download plans and specifications. The link leads to a page that looks like a file sharing or plan hosting site and asks you to sign in with your Microsoft 365 or Google account. The page is fake and captures your password.

What to check:

  • Did you expect an invitation from this sender or project?
  • Does the link domain match the service it claims to be?
  • When in doubt, go to the service directly rather than clicking the link, or call the sender at a number you already have.

Pattern two: the shared document

A message says a colleague or vendor shared a document, perhaps an estimate or a contract. The sender may be a real contact whose mailbox has been compromised, which makes the message especially convincing.

What to check: the context. A message with no explanation, an odd subject, or a request that does not match your relationship with the sender deserves a quick call or text.

Pattern three: the lien waiver or pay application

Messages about lien waivers, pay applications, or change orders carry weight because ignoring them has consequences. Attackers use that. The attachment may carry malware, or the link may lead to a credential-stealing page.

Pattern four: the conversation hijack

If an attacker controls a mailbox, they can reply inside an existing thread about a real project. The reply might include new bank details or a link. Because the thread is genuine, defenses drop.

Pattern five: the executive request

A message that appears to come from the owner asks the controller or an assistant for a quick favor, such as buying gift cards or changing a payment. It often arrives while the person is known to be traveling.

Habits that help

  1. Slow down for anything involving money or passwords. Verify by phone using a number you already trust.
  2. Look at the sender's actual address, not only the display name. On a phone, tap the name to reveal it.
  3. Hover or press and hold links to see where they lead before opening.
  4. Never enter your work password on a page you reached through an email link.
  5. Report suspicious messages using a simple, consistent method, such as a report button or a shared mailbox, and thank people who do so.
  6. Do not punish clicks. Employees who fear blame hide mistakes. A fast report limits damage.

Technical protections that back people up

People will occasionally click. Layered technology reduces the damage:

  • Multi-factor authentication on email and business apps, so a stolen password is not enough.
  • Email security that flags lookalike domains, scans links and attachments, and warns on external senders.
  • Endpoint protection that is monitored by people who respond to alerts.
  • Conditional access policies that block sign-ins from unusual places or unmanaged devices.
  • Alerts for new mailbox forwarding rules and unusual sign-ins.

Training that works for field and office staff

Annual videos are rarely enough. Short, frequent, job-specific examples work better: show estimators a fake bid invitation, show accounting a fake banking change, show superintendents a fake photo-sharing link. Add occasional simulated phishing messages, and use them to teach rather than to catch people out.

What to do after a click

If someone enters a password or opens a suspicious file, they should tell IT immediately. IT can reset the password, end active sessions, check mailbox rules, and look for related activity. Every hour counts.

How Ironfield Cyber helps

Ironfield Cyber builds email protection, multi-factor authentication, and training designed around how contractors work. If you want to test how your team handles a realistic bid-invite phishing message, we can set that up and walk through the results together.