Fraudsters targeting contractors and energy companies do not need to break into a network if they can persuade an accounts payable clerk to change a bank account. The clerk is often junior, busy and trying to be helpful. Giving that person clear red flags, and permission to slow down, is one of the cheapest and most effective defenses a company has.
The FBI's Internet Crime Complaint Center has long identified business email compromise as a costly category of fraud, and the pattern is consistent: a convincing request, a sense of urgency and a payment sent somewhere it should not go.
Red flags in the request
Teach these in plain terms.
- A change of bank details. Any request to alter where a vendor, subcontractor or employee gets paid deserves independent verification.
- Urgency and pressure. Messages that say the payment is late, the project will stop or an executive needs it today.
- Secrecy. Instructions not to discuss the request or to avoid calling.
- A new contact. A different person at a familiar vendor suddenly handling banking matters.
- Unusual account types or locations. A change from a business account at a known bank to a personal account, a different bank or a different state or country with no explanation.
- Out-of-pattern amounts or timing. A payment well outside the normal rhythm for that vendor.
- A request to skip the normal process. "Just wire it, we will paperwork later."
Any one of these deserves a pause. Several together should trigger escalation.
Red flags in the message itself
- A sender address that looks right but has a small difference, such as an extra letter or a different domain ending.
- A reply-to address that differs from the sender.
- Writing style that is off for the person, including odd phrasing or generic greetings.
- Attachments, such as a new payment form, that arrive without prior discussion.
- An email thread that appears to continue a conversation but contains no real history.
- Signatures with a phone number you do not recognize.
Attackers who have compromised a real mailbox can send from the genuine address, so a message that looks right is not proof. The process must not rely on how the email looks.
The habit that beats all of it: call back
For any change to payment instructions, the clerk should confirm by phone using a number already on file, not a number in the email. Speak to a known contact, confirm the details and record who was called, when and what was agreed. If no known contact is available, escalate rather than guessing.
Add a second approver for any bank change and for payments above a threshold set by management. Make the threshold known to staff and apply it consistently.
Give clerks permission to say no
Many clerks hesitate because they fear annoying a vendor or a boss. Leadership should say, and put in writing:
- Verification delays are expected and supported.
- No executive will be upset about a call-back.
- Anyone who pauses a suspicious request will be thanked, not blamed.
- Anyone who realizes they made a mistake should report it immediately, because speed is what recovers money.
If a real executive does ask for an urgent payment, they will answer a verification call quickly.
Know what to do when something slips
Time is critical. Post a one-page response sheet at each finance desk.
- Tell your manager and the person responsible for finance immediately.
- Contact the bank right away to request a recall of the payment.
- Report to the FBI's Internet Crime Complaint Center and to local law enforcement, as your bank or counsel advises.
- Preserve the emails and do not delete anything.
- Notify your IT provider so mailboxes and sign-ins can be reviewed.
- Alert your cyber and crime insurance contacts.
The first hours matter most, so the sheet should list phone numbers for the bank's fraud line in advance.
Support the process with tools
- Multi-factor authentication on email for everyone in finance.
- Alerts on new mailbox forwarding rules.
- Restrict who can edit vendor master records and log changes.
- Review vendor bank changes in a weekly report.
- Use bank services such as payee verification or positive pay where available.
Train with real examples
Use short, regular training with sanitized examples of fraudulent requests. A five-minute review at the monthly finance meeting is better than a long annual session. Practice the call-back with a mock request.
Closing thoughts
The best controls are procedures a busy person can follow in a minute. Ironfield Cyber helps contractors and energy companies write those procedures, protect email and train finance teams. If you would like a one-page red flag sheet tailored to your payment workflow, we can build it with you.