A subcontractor's accounts receivable contact emails your accounting department: the company has changed banks, please update the ACH details before the next pay application is processed. The message looks right. The signature matches. The logo is correct. The request is polite and a little urgent. In many cases, it is also fake.
The FBI's Internet Crime Complaint Center (IC3) has long identified business email compromise, including requests to change payment instructions, as one of the costliest categories of cybercrime reported. Construction and energy companies are attractive targets because they pay large invoices to many vendors, often on tight schedules, and rely heavily on email.
The good news is that this is one of the most controllable risks a company faces. A written verification procedure, followed every time, stops most attempts.
Why these requests work
Attackers succeed by exploiting process gaps, not technical gaps. Typical scenarios include:
- A vendor's real email account is compromised, so the request comes from a genuine address.
- A look-alike domain, differing by one letter, impersonates the vendor.
- An attacker watches an email thread about a pay application and inserts themselves at the right moment.
- A fake request arrives while the usual accounts payable person is out.
In every case, the weak point is the same: a payment instruction was changed based on an email alone.
The procedure
Write this down and make it company policy. No exceptions for large vendors, longtime friends, or urgent deadlines.
1. Treat every change as unverified
Any request to add or change bank account details, remittance addresses or payment methods goes into a verification queue. It is never processed directly from the email.
2. Call back using a known number
Look up the vendor's phone number from your own records: a prior contract, the vendor master file from before the request, or a previously verified contact. Do not use the number in the email or on the new form. Speak to a person you already know, if possible.
3. Ask specific questions
Confirm that the vendor requested the change, the effective date, and the last four digits of the new account. Ask a question only a real contact could answer, such as a recent project name or invoice number.
4. Require a second person to approve
The person who receives the request should not be the only person who completes it. A second employee reviews the documentation and the callback notes before the vendor record changes.
5. Document everything
Record who called, the number used, who they spoke with, the date and time, and who approved. These records are valuable if something goes wrong and when working with your bank.
6. Send a test payment or hold the first payment
For larger vendors, consider a small test payment confirmed by the vendor, or a short hold on the first payment to the new account while verification finishes.
7. Confirm the change after the fact
Send a confirmation to the previously known contact that the record was updated. If the request was fake, the real vendor will tell you quickly.
Controls that support the procedure
- Restrict who can edit vendor master data in Sage, Viewpoint or your accounting system, and log all changes.
- Enable multi-factor authentication on all email accounts, especially accounting and executive mailboxes.
- Use email filtering that flags look-alike domains and external senders.
- Review mailbox rules for hidden forwarding, a common sign of compromise.
- Ask your bank about positive pay, payee verification, and dual-approval features for wires and ACH.
Train the people who handle money
Accounts payable staff, project accountants and project managers who approve pay applications should understand that polite pressure is part of the attack. Give them explicit permission to slow down and say, "Our policy requires a callback." Make sure owners and executives support them when a vendor complains.
If you think a payment was diverted
Act within hours. Contact your bank immediately and ask them to initiate a recall, notify your IT or security provider, and file a report with IC3. Speed matters because recovery becomes less likely as funds move.
Next steps
Ironfield Cyber helps contractors and energy firms put these procedures into writing, tighten email security, and train accounting teams. If you would like a review of how your vendor changes are handled today, we can do that in a short conversation with your controller.