Wire Fraud Response: The First Hour After a Bad Payment

If a payment went to the wrong account, speed matters. Here is a first-hour response plan contractors and energy firms should write down before they need it.

3 min readBy Ironfield Cyber Team

Most contractors discover a diverted payment days later, when a legitimate vendor calls asking where their money is. But sometimes you catch it quickly: a bank callback fails, a supplier mentions they never changed accounts, or someone on your team has a bad feeling right after hitting send. In those moments, the first hour matters more than anything else you do.

This post lays out a practical response plan. Write it down, assign names to each step, and keep it where your accounting team can find it without asking IT.

Why the first hour matters

When a payment leaves your bank, it moves through the receiving bank and often onward to other accounts. Fraudsters move money quickly, frequently splitting it or sending it to additional accounts within hours. The sooner your bank contacts the receiving bank, the better the chance that funds can still be frozen or recalled. No one can promise recovery, but delay almost always makes it harder.

Step 1: Stop and preserve

The person who discovers the problem should tell the controller or owner immediately, then stop touching the evidence.

  • Do not delete the email that requested the banking change.
  • Do not reply to the sender or click anything in the message.
  • Save the original message with full headers, any attachments, the invoice, and the payment confirmation.
  • Write down what you remember: who requested the change, when, and who approved it.

Step 2: Call your bank, not email

Call your bank's fraud or treasury support line directly, using a number you already have on file. Explain that you sent a wire or ACH payment to an account you now believe is fraudulent. Ask them to:

  1. Initiate a recall or reversal request with the receiving bank.
  2. Flag the receiving account.
  3. Tell you what documentation they need and by when.

Have the amount, date, routing and account numbers, and the confirmation ready. Ask for a case or reference number and the name of the person you spoke with.

Step 3: File a report

The FBI's Internet Crime Complaint Center (IC3) accepts reports of business email compromise, and the FBI has published guidance encouraging victims to report quickly, especially for recent wire transfers. Also notify local law enforcement so you have a report number for your bank and insurer. Do not assume it is too small to report.

Step 4: Contain the email problem

A diverted payment usually means an email account was compromised, a vendor was compromised, or someone spoofed a lookalike domain. Your IT provider should work on these in parallel with the bank steps:

  • Check whether any of your own mailboxes were accessed by an unfamiliar sign-in.
  • Look for inbox rules that forward or hide messages.
  • Reset passwords and sessions for any affected account, and confirm multi-factor authentication is on.
  • Compare the sender's domain closely with the real vendor's domain.

If the vendor was compromised, tell them. They may be unaware, and other customers may be at risk.

Step 5: Notify the right people

Tell your insurance broker or carrier promptly. Many policies have notice requirements, and cyber or crime coverage may have conditions about verification procedures. Also notify your legal counsel if the amount is significant, and your owner or board as appropriate. If the legitimate vendor is still owed payment, contact them through a known phone number and explain what happened so the relationship is protected.

Step 6: Fix the process after the dust settles

Once the immediate response is done, review how the change request passed through your process. Typical gaps include:

  • A banking change accepted by email alone.
  • No callback to a phone number already on file.
  • One person able to change vendor details and release payment.
  • Pressure to pay quickly on a large progress draw.

Require callback verification for every banking change, separate the person who edits vendor records from the person who approves payments, and add a waiting period before the first payment to new instructions.

Practice it once

Run a fifteen-minute tabletop exercise with accounting and the owner. Ask: who calls the bank, and what number do they use? Who has authority to approve a recall request? Where is the insurance policy? You will find gaps in a calm room that you would otherwise find in a panic.

How Ironfield Cyber can help

Ironfield Cyber helps contractors and energy companies write payment-fraud response plans, tighten vendor verification, and investigate suspicious mailbox activity. If you would like a quick review of your payment process, we are glad to walk through it with your finance team.