Someone in accounting realizes the payment went to the wrong place. A supplier calls asking about an invoice you thought was paid. A callback to confirm a bank change reaches a person who never made the request. In that moment, the minutes that follow have an outsized effect on whether any money can be recovered.
This playbook is meant to be printed, kept near the accounting desk and rehearsed. It reflects widely published guidance, including FBI Internet Crime Complaint Center recommendations to contact the financial institution immediately and file a complaint. Specific recall success depends on timing and circumstances, and nothing here is a guarantee.
Minute 0 to 10: Confirm and stop
- Stop further payments to the same vendor or account until the situation is understood.
- Gather the facts: payment date and time, amount, method (wire, ACH, check), originating account, recipient bank name, account number and the instructions you received.
- Notify your incident lead. Assign one person to coordinate, so that information does not scatter across email threads.
- Do not alert the suspected criminal. Avoid replying to the fraudulent message.
Minute 10 to 20: Call your bank
Phone the relationship manager or the bank's fraud or wire department, not just a general customer line. Tell them you believe you have been the victim of a fraudulent transfer and ask them to:
- Initiate a recall or reversal request
- Contact the receiving bank to request a freeze on the funds
- Provide a reference number and confirm what documentation they need
Ask which department to work with for follow-up, and keep a log of names, times and what was said. For ACH payments, ask about the options for returning or stopping the transaction. Timing is critical, since funds are often moved quickly out of the receiving account.
Minute 20 to 30: Report to law enforcement
File a complaint with the FBI's Internet Crime Complaint Center at ic3.gov, and include the transaction details, account information, communications and any email headers you have. Reporting quickly allows federal partners to attempt to work with the recipient bank where circumstances permit. Also consider reporting to local law enforcement for your records.
Minute 30 to 45: Preserve evidence and secure accounts
Fraud of this kind frequently starts with a compromised mailbox, whether yours or the vendor's.
- Do not delete messages. Preserve them, including original headers.
- Reset passwords on affected accounts and any account that may share credentials
- Revoke active sessions and review multifactor settings
- Check mailboxes for suspicious forwarding rules, hidden rules and unfamiliar connected apps
- Review recent sign-in activity for unusual locations
- Alert your IT provider so they can look for further compromise
Minute 45 to 60: Notify the right people
- Insurance carrier and broker. Many policies require prompt notice, and coverage for funds transfer fraud may have conditions, so call early and read the notice instructions.
- Legal counsel. Particularly if contracts, regulated data or customer funds are involved.
- The real vendor, using a verified phone number, so they know of the attempt and can check their own systems. The vendor may be compromised without realizing it.
- Leadership and your controller. Provide a brief written summary.
After the first hour
Run a short investigation
Determine how the attacker learned the payment details. Was it a mailbox compromise, a spoofed domain, a fake vendor change or an insider? The answer decides which controls to improve.
Check for repeats
Criminals often retry. Review recent payments and vendor changes for other suspicious activity, and confirm bank details for your main vendors through verified calls.
Communicate carefully
Tell affected employees what happened, factually and without blame. If customers, subcontractors or partners could be affected, consult counsel about notice.
Improve the process
Use the incident to strengthen callback verification, dual approval and email security. Document what worked and what slowed you down.
Prepare in advance
A playbook only helps if it is available when stress is high. Do these now:
- Store the bank fraud contact, insurer hotline and IC3 link on a card, not just in email
- Make sure at least two people know the process
- Practice with a fictional scenario once a year
- Confirm your wire cutoff times and what your bank can do after hours
How Ironfield Cyber helps
Ironfield Cyber helps contractors and energy companies prepare for payment fraud with email protections, mailbox monitoring and written response procedures, and supports the investigation if an incident occurs. If you would like help building this playbook for your team, we can start with a short working session.