Preventing Vendor Payment and Wire Fraud in Construction
A five- or six-figure wire transfer lands in the wrong account because a vendor 'updated their banking details' by email, and by the time anyone notices, the money is gone. This is now one of the most expensive cybercrime patterns hitting construction firms, and it succeeds because it targets a business process rather than a technical vulnerability.
Construction wire fraud is prevented by combining technical controls (mailbox MFA, email impersonation protection, and DMARC alignment) with a written, mandatory rule that no change to a vendor's banking details is ever accepted based on email alone, always confirmed through a separate, previously known phone number.
How the attack actually works
The attack rarely starts with the intended victim. Often, an email account somewhere in the vendor or contractor's supply chain gets compromised first, frequently because it had no multi-factor authentication. Once inside, the attacker doesn't act immediately. They quietly read invoice threads, payment schedules, and correspondence style for days or weeks, learning exactly how that vendor communicates.
When a real invoice or payment is due, the attacker sends an email, sometimes from the compromised account itself, sometimes from a look-alike domain that's one letter off, saying the vendor has 'updated their banking information' and providing new account details. Because the email arrives in an existing thread, referencing real project details, it looks completely legitimate. The payment goes out, and by the time the real vendor calls asking where their money is, the funds are gone.
Why this specifically hits construction hard
Construction involves large, irregular payments to subcontractors and suppliers, multiple parties communicating primarily by email, and a payables process that's often handled by one or two people under time pressure to keep a project moving. That combination of high-value transactions and lean administrative process is exactly what this fraud pattern exploits.
Technical controls that reduce the risk
These controls matter and stop a meaningful share of attempts, but none of them can fully guarantee that a compromised vendor mailbox somewhere in your supply chain won't send a convincing message. That's why the technical layer alone is not sufficient.
- Phishing-resistant multi-factor authentication on every mailbox, internal and reviewed for any external partners you can influence
- Anti-impersonation and inbox-rule monitoring that flags suspicious forwarding rules or look-alike sender domains
- DKIM and DMARC alignment on your own domain so attackers can't easily spoof your company in emails to others
- Mail-flow rules that visibly tag messages from newly registered or look-alike vendor domains
Has your firm reviewed its payment verification process?
We'll help you put the technical controls and the written procedure in place before an attacker tests them for you.
Talk to Our TeamThe written verification procedure that actually stops it
The single control that reliably stops this fraud, even when every technical layer fails, is a simple written rule applied without exception: any change to a vendor's banking or payment details, no matter how legitimate the request looks, is verified by phone before the payment goes out, using a phone number already on file, never a number provided in the email requesting the change.
- Flag any email requesting a change to banking or payment details, from any vendor, regardless of urgency language
- Do not click reply or use any contact information contained in that email
- Call the vendor using a phone number already on file from before the request, such as a signed contract or an earlier invoice
- Verbally confirm the change directly with a known contact at the vendor
- Only then update payment records and process any pending payment
- Document the verification (date, who called, who confirmed) for the file
Making the procedure stick
A written procedure that sits in a binder nobody reads doesn't stop anything. It needs to be trained into whoever handles payables, reinforced when a new hire takes over that role, and treated as non-negotiable even when a request appears urgent, because urgency is itself one of the attacker's primary tools.
This procedure also produces documentation that satisfies cyber-insurance questionnaires and ISN or Avetta prequalification packages, which increasingly ask construction firms to demonstrate exactly this kind of control.
Related risks worth addressing at the same time
Firms tightening up payment verification should also review job-site connectivity, since site supervisors handling change orders and approvals over unreliable connections are more likely to work around proper channels under pressure; see our guide to job-site internet options in Northern Ontario. Document control practices that keep drawings and RFIs authoritative and versioned reduce a related category of costly mistakes on the project side.
Sources and further reading
Frequently asked questions
What's the very first sign of a vendor payment fraud attempt?
A request to change banking details, especially one that references a real invoice or project and carries urgency ('please process before end of day'), is the classic pattern. Legitimate vendors rarely require same-day account changes.
Is MFA alone enough to stop this?
No. MFA reduces the chance your own mailboxes get compromised, but the fraud can originate from a compromised vendor account outside your control. The out-of-band phone verification procedure is the control that stops it regardless of where the compromise happened.
Can insurance help if we do get hit by this kind of fraud?
Some cyber-insurance and crime policies cover social-engineering fraud, but coverage varies widely and often requires that certain controls, like documented verification procedures, were already in place. Review your specific policy language with your broker.
Joshua Arimoro
Joshua Arimoro is the Principal Consultant at Nickel City Tech Solutions, a managed IT and cybersecurity provider based in Lively, Ontario, serving businesses across Greater Sudbury and Northern Ontario. He works hands-on with Microsoft 365, server and network infrastructure, endpoint management, and backup and recovery for small and mid-sized organisations.
More about our teamPut real controls around vendor payments
Nickel City Tech Solutions helps construction firms across Northern Ontario build the technical and procedural defences that stop wire fraud.
Related services, locations, and resources
Related services
- Managed IT Services
Proactive monitoring, patching, and predictable monthly support.
- Cybersecurity Services
Endpoint protection, MFA, email filtering, and M365 hardening.
- Microsoft 365 Support
Exchange, Teams, SharePoint, OneDrive, and licensing.
- Backup & Disaster Recovery
Backup strategy, monitoring, and recovery testing.
Related service areas
Related resources
- IT Support for Mining Supply and Service Contractors in Sudbury
Mining supply and service contractors in Sudbury deal with remote sites, prequalification questionnaires, a…
- How to Specify a CAD or BIM Workstation the Right Way
A poorly specified CAD or BIM workstation costs an engineering or design firm real productivity every day. …
- Project Data Retention for Engineering Firms
Completed projects don't stop mattering once they're delivered. Engineering firms need a deliberate retenti…
- Job-Site Internet Options in Northern Ontario
A job site with unreliable internet costs a construction crew time every single day. Here's a comparison of…
