Why wire fraud is a process failure, not just an email problem
Wire fraud and invoice redirection scams rarely start with a hacked bank account. They start with a convincing message: a 'vendor' asking to update banking details, or a 'CEO' asking finance to rush a payment before a trip. The email or text is often the easy part for the attacker. The real vulnerability is a payment process that lets one message change where money goes without an independent check.
- Most cases involve either a compromised mailbox watching real invoice threads, or a lookalike domain one letter off from the real vendor
- Attackers study real patterns first: who approves payments, which vendors are recurring, and when a rush request would look normal
- Banks can sometimes recover funds if reported within hours, which is why speed of detection matters as much as prevention
How the scam usually unfolds
The pattern repeats across small businesses because it works. Recognizing the shape of it is often enough to stop the loss.
- A finance contact receives an email that looks like it is from a known vendor or executive
- The message references a real invoice, project, or deal, sometimes because the attacker had mailbox access earlier
- It asks to update banking details, expedite payment, or purchase gift cards or e-transfers 'quietly'
- It creates urgency: a closing deadline, a travelling executive who cannot be reached by phone, an angry vendor threatening to pause work
- Payment goes out, and the redirected account is drained within hours
The verification habit that stops almost all of these
One habit blocks the overwhelming majority of wire fraud attempts: verify any change to payment details or any unusual payment request through a second channel you already trust, not through contact information in the request itself.
- Call the vendor or executive using a phone number already on file, never one provided in the suspicious message
- Treat 'banking details changed' as a red flag requiring verbal confirmation every time, with no exceptions for regular vendors
- Require a second person to approve any new or changed payment destination above a set dollar threshold
- Slow down urgency deliberately: a real vendor will accept a same-day callback before a wire is confirmed
- Watch for subtle domain differences (an extra letter, a swapped domain extension) in the sender address
What to do if a payment already went out
Minutes matter. Banks and fraud units can sometimes intercept a wire or e-transfer if notified fast enough, but the window closes quickly.
- Call your bank's fraud line immediately and request a wire recall or hold
- Report the incident to the RCMP's national cybercrime and fraud reporting system
- Preserve the original email or text, including full headers, without forwarding it in a way that alters the source
- Check whether the same mailbox thread has other pending invoices that may also be compromised
- Notify the real vendor directly through a verified channel so they can warn other clients
Building lasting resilience, not just a one-time fix
A single awareness email rarely holds up under real pressure. Durable protection combines process controls with periodic testing so the habit survives staff turnover and a busy quarter.
- Document a written payment-change verification policy that new hires are trained on
- Run periodic tabletop exercises simulating a rush payment request
- Separate who can request a payment from who can approve a new banking destination
- Review email forwarding rules and mailbox permissions to rule out silent compromise
Frequently asked questions
Is wire fraud covered by cyber insurance?
Sometimes, but often under a separate 'social engineering' or 'funds transfer fraud' endorsement rather than standard cyber coverage, and frequently with lower sub-limits. Confirm this specifically with your broker rather than assuming general cyber coverage applies.
Can the bank just reverse the wire?
Sometimes, if reported within hours and the receiving bank still holds the funds. Once the money is moved again or withdrawn, recovery odds drop sharply. Speed of reporting is the single biggest factor in recovery.
How do attackers know so much about our real invoices and vendors?
Usually because a mailbox somewhere in the chain, yours or the vendor's, was quietly compromised earlier and monitored for weeks before the fraudulent request was sent. This is why mailbox hygiene and vendor security matter even when the fraud email arrives from what looks like a legitimate thread.
Are gift-card or e-transfer requests always a scam?
For a real vendor invoice, yes, essentially always. Legitimate B2B payments do not run through gift cards, and legitimate urgent e-transfer requests from an 'executive' who cannot be reached by phone are one of the most common fraud patterns seen in Canadian small businesses.