Wire Fraud in Construction: How One Email Costs Contractors Six Figures

Construction2

Somewhere in Massachusetts this month, a contractor’s office manager will get an email that looks exactly like it came from a familiar sub or vendor: “We’ve changed banks — please use the new account for the next draw.” The invoice matches an open project. The signature looks right. The payment goes out. By the time anyone talks to the real vendor, the money has been moved twice and is gone.

Why Construction Is the Perfect Target

Business email compromise hits construction harder than almost any industry, and the reasons are structural. Large payments move on predictable schedules tied to draws and milestones. Payment chains involve many parties — owners, GCs, subs, suppliers — who often haven’t met. Project details are semi-public through permits and bid announcements, giving attackers everything they need to write a convincing email. And most firms run lean back offices where one busy person handles payables.

How the Scam Actually Works

The attack rarely starts with the fake email. It starts weeks earlier, when someone’s email account is quietly compromised — often through a phishing page that captured a password. The attacker reads mail silently, learns the project names, the payment rhythms, the way people sign their messages. Then, right before a real payment is due, they strike: sometimes from the compromised account itself, sometimes from a lookalike domain one letter off. The request is never strange. That’s the point.

The Controls That Stop It

Three process rules and two technical layers stop nearly all of it. Process: verify any change to payment details by phone using a number you already have — never one from the email; require a second person’s sign-off on new payees or changed bank details; slow down end-of-month and Friday-afternoon requests, which is when attackers deliberately strike. Technical: enforce multi-factor authentication on every email account, so a stolen password isn’t enough, and deploy email security that flags lookalike domains and external senders.

What to Do if Money Already Moved

Speed matters more than anything. Call your bank’s fraud department immediately and ask for a recall and a SWIFT recall if it went internationally. File with the FBI’s IC3 (ic3.gov) — funds recalled within 48 hours are sometimes recoverable. Then assume the email account that was impersonated or compromised is still burned: reset credentials, check forwarding rules attackers love to hide, and review what else that mailbox touched.

Making It Stick

Policies fade; systems don’t. Boston Networks builds these controls into how construction companies and trade contractors operate — MFA everywhere, hardened email, staff training with realistic phishing simulations, and 24/7 monitoring that catches compromised accounts before they’re used against you. Talk to us before the email arrives, not after.

Get Your Free Guide To Choosing a Managed Services Provider