Payment diversion fraud is the most expensive thing that routinely happens to construction companies that never make the news. No ransomware, no outage, no drama. An invoice arrives looking exactly like the last twelve from the same sub, the banking details are different, accounts payable updates the record, and a progress payment lands in an account the attacker controls. The FBI’s Internet Crime Complaint Center reports billions of dollars in business email compromise losses every year, and construction shows up in those numbers constantly because the industry’s payment habits are exactly what the scam feeds on.
Here is how the attack actually works, the one procedure that stops it, and the technical layer that makes the procedure hard to get around.
Why does this hit construction companies so hard?
Four things about how construction pays for work make it a standing target:
- The payments are large and lumpy. Progress payments, draw requests, and retainage releases are regularly six and seven figures. One diverted wire can exceed a year of IT budget.
- Many parties, no shared system. A single project can involve a GC, dozens of subs, suppliers, an owner’s rep, a lender, and a title company. Payment details move between them by email because that’s the only channel everyone shares.
- Banking details change legitimately all the time. Subs switch banks, factor receivables, or get acquired. A “please update our remittance information” email is normal, which is what makes the fraudulent version invisible.
- Approvals happen from the field. PMs and supers approve invoices from a phone in a trailer between other fires. Scrutiny of the sender address and the fine print is at its lowest exactly where the attacker wants it.
How does a payment diversion actually unfold?
The pattern is consistent across cases, and it is patient. This is the generic industry playbook, not a specific client’s story:
- Get a mailbox or fake one. The attacker either compromises a real email account, often at a subcontractor or vendor with weaker security than yours, or registers a lookalike domain one character off from the real one.
- Watch and wait. With access to a real mailbox, they read quietly for weeks. They learn who invoices whom, what the invoices look like, when draws are paid, and who at your company processes them. Often they set a hidden inbox rule that forwards or hides messages so the real owner never notices.
- Strike at the right moment. Just before a large payment is due, they send the update. Same invoice format, same signature block, same thread history. Only the routing and account numbers are new. Sometimes they add pressure: a lien threat, a schedule excuse, a “we changed banks after the audit.”
- Move the money fast. Once the payment lands, it hops through mule accounts within hours. This is why the first hour after discovery matters so much.
Notice that at the moment of loss, nothing technical fails. The email may come from a completely genuine account. That is why the core defense is procedural.
What is the one procedure that stops it?
Verbally verify every new or changed payment instruction by calling a phone number you already have on file. Never use a number, link, or contact from the email requesting the change.
That’s the whole rule, and it defeats the attack even when the sender’s mailbox is fully compromised, because the attacker controls the email channel but not your existing phone records. Replying to the email to confirm does nothing; the attacker answers your reply.
To make the rule real rather than aspirational:
- Write it down as policy and have leadership sign it. Braintek maintains a written verbal confirmation policy for wire instructions internally, and our construction clients adopt the same practice for their own payables. A written policy is also what cyber insurance carriers ask about when they underwrite funds transfer fraud coverage.
- Apply it to every change with no exceptions for urgency. Urgency is the tell, not a reason to skip the call.
- Keep a known-good contact list for every vendor’s accounting department, built at onboarding, not at the moment of a change.
- Add a second approver for wires above a threshold you choose. Two people have to be fooled instead of one.
- Tell your vendors you do this, and ask them to do the same before changing where they send your money.
What technical controls back the procedure up?
The procedure stops the loss. The technical layer makes the attack harder to launch and easier to spot, and it maps cleanly onto CIS Controls Implementation Group 1, the same framework insurance carriers effectively test against.
- MFA on every account, no exceptions. Most payment diversion starts with a compromised mailbox, and MFA blocks the bulk of account takeover attempts. Cover email, VPN, and admin accounts, and prefer app-based or phishing-resistant methods over SMS.
- Conditional access in Microsoft 365. Entra ID can block sign-ins from countries you don’t operate in, flag impossible travel, and require compliant devices for access. For a Houston contractor whose entire workforce is in Texas, a successful login from overseas should never be silent.
- Enforce SPF, DKIM, and DMARC on your domain. These let receiving mail systems reject mail that fakes your domain, which protects your subs and clients from attackers impersonating you. Set DMARC to an enforcement policy, not just monitoring. Many construction companies have SPF alone and assume they’re covered.
- Alert on mailbox rules and forwarding. Attackers who compromise a mailbox almost always create hiding rules or external forwarding. Alerting when a new rule or forward appears catches an intrusion in the watching phase, before any money moves.
- External sender banners and lookalike detection. A visible tag on mail from outside the company makes a spoofed internal address stand out, and modern filtering can flag domains that are one character off from vendors you actually correspond with.
- Train the people who touch money, specifically. Generic phishing training helps, but AP staff, controllers, and PMs who approve invoices need scenario training on this exact scam, with simulated banking-change requests, because they are the actual targets.
What should you do in the first hour if the money already went out?
Speed is the only variable you still control. In order:
- Call your bank’s fraud department immediately. Ask for a recall of the wire and a freeze, and ask them to contact the beneficiary bank. Funds often sit in the first mule account for a short window before moving on.
- File at ic3.gov right away. The FBI’s Internet Crime Complaint Center runs a financial fraud kill chain process that can help freeze recently wired funds, and it works best within the first hours and days.
- Preserve everything. Keep the original emails with full headers, the fraudulent invoice, and any call records. Don’t delete the thread, don’t let anyone “clean up” the mailbox.
- Assume the mailbox is still compromised. Reset the affected account’s password, revoke active sessions, and check for hidden inbox rules and forwarding before sending anything else about the incident by email. The attacker may be reading your response in real time.
- Notify your insurance carrier if you carry crime or cyber coverage, and expect them to ask whether your verification procedure was followed.
Where does Braintek fit?
We support construction companies across Houston and Dallas-Fort Worth, with staff in both markets, and this scam is one of the first things we harden when we take on a new construction client. The Microsoft 365 and Entra ID controls above, conditional access, DMARC enforcement, mailbox rule alerting, are configuration work we do as part of our cybersecurity services, and the verification policy is something we help clients write and roll out to their AP process, modeled on the one we run internally. When something looks off, a suspicious banking-change email is exactly the kind of call our team answers in about 60 seconds, and a two-minute conversation before a wire goes out is worth more than any tool.
If you want a broader read on where you stand, a cyber security risk assessment covers this alongside the rest of your exposure, and our notes on what carriers require for cyber insurance show how these same controls decide whether your funds transfer fraud coverage pays when you need it.
