Free Resource · guide

How Can Construction Companies Protect Against Email Fraud, Invoice Scams, and Payment Diversion?

The single most effective defense is a procedure, not a product: verbally verify every new or changed payment instruction by calling a phone number you already have on file, never one from the email that requested the change. Layer technical controls on top of that, MFA on every account, DMARC enforcement, alerts on mailbox rules and forwarding, but the callback rule is what stops the wire from leaving. Construction is a prime target because large progress payments move on email threads between GCs, subs, and vendors, and attackers know it.

Payment diversion fraud is the most expensive thing that routinely happens to construction companies that never make the news. No ransomware, no outage, no drama. An invoice arrives looking exactly like the last twelve from the same sub, the banking details are different, accounts payable updates the record, and a progress payment lands in an account the attacker controls. The FBI’s Internet Crime Complaint Center reports billions of dollars in business email compromise losses every year, and construction shows up in those numbers constantly because the industry’s payment habits are exactly what the scam feeds on.

Here is how the attack actually works, the one procedure that stops it, and the technical layer that makes the procedure hard to get around.

Why does this hit construction companies so hard?

Four things about how construction pays for work make it a standing target:

  • The payments are large and lumpy. Progress payments, draw requests, and retainage releases are regularly six and seven figures. One diverted wire can exceed a year of IT budget.
  • Many parties, no shared system. A single project can involve a GC, dozens of subs, suppliers, an owner’s rep, a lender, and a title company. Payment details move between them by email because that’s the only channel everyone shares.
  • Banking details change legitimately all the time. Subs switch banks, factor receivables, or get acquired. A “please update our remittance information” email is normal, which is what makes the fraudulent version invisible.
  • Approvals happen from the field. PMs and supers approve invoices from a phone in a trailer between other fires. Scrutiny of the sender address and the fine print is at its lowest exactly where the attacker wants it.

How does a payment diversion actually unfold?

The pattern is consistent across cases, and it is patient. This is the generic industry playbook, not a specific client’s story:

  1. Get a mailbox or fake one. The attacker either compromises a real email account, often at a subcontractor or vendor with weaker security than yours, or registers a lookalike domain one character off from the real one.
  2. Watch and wait. With access to a real mailbox, they read quietly for weeks. They learn who invoices whom, what the invoices look like, when draws are paid, and who at your company processes them. Often they set a hidden inbox rule that forwards or hides messages so the real owner never notices.
  3. Strike at the right moment. Just before a large payment is due, they send the update. Same invoice format, same signature block, same thread history. Only the routing and account numbers are new. Sometimes they add pressure: a lien threat, a schedule excuse, a “we changed banks after the audit.”
  4. Move the money fast. Once the payment lands, it hops through mule accounts within hours. This is why the first hour after discovery matters so much.

Notice that at the moment of loss, nothing technical fails. The email may come from a completely genuine account. That is why the core defense is procedural.

What is the one procedure that stops it?

Verbally verify every new or changed payment instruction by calling a phone number you already have on file. Never use a number, link, or contact from the email requesting the change.

That’s the whole rule, and it defeats the attack even when the sender’s mailbox is fully compromised, because the attacker controls the email channel but not your existing phone records. Replying to the email to confirm does nothing; the attacker answers your reply.

To make the rule real rather than aspirational:

  • Write it down as policy and have leadership sign it. Braintek maintains a written verbal confirmation policy for wire instructions internally, and our construction clients adopt the same practice for their own payables. A written policy is also what cyber insurance carriers ask about when they underwrite funds transfer fraud coverage.
  • Apply it to every change with no exceptions for urgency. Urgency is the tell, not a reason to skip the call.
  • Keep a known-good contact list for every vendor’s accounting department, built at onboarding, not at the moment of a change.
  • Add a second approver for wires above a threshold you choose. Two people have to be fooled instead of one.
  • Tell your vendors you do this, and ask them to do the same before changing where they send your money.

What technical controls back the procedure up?

The procedure stops the loss. The technical layer makes the attack harder to launch and easier to spot, and it maps cleanly onto CIS Controls Implementation Group 1, the same framework insurance carriers effectively test against.

  • MFA on every account, no exceptions. Most payment diversion starts with a compromised mailbox, and MFA blocks the bulk of account takeover attempts. Cover email, VPN, and admin accounts, and prefer app-based or phishing-resistant methods over SMS.
  • Conditional access in Microsoft 365. Entra ID can block sign-ins from countries you don’t operate in, flag impossible travel, and require compliant devices for access. For a Houston contractor whose entire workforce is in Texas, a successful login from overseas should never be silent.
  • Enforce SPF, DKIM, and DMARC on your domain. These let receiving mail systems reject mail that fakes your domain, which protects your subs and clients from attackers impersonating you. Set DMARC to an enforcement policy, not just monitoring. Many construction companies have SPF alone and assume they’re covered.
  • Alert on mailbox rules and forwarding. Attackers who compromise a mailbox almost always create hiding rules or external forwarding. Alerting when a new rule or forward appears catches an intrusion in the watching phase, before any money moves.
  • External sender banners and lookalike detection. A visible tag on mail from outside the company makes a spoofed internal address stand out, and modern filtering can flag domains that are one character off from vendors you actually correspond with.
  • Train the people who touch money, specifically. Generic phishing training helps, but AP staff, controllers, and PMs who approve invoices need scenario training on this exact scam, with simulated banking-change requests, because they are the actual targets.

What should you do in the first hour if the money already went out?

Speed is the only variable you still control. In order:

  1. Call your bank’s fraud department immediately. Ask for a recall of the wire and a freeze, and ask them to contact the beneficiary bank. Funds often sit in the first mule account for a short window before moving on.
  2. File at ic3.gov right away. The FBI’s Internet Crime Complaint Center runs a financial fraud kill chain process that can help freeze recently wired funds, and it works best within the first hours and days.
  3. Preserve everything. Keep the original emails with full headers, the fraudulent invoice, and any call records. Don’t delete the thread, don’t let anyone “clean up” the mailbox.
  4. Assume the mailbox is still compromised. Reset the affected account’s password, revoke active sessions, and check for hidden inbox rules and forwarding before sending anything else about the incident by email. The attacker may be reading your response in real time.
  5. Notify your insurance carrier if you carry crime or cyber coverage, and expect them to ask whether your verification procedure was followed.

Where does Braintek fit?

We support construction companies across Houston and Dallas-Fort Worth, with staff in both markets, and this scam is one of the first things we harden when we take on a new construction client. The Microsoft 365 and Entra ID controls above, conditional access, DMARC enforcement, mailbox rule alerting, are configuration work we do as part of our cybersecurity services, and the verification policy is something we help clients write and roll out to their AP process, modeled on the one we run internally. When something looks off, a suspicious banking-change email is exactly the kind of call our team answers in about 60 seconds, and a two-minute conversation before a wire goes out is worth more than any tool.

If you want a broader read on where you stand, a cyber security risk assessment covers this alongside the rest of your exposure, and our notes on what carriers require for cyber insurance show how these same controls decide whether your funds transfer fraud coverage pays when you need it.

Not sure your payment process would catch a swapped account number?

Tell us how invoices and banking changes move through your company today. We'll walk the path an attacker would take, show you where a swapped account number would slip through, and lay out the verification procedure and email controls that close it.

By submitting, you agree to be contacted by Braintek about your inquiry.

FAQs

What is business email compromise, in plain terms?

An attacker gets into or convincingly imitates a real email account, watches how money moves, then sends a message that looks routine: an invoice with new banking details, a request to update a vendor's account, a wire instruction from the boss. Nothing is hacked at the moment of loss. Someone is simply tricked into sending real money to the wrong account, which is why technical tools alone don't stop it.

Why are construction companies targeted more than other businesses?

The money is large and the process is exposed. Progress payments and retainage releases are often six or seven figures, they move between many parties who don't share systems, and payment details ride in email threads with subs, suppliers, and title companies. Project schedules also create urgency, and urgency is exactly what these scams exploit.

Is a confirmation email back to the sender good enough verification?

No. If the sender's mailbox is compromised, the attacker answers your confirmation email and politely confirms their own fraudulent account number. Verification only counts when it happens outside the email channel: a phone call to a number you already had on file before the change request arrived.

We already have spam filtering. Doesn't that cover this?

Filtering catches bulk phishing, but a payment diversion email often comes from a real, compromised account at a company you genuinely work with. It passes every technical check because it is technically legitimate. That is why the defense has to include a human procedure, not just filtering.

What should we do in the first hour if we already sent the money?

Call your bank immediately and ask for a recall and a fraud freeze on the outgoing wire, then have them contact the receiving bank. File a complaint at ic3.gov, the FBI's Internet Crime Complaint Center, which can trigger their financial fraud kill chain process for recent wires. Preserve the original emails with full headers, don't delete or forward-and-purge anything, and notify your insurance carrier if you carry crime or cyber coverage. Speed matters more than anything else here.

Does cyber insurance cover a diverted payment?

Sometimes, under funds transfer fraud or social engineering coverage, but usually with a sublimit and usually conditioned on you having followed a verification procedure. Carriers ask on the application whether you verify banking changes by callback. If you attested yes and didn't do it, the claim is in jeopardy. Our article on cyber insurance controls for construction companies covers what applications require.

How do we get subcontractors and vendors to follow the same rules?

Put it in the relationship up front. Tell every vendor in writing that you will never accept banking changes by email alone and will always call to confirm, and ask them to treat your payment details the same way. It protects both sides, and it removes the awkwardness of the call later because everyone expects it.

Ready for IT that just works?

Book a no-pressure discovery call. We'll review your setup and show you exactly where you stand.