The first hour of a payment-redirection attempt
Invoice and wire fraud is rarely a technical failure. It is a process failure with a technical opening, and the first hour decides how much of it is recoverable.
The pattern almost never starts with money. It starts with a quiet mailbox login, usually weeks earlier, from an account with authority but not much scrutiny. The attacker reads. They learn how your firm phrases things, who signs off on what, and when a payment is due.
Then a message arrives that is correct in every respect except the account number. It arrives at the right point in a real transaction, in the right voice, referencing the right matter. Nobody is careless when they act on it.
What actually reduces the loss
- A verification rule that applies to every bank-detail change, with no exception for urgency or seniority.
- Verification by a phone number you already held, never one supplied in the message.
- Alerting on mailbox rules being created — attackers hide replies by auto-filing them.
- A named person who can call the bank within the hour, and the number to hand before it is needed.
Domestic wires can sometimes be recalled within hours. The window closes fast, and the delay is usually spent deciding who has authority to make the call.
The uncomfortable part
Most firms discover during the incident that nobody was sure who could authorise a recall request, or which bank contact to use. That is a fifteen-minute conversation to have in advance and an expensive one to have live. Write the two phone numbers down somewhere that does not require email access to reach.