A convincing invoice, a familiar email thread, and a deadline can be enough to send a legitimate payment to a criminal’s account. Wire transfer fraud succeeds when trust replaces verification—not just when someone clicks a malicious link.
If you have already sent a suspicious wire, contact the sending bank immediately. If you have not, pause the payment and independently verify the instructions. For businesses, homebuyers, and individuals, the core safeguard is the same: confirm where the money is going through a trusted channel established outside the payment request.
Already Sent the Money? Act Immediately
1. Call your bank’s fraud or wire-transfer team
Use the number in your banking app, on your statement, or another independently verified source—not contact details in the suspicious message. Explain whether someone accessed your account without permission or deceived you into authorizing the wire. That distinction can affect the bank’s investigation and applicable protections.
Ask the bank to:
- Stop the wire if it has not been released.
- Attempt an urgent recall or recovery if it has.
- Contact the receiving institution about the suspected fraud.
- Provide a case number and follow-up instructions.
IC3’s business email compromise guidance also recommends asking about a Hold Harmless Letter or Letter of Indemnity. Let the bank guide any required documentation. If you used a money-transfer company instead, contact that provider immediately and request cancellation or a refund.
2. Report the fraud and preserve evidence
File a report through the FBI’s Internet Crime Complaint Center. Gather the transfer date, amount, currency, transaction reference, beneficiary details, sending and receiving banks, and a timeline. Preserve original emails, attachments, messages, receipts, and relevant account records.
Do not delay the bank call while assembling a perfect report. Financial recovery, reporting, and account security should proceed in parallel when possible.
3. Contain account compromise and avoid recovery scams
If email or banking access may be compromised, involve your IT team or security provider immediately. Use a trusted communication channel for incident coordination.
Be wary of anyone promising guaranteed recovery for an upfront fee. The FTC warns that recovery scammers target people who have already lost money, sometimes impersonating government agencies or legitimate organizations.
Understand What You Are Trying to Stop
In business email compromise, or BEC, criminals impersonate an executive, vendor, attorney, or settlement professional. They may use a lookalike address or take over a real mailbox, allowing them to insert fraudulent instructions into an existing conversation. The FBI identifies vendor payments and real estate transactions as common targets.
Warning signs include changed bank details, unexpected beneficiaries, secrecy, and pressure to bypass approval. These warrant investigation, but their absence does not prove a payment is safe.
Grammar is not a reliable defense. The FBI warns that criminals use generative AI to improve messages and create convincing audio and video impersonations. A familiar voice should not override payment controls.
Verify Payment Instructions Independently
Establish trusted contacts before money is due
Record a verified contact and telephone number when a vendor relationship or transaction begins. Before sending a wire, call that person using the established number. Confirm the payment’s purpose, beneficiary, receiving bank, and account instructions.
Replying to the same email is not independent verification. Neither is calling a new number supplied in that email. An incoming call—even with a familiar caller ID—should not replace your own callback to a trusted number.
For example: A supplier sends an invoice announcing a new bank account. Instead of using the invoice’s phone number, accounts payable calls the supplier contact already on file. The payment remains on hold until the change is verified and separately approved.
Treat every bank-detail change as a new authorization
Do not overwrite saved beneficiary information simply because an email requests it. A practical workflow is to hold the change, verify it through the established contact, document the confirmed instructions, and obtain separate approval before use.
Record who verified the details, which trusted number they called, when verification occurred, and who approved release. Protect that record because it contains sensitive financial information.
If the contact is unavailable, pause. Establish backup contacts in advance rather than improvising under deadline pressure.
Separate preparation from approval
For businesses, have one person prepare the wire and another approve it. Apply separation to beneficiary changes as well. The second reviewer must examine the verification evidence—not merely trust the preparer. This implements the FBI’s recommendation for independent verification and secondary sign-off.
Ask your bank about separate user permissions, dual approval, transfer limits, beneficiary controls, and transaction alerts. Availability varies.
The tradeoff: Verification adds time and staffing requirements. Reduce disruption with scheduled payment windows and designated alternates, not informal exceptions for urgent requests or senior executives.
Urgency is a reason to follow the verification process—not a reason to suspend it.
Protect Accounts Without Confusing Login Security With Payment Safety
Require multifactor authentication, or MFA, for email, banking, administrative access, and other supported payment systems. CISA recommends prioritizing phishing-resistant MFA; FIDO/WebAuthn-based options provide that protection where supported. Plan enrollment, backup authenticators, and secure recovery procedures.
Keep two questions separate:
- Authentication: Is this person entitled to access the account?
- Payment verification: Is this recipient and transaction legitimate?
MFA helps prevent account takeover. It does not stop an authorized employee from approving fraudulent instructions. Similarly, two approvers can both be deceived if neither independently verifies the destination.
Investigate unexpected forwarding, missing messages, unfamiliar inbox rules, or unauthorized authentication methods. For Microsoft 365, Microsoft’s compromise-response procedure includes disabling affected accounts during investigation, revoking sessions, reviewing authentication methods and application permissions, removing malicious rules, and examining logs. A password reset alone is not a complete response.
Train employees with realistic payment-change scenarios and give them explicit authority to stop questionable transactions. Reporting a concern should be easier than making an exception.
Special Precautions for Homebuyers and Individuals
Before closing, identify trusted representatives at your title or settlement company and agree on how to verify wiring instructions. Save their contact information separately from email. The CFPB recommends establishing trusted contacts and independently confirming account information.
Immediately before wiring, call the agreed number and confirm the beneficiary and account details. If a last-minute message changes the destination, stop—even if delaying payment could affect the closing schedule.
For example, an email claiming that the settlement company’s bank is “undergoing maintenance” does not justify sending closing funds to a replacement account. Resolve the discrepancy with your established representative.
Individuals making other high-value payments can use the same callback process. Someone else’s deadline is not evidence that their instructions are authentic.
Can a Fraudulent Wire Be Reversed?
A recall request is not a guaranteed reversal. The Federal Reserve describes Fedwire settlement as immediate, final, and irrevocable. Banks and authorities may still attempt to recover fraud proceeds, but a completed wire cannot simply be undone on demand.
Rights depend on the transfer. For covered consumer remittances sent abroad, federal protections generally include a 30-minute cancellation opportunity after payment, unless funds have already been picked up or deposited into the recipient’s account. The CFPB explains these remittance protections; they are not a universal cancellation window for domestic business wires.
Ask your provider about your specific transaction. Report suspected fraud even if time has passed.
Your Wire Transfer Fraud Checklist
Before releasing a payment
- ☐ Confirm the payment’s purpose and intended recipient.
- ☐ Verify instructions using a previously established, trusted contact.
- ☐ Confirm beneficiary, bank, and account details—not just the amount.
- ☐ Independently verify any banking change before updating saved records.
- ☐ Document verification and complete required separate approvals.
- ☐ Stop unresolved discrepancies; do not let urgency override controls.
If fraud is suspected
- ☐ Call the sending institution immediately.
- ☐ Request a stop, recall, or recovery attempt and obtain a case number.
- ☐ Submit an IC3 report with accurate transaction information.
- ☐ Preserve original communications and payment records.
- ☐ Involve IT or security if account compromise is possible.
- ☐ Reject unsolicited recovery guarantees and upfront-fee offers.
Make Verification Routine
Stopping wire transfer fraud requires secure accounts, independent payment verification, and disciplined approval—not one supposedly foolproof tool. Before your next wire, establish trusted contacts, confirm your bank’s controls, and put this checklist into the payment workflow. If money has already gone to a suspected scammer, make the bank call now.