How Can Construction Companies Prevent Vendor Payment and Wire Fraud?
Construction companies can reduce vendor payment and wire fraud by using a 5-step payment verification process: verify the request, confirm changes through a separate communication channel, require approval, secure employee accounts, and document the transaction before releasing funds.
The biggest rule is simple:
Never change vendor or subcontractor payment information based only on an email.
Construction companies regularly exchange invoices, contracts, payment information, change orders, and other financial documents with subcontractors and vendors. That creates an opportunity for criminals to impersonate a trusted contact or compromise an email account and redirect a legitimate payment.
A single convincing email can potentially turn a routine vendor payment into a significant financial loss.
Here is a practical five-step framework construction companies can use to reduce that risk.
1. Treat Every Vendor Bank-Account Change as High Risk
A familiar vendor sends an email:
“We’ve changed banks. Please use the attached account information for all future payments.”
It may look completely legitimate.
The email may contain the vendor’s name, signature, project information, invoice details, and even previous email conversation history.
But the accounting employee should not change the payment information based solely on that email.
Create a company policy that treats requests involving changes to any of the following as high risk:
- Bank account numbers
- ACH information
- Wire instructions
- Payment destination
- Vendor contact information
- Payment methods
- Large or unusual payments
The employee receiving the request should assume it requires independent verification before making the change.
2. Verify Payment Changes Through a Separate Channel
This is one of the most important controls.
If a request arrives by email, don’t verify it by replying to that same email.
Instead, contact the vendor or subcontractor through a separately verified communication channel.
For example:
Email request → verify by phone
But don’t automatically call the phone number included in the suspicious email.
Use a phone number your company already has on file, from an existing vendor record, contract, or another independently verified source.
The verification conversation can be straightforward:
“We received a request to change your payment information. Before making the change, we’re independently confirming that your company authorized it.”
If the vendor cannot confirm the change, stop the payment process and escalate the issue.
The Two-Channel Rule
A simple policy construction companies can adopt is:
Payment change requested through Channel A → independently verify through Channel B.
This creates another obstacle for an attacker who may control only one communication channel.
3. Require a Second Person to Approve High-Risk Payments
One employee should not necessarily be able to receive a bank-change request, modify vendor information, and release a significant payment without another review.
Consider a two-person approval process for:
- New vendor banking information
- Changes to existing payment instructions
- Wire transfers
- Large ACH payments
- Unusual payment requests
- Payments outside normal procedures
For example:
Employee 1: Receives and independently verifies the change.
Employee 2: Reviews the verification and approves the payment.
The appropriate dollar threshold will vary by company.
A contractor might establish additional approval requirements for transactions over $5,000, $10,000, $25,000, or another amount appropriate for its operations and risk tolerance.
The important part isn’t choosing a universal number.
It’s establishing the threshold before a suspicious payment request arrives.
4. Secure the Email Accounts Used for Vendor Communications
Payment procedures alone aren’t enough.
Attackers may target the email accounts of:
- Owners
- Executives
- Controllers
- Accounting employees
- Project managers
- Vendors
- Subcontractors
If an account is compromised, an attacker may be able to monitor legitimate conversations and wait for the right moment to insert fraudulent payment instructions.
Construction companies should consider multiple layers of protection, including:
- Multifactor authentication (MFA)
- Email security and filtering
- Endpoint protection
- Strong access controls
- Security monitoring
- Employee phishing awareness
- Prompt account disabling during employee offboarding
- Regular review of suspicious login activity
Employees handling financial transactions should receive particular attention because their accounts can provide a direct path to company funds.
Watch for Warning Signs
Employees should slow down when a payment email involves:
- Unexpected banking changes
- Urgent requests
- Pressure to bypass normal procedures
- Requests for secrecy
- A slightly different email domain
- Unexpected attachments
- Changes in writing style
- A new phone number
- Last-minute payment instructions
One warning sign doesn’t automatically mean fraud.
It does mean the request deserves verification.
5. Document the Verification Before Releasing Payment
Verification should be a repeatable business process, not something employees handle differently every time.
Before changing payment information, document:
- Who requested the change?
- When was the request received?
- How was the request independently verified?
- Who at the vendor confirmed it?
- Which known phone number or contact method was used?
- Who approved the change internally?
- When was the payment information updated?
That creates accountability and makes the procedure easier for accounting employees to follow consistently.
Example: A Subcontractor Changes Banking Information
Consider a hypothetical construction company preparing to pay a subcontractor.
An accounting employee receives an email that appears to come from the subcontractor:
“Our banking information has changed. Please send this week’s payment to the new account attached.”
Instead of immediately updating the vendor record, the employee follows the company’s five-step procedure.
Step 1: Flag the bank-account change as a high-risk request.
Step 2: Call the subcontractor using the phone number already stored in the company’s vendor records.
Step 3: Confirm whether the subcontractor actually requested the change.
Step 4: Have a second authorized employee review the verification before changing the banking information.
Step 5: Document the verification and approval.
If the subcontractor says:
“We didn’t change our banking information.”
the payment is stopped before company funds are sent to the wrong account.
That’s why verification procedures matter even when an email looks legitimate.
What Is Business Email Compromise?
Business email compromise, often called BEC, is a type of fraud in which criminals use email to impersonate or compromise a trusted business contact.
In construction, an attacker might impersonate:
- A subcontractor
- A material supplier
- A company executive
- An accounting employee
- A project manager
- Another trusted vendor
The objective may be to convince an employee to change payment instructions or send money to an account controlled by the attacker.
Because the request may appear to come from someone the employee already knows, traditional “don’t open strange emails” advice isn’t enough.
Employees need a verification process for legitimate-looking financial requests.
What Should You Do If You Suspect a Fraudulent Payment Request?
If something doesn’t look right:
- Stop the payment or account change.
- Do not reply to the suspicious message for verification.
- Contact the vendor through independently verified contact information.
- Notify the appropriate manager or financial employee.
- Contact your IT/security provider if email compromise is suspected.
- Review the affected account for suspicious activity.
- Reset or secure credentials when appropriate.
- Document what happened.
If money has already been transferred, contact your financial institution and appropriate professional advisers immediately. Speed can be important when responding to suspected financial fraud.
Who Should Be Trained on Vendor Payment Fraud?
Don’t limit training to the IT department.
Employees involved in any part of the payment process should understand the procedure, including:
- Owners and executives
- CFOs and controllers
- Accounting employees
- Accounts payable staff
- Project managers
- Office managers
- Employees authorized to approve payments
Project managers are particularly important because they may communicate regularly with subcontractors and vendors.
Cybersecurity is therefore not only an IT responsibility.
It is also a business-process responsibility.
A Simple Vendor Payment Security Checklist
Before changing vendor payment information, ask:
Was the change independently verified?
Did we use contact information we already trusted?
Did a second person approve the change when required?
Is the requesting account legitimate and secure?
Did we document the verification?
If the answer to any required step is no, stop and verify before releasing the payment.
How Can IT Help Reduce Construction Payment Fraud?
Technology cannot replace financial controls, but it can reduce the opportunities attackers have to impersonate employees or compromise accounts.
A managed IT and cybersecurity provider can help construction companies evaluate areas such as:
- Microsoft 365 security
- Multifactor authentication
- Email protection
- Endpoint security
- Account monitoring
- Access controls
- Employee cybersecurity awareness
- Secure employee onboarding and offboarding
- Backup and recovery
- Incident-response planning
The strongest approach combines technology + employee awareness + payment procedures.
Cybersecurity Support for Construction Companies
Computerbilities has 30+ years of experience supporting construction and contracting businesses and understands that contractors operate differently from traditional office-only organizations.
Your employees may be spread across the office, home, and multiple job sites while communicating with project managers, vendors, suppliers, and subcontractors every day.
That makes cybersecurity both a technology issue and an operational issue.
Computerbilities helps construction businesses strengthen their IT and cybersecurity environments with proactive support, security solutions, monitoring, and industry-focused guidance.
Concerned about email security, vendor fraud, or cybersecurity risks in your construction business? Contact Computerbilities to discuss your current IT and security environment.