The wire transfer that almost happened
Email fraud against small businesses doesn't involve malware or hacking. It involves a convincing email about changed bank details, and a controls gap you can close this month.
The most expensive security incident at a small business usually involves no malware, no exploit, and nothing your antivirus would have flagged. It involves a believable email about a change of bank details, an accounts payable clerk doing exactly their job, and a wire that clears before anyone notices.
The FBI has been publishing losses from this category for years and it consistently dwarfs ransomware for businesses in the 10–200 employee range. It is also the one that people prepare for the least, because it does not look like a computer problem. It looks like an email.
How it actually runs
The version we see in Orange County, against distributors, property managers, and construction and dental offices alike, follows a script.
Week one: someone’s mailbox opens. Usually through a reused password, or a convincing sign-in page. No alarm goes off, because from the outside it is a legitimate login. The attacker does not send anything yet.
Weeks one to four: they read. They learn who approves payments, who your vendors are, what your invoices look like, how your controller writes, when the owner travels. Frequently they add a quiet mailbox rule that files replies containing “invoice” or “wire” into an unread folder, so the real conversation stays hidden from the actual mailbox owner.
The ask. A message arrives, on the right thread, in the right voice, from a domain one character off yours, or from the genuinely compromised mailbox itself. Our bank has changed. Please update remittance details for this invoice. Often it is timed for a Friday afternoon, or for the week the owner is demonstrably out of the country.
The clear. Wires do not reverse like credit cards. If it clears and it is noticed on Monday, recovery depends on how fast the receiving bank freezes the account. Sometimes that works. Usually it does not.
Nothing in this sequence requires sophistication. It requires patience and a business without a verification step.
The controls that stop it
There are exactly two that matter most, and neither is a product.
Verify every banking change out of band. Any request to change payment details (vendor, employee direct deposit, anything) gets confirmed by phone to a number you already had on file, not a number in the email. Written into your AP procedure, applied without exception, including when the request appears to come from the owner. Especially then. This one rule stops the majority of these attempts outright.
Multi-factor authentication on email, for everyone. This is what closes week one. It is free with the mail platform you are already paying for, it takes an afternoon to roll out, and it is the single highest-value hour of security work available to a small business. There is no version of this article where that is optional.
After those two, in order of value:
- A second approver above a dollar threshold you pick. Pick one that matches your real payment sizes, not a number from a template.
- Alerting on mailbox rules. Auto-forwarding and auto-filing rules created on a user mailbox should generate an alert to someone. That single signal catches compromises during the reading phase, before any money is discussed.
- Block or flag look-alike domains. Mail filtering can catch the one-character-off domain and the display name that impersonates your CEO.
- Tell your staff the specific script, not “be careful with email.” Someone who has read the sequence above recognizes it. Someone who has sat through a generic phishing video does not.
The part people get wrong
Two things, consistently.
The first is treating this as an IT problem. It is a finance procedure problem that arrives by email. The control that works lives in accounts payable, and it works even when the email is perfect, which is why it is the one to implement first, before any tooling.
The second is blaming the clerk afterward. In every one of these cases the employee did what the process allowed. If a single convincing email can move money out of your company, the process is the finding, not the person. Fix the process and the same employee becomes the control that stops the next attempt.
If it is happening right now
If you think a mailbox is compromised: reset the password and revoke active sessions, then check for mail rules and forwarding you did not create. If money has already moved, call your bank’s fraud line immediately and ask for a wire recall, then file with the FBI’s IC3. Speed matters more than anything else in the first hours, and recovery odds drop sharply after the first day.
If you would rather not find out how good your process is under pressure, the verification rule and MFA can both be in place before the end of the month. That is a short conversation, and we are happy to have it whether or not you end up working with us.