A supplier emails asking you to update their banking details before the next draw. The email comes from their real address. It references the right job, the right amount and the right date, because whoever sent it has been reading the thread for weeks.
The money goes out. The supplier calls a week later asking where it is.
This is payment redirection fraud, sometimes called business email compromise. It needs no malware and no break-in. A single email that looks exactly like the hundred before it is enough.
Why construction specifically
The scam works anywhere money moves by email. Construction just offers better conditions than almost any other industry.
The payments are large and scheduled. Progress draws, holdback releases and material invoices land on predictable dates for predictable amounts. An attacker who can read the thread knows exactly when to strike and what number will not raise an eyebrow.
There are a lot of parties. A single project can involve a general contractor, a dozen subtrades, suppliers, an owner and a lender. Every one of them is an inbox that can be compromised, and a compromise at any of them puts your payments at risk.
The work happens on phones. Superintendents and owners approve things from a truck between site visits. A small screen hides the details that would give a fake away, and nobody reads headers on a phone.
Accounts payable is often one person. In a firm of fifteen, the person paying invoices is frequently also running payroll, chasing receivables and answering the phone. Friday afternoon, with a cheque run due, is when this lands.
How it usually plays out
There are three common versions, and they are worth knowing apart.
The supplier's mailbox is compromised. This is the hardest to spot, because the email is genuinely from them. The attacker got in through a phished password, sets up a rule to hide replies from the real owner, and waits for a payment worth diverting.
A lookalike domain. The message comes from something one character away from the real
address, often with a .co where the .ca should be, or an extra letter in the middle. The
thread is copied in from a real conversation, so the history looks right.
Your own mailbox is the one compromised. The attacker sends the change request to your clients, from you, redirecting what they owe you. You find out when a customer insists they paid and you have no record of it.
The third version is the one firms forget to guard against, and it is the one that damages a client relationship as well as cash flow.
The controls that stop it
None of these need new software. Most of them need a written rule and the discipline to follow it when someone is in a hurry.
Verify every banking change by phone, on a number you already had. Not the number in the email, not the number in the signature block of the email, and not a number the caller gives you. The one in your system from before the request arrived. This one rule defeats the first two versions above, because the attacker controls the email but not the supplier's phone. The third needs your clients to follow the same rule, which is what the next two points are for.
Write it down. A verbal policy is followed until the first urgent request. A written one is something your office manager can point to when a caller insists there is no time to check. "It is our policy" ends the argument without anyone having to be rude.
Require a second person for any change to payment details. Not for every payment, only for changes to where money goes. It adds a minute and removes the single point of failure.
Tell your suppliers and clients the policy. A line on your invoices and in your email signature saying you will never change banking details by email turns every client into part of your defence. It also protects you if your own mailbox is ever the one compromised.
Turn on multi-factor authentication for every mailbox. Including the owner's, including the shared accounts inbox, including the one nobody uses anymore. A compromised mailbox usually starts with a password that was reused or phished, and multi-factor is what stops a stolen password from being enough.
Publish your email authentication records. SPF, DKIM and DMARC tell receiving mail servers how to recognise mail that genuinely comes from your domain. With DMARC set to reject, someone pretending to be you has a much harder time reaching your clients' inboxes. It is an afternoon of DNS work, and it is one of the questions on most cyber insurance applications.
Flag outside email. A banner on messages from outside your organisation, and an alert on domains that look like one you deal with regularly, catches the lookalike version before anyone reads the body.
If a payment has already gone
Speed matters more than anything else in the first hour.
- Call your bank immediately and ask them to recall the payment. The chance of getting money back falls quickly once it has moved on from the receiving account.
- Call the supplier on the number you had to confirm what happened and warn them. If their mailbox is compromised, they need to know today.
- Check your own mailbox for forwarding rules you did not create, and change the password on any account that could have been the entry point. Then confirm multi-factor is on.
- Keep the emails. Do not delete the thread. It is evidence for the bank, the police and your insurer.
- Report it to your local police and to the Canadian Anti-Fraud Centre.
- Notify your insurer promptly. Coverage for this kind of loss is often a separate provision with its own limit, and some policies require that a verification procedure was in place. Read your wording before you need it, not after.
The part that is not technical
Firms that lose money to this rarely lacked the knowledge. Most of them had some version of the rule. What they lacked was a written policy, a second pair of eyes, and a habit strong enough to survive a busy Friday.
That is fixable in an afternoon, and it costs nothing.
We set up the technical half for construction and trades firms as a matter of course: multi-factor on every mailbox, email authentication, outside-sender flags and the forwarding-rule alerts that catch a compromised account early. The written rule is yours, and it is the half that matters most.
Related guides
- The IT checklist accounting firms should finish before tax seasonThe work to finish in the quiet months, so nothing breaks between February and April 30.
- Windows 10, a year after support ended: the October decisionWhat year two of Extended Security Updates costs, and how to decide machine by machine.