irp pt 2 image no it strategy llc

The Attack That Doesn't Look Like an Attack. Wire Fraud and Your Incident Response Plan. (Part 2)

By Nate Olson, Fractional IT Director & vCIO | N.O. IT Strategy LLC

In Part 1, I walked you through how your Incident Response Plan (IRP) helped you navigate what to do when your business was hit with ransomware, where that threat is obvious. Screens are locked, a countdown appears, and you know within minutes you’re in trouble.

Wire fraud is the opposite. Nothing locks, nothing seems broken and no alarm have gone off. An email comes in, somebody does their job, and the money is gone. By the time anyone notices, it has often already moved through a few banks and out of reach.

Unfortunately, it’s not rare. Business email compromise (BEC) cost U.S. businesses $2.77 billion in 2024 across more than 21,000 reported incidents, with an average loss of $137,132 per incident. A separate survey found 63% of organizations were hit with an attempt last year. This is the most common expensive attack on a business that almost nobody plans for.

Here’s how it can happen.

You get an email from a vendor you’ve worked with for years. Same name, same signature, maybe even the same ongoing thread. It says their banking details have changed, please send this month’s payment to the new account. Or it’s a quiet, urgent note from your boss asking you to wire a deposit for a deal closing today. Nothing about it looks wrong, because the attacker has been sitting inside that email account for weeks, learning how your people talk and waiting for a real invoice to come due.

So someone in accounting does exactly what they’re supposed to do, they pay it.

Without a plan, here’s what usually happens. The wire goes out. At some point, the real vendor calls asking where their money is or maybe you received a late notice. You call the vendor, they never received payment. You have proof of payment right? Which end up showing you paid someone else when the notes are compared. Now the panic starts. Someone calls the bank, but the funds are long gone. Someone files a report online, eventually. Then you call your insurance carrier, confident you’re covered, and that’s where the second gut punch lands. More on that in a minute.

With a plan, the story changes at four points.

Verification, before the money moves.

This is the gamechanger. Your plan requires that any new or changed payment instruction gets verified out of band, meaning a phone call to a number you already had on file, not the number in the email and not a reply to the thread.

One 90-second call to the vendor/requester kills almost every version of this attack. It feels like friction. It is the cheapest insurance in your operation. And as you’ll see, your actual insurance may depend on it.

The first hour, if it gets through.

Wire fraud is one of the few attacks where speed can claw the money back. Your plan says the moment you suspect a fraudulent transfer, you call your bank’s fraud line and request a recall, and you report it to the FBI at ic3.gov immediately.

That report triggers the FBI’s Financial Fraud Kill Chain, which works with banks to freeze the funds before they vanish. The FBI’s recovery team reported a 66% success rate freezing fraudulent transfers. But the difference between getting your money back and never seeing it again is measured in hours, not days. A plan means nobody wastes the morning deciding who to call.

Locking down the account.

If the attacker was inside an email account, and they usually were, the fraud is only the part you can see. Your plan says reset credentials, turn on multifactor authentication, and check for the hidden mailbox rules attackers set up to auto-delete or forward replies so the victim never sees the warning signs. Then figure out what else they read while they were in there.

Skip this and they simply come back next month.

The insurance reality, the one that stuns people.

Remember that gut punch I mentioned earlier, here you go.

Most owners assume their cyber policy covers a wire fraud loss. It’s possible, it does not. Since your employee chose to send the money, insurers frequently treat it as “voluntary parting” and it is usually not automatically covered by a cyber policy.

Check with your carrier, but paying for this specifically takes a social engineering fraud or funds transfer fraud endorsement, and even then the coverage is usually capped well below your real exposure. A policy with a $2 million limit might cap social engineering fraud recovery at $100,000 or $250,000. Many carriers will only pay if you can show you used a verification procedure, such as out-of-band authentication, before transferring the funds.

That’s the exact call from the first point above. Your plan is what makes sure that call happened, and what makes you find all of this out now, while you can still fix your coverage, instead of in the denial letter. 

Now look at what every one of those points depends on, a person.

Wire fraud doesn’t beat your technology, it beats your people, so your strongest defense is a team that recognizes the play and picks up the phone before the checkbook. The trained employee who pauses on the “urgent” request is worth more than any email filter you can buy.

here is where I see businesses kidding themselves. They run an annual security awareness session, check the box, and then nothing else training wise until next year, same checkbox. While that solution seems painless, its potential harm greatly outweighs the convenience, people forget. The scams change, a training you ran last January does nothing for the employee who gets a flawless fake invoice in October. Awareness only works when it’s continuous, when each month builds on the last, so the lessons stick and your team stays sharp against what’s actually circulating right now.

If you don’t have that running, it’s one of the cheapest gaps to close, and one I can close for you.

Here’s the whole point. 

Ransomware kicks your door in. Wire fraud knocks politely, in a voice you recognize, and walks out with the money while everyone smiles. The plan is what turns “the money is gone” into “we made one phone call and stopped it,” and what keeps you from learning, too late, that you were never insured for it in the first place.

That’s Part 2 of the IRP series.

 In Part 3, I’ll take on the data breach, where nothing leaves your bank account but your customers’ information walks out the door, and a legal clock starts running the second it does.

Don’t want to wait for the whole series?

I help on both ends of this. I build incident response plans that hold up under pressure, the kind that make these decisions before the attack instead of during it. And for businesses that don’t already run annual security awareness training, I offer a continuous program that builds month over month, so your team doesn’t forget what they learned and can catch the fake invoice before the money ever moves. 

If you need help with either one, let’s talk.


Sources

  1. FBI Internet Crime Complaint Center (IC3). 2024 Internet Crime Report.
  2. Association for Financial Professionals. 2025 Payments Fraud and Control Survey.
  3. Aon. When Is a Cyber Crime Not a “Cyber-Crime”? Social Engineering Fraud and Business Email Compromise.