SardineCon SF/2026

Learn More

What is Wire transfer fraud?

SUBSCRIBE

Wire transfer fraud is tricking someone into sending, or directly executing, a fraudulent wire through business email compromise, social engineering, or account takeover. Wires are fast, high-value, and almost impossible to reverse once sent, which makes them a prime target.

What is wire transfer fraud, in plain English?

A wire is a direct bank-to-bank transfer that settles fast and moves large sums. Wire transfer fraud is any scheme that ends with one of those transfers going to a criminal. Sometimes the fraudster tricks an employee or customer into sending it, and sometimes they take over an account and send it themselves. Either way, real money leaves through a legitimate rail.

The most common route is business email compromise, where an attacker impersonates a vendor, executive, or partner and sends payment instructions that look routine. Other routes include broader social engineering, invoice manipulation, and full account takeover. The wire itself is ordinary; what makes it fraud is the deception or intrusion behind the instruction.

Two properties make wires uniquely dangerous. They are high-value, so a single successful fraud can be enormous, and they are near-final, because once a wire settles there is no built-in reversal. Recovery depends on catching it before or just after the money moves.

How a fraudulent wire happens

The classic business-email-compromise version follows a tight sequence:

  1. Access — Compromise or spoof an inbox. The attacker gains access to, or convincingly imitates, a trusted vendor, executive, or finance contact.
  2. Set up — Change the payment details. A believable message updates bank details or pushes an urgent new invoice, redirecting payment to a mule account.
    • Caught — Verified out of band. Finance calls the known number, spots the change, and stops the wire before sending.
    • Missed — Trusted the email. The new details are accepted at face value and the payment is queued.
  3. Send — Execute the wire. The transfer is approved and sent, often timed for a Friday or before a holiday to delay discovery.
  4. Move — Layer and cash out. Funds are quickly split, forwarded through mule accounts, and withdrawn before anyone notices.

Who is involved?

Who

Their role

The paying party

The business or person who sends the wire, deceived into it or hijacked; usually the one who bears the loss.

The impersonated party

The real vendor or executive whose identity is spoofed or whose inbox was compromised.

The mule and receiver

Holds the destination account and rapidly moves the funds onward to break the trail.

The banks

Sending and receiving institutions that must act fast on recall or freeze requests to recover anything.

What it looks like in practice

In practice

A company's accounts payable clerk gets an email that appears to come from a long-standing supplier, saying the supplier has switched banks and to use new account details on the next invoice. The wording matches past emails and references a real open invoice.

The clerk updates the record and wires a six-figure payment. Days later the genuine supplier chases the overdue invoice, and the fraud is clear. The bank issues a recall request, but most of the funds have already been layered through mule accounts. Had the clerk phoned the supplier's known number to confirm the change, the wire would never have gone out.

Why it matters to operators

Wire fraud combines the worst traits for a defender: large amounts and finality. There is no chargeback mechanism and no automatic reversal, so the moment a fraudulent wire settles the money is effectively gone unless you move within a very short window. That makes prevention and speed the whole game.

The controls that work are procedural, not just technical. Confirming any change of payment details through a separate known channel, requiring two approvers on high-value wires, and screening the beneficiary's risk before release stop the most common schemes. When one does slip through, a fast recall or freeze request to both banks is the only realistic path to recovery.

What to watch in the data

  • Last-minute detail changes. A vendor or payee bank account that changed just before a payment, especially via email only.
  • Urgency and secrecy. Pressure to pay fast, keep it confidential, or bypass normal approval steps.
  • New or mismatched beneficiary. A first-time recipient, a name that does not match the account, or a bank in an unexpected country.
  • Timing games. Requests landing before weekends or holidays to widen the gap before anyone reconciles.
  • Rapid onward movement. Received funds that are split and forwarded almost immediately, a mule signature on the receiving side.

Quick questions

Can a fraudulent wire be reversed?

Not automatically. Wires have no built-in reversal like a card chargeback. Recovery depends on a fast recall or freeze request to the sending and receiving banks before the money is moved onward, which is why speed is everything.

How is wire fraud connected to business email compromise?

Business email compromise is the most common way wire fraud is set up. The attacker impersonates a trusted party by email to deliver believable payment instructions, and the fraudulent wire is the payout. Not all wire fraud is BEC, but a large share of it is.

Is wire fraud authorized or unauthorized?

It can be either. If an employee is deceived into sending it, it resembles authorized fraud. If an attacker takes over the account and sends it themselves, it is unauthorized. The distinction affects the investigation and liability.

What single control helps most?

Out-of-band verification. Confirming any new or changed payment details by calling a known, previously verified number, not one supplied in the request, stops the majority of BEC-driven wire fraud before it starts.

Why do attackers time wires around weekends?

Because reconciliation and staffing are lighter, so the fraud goes unnoticed longer. Every extra hour before discovery gives them more time to layer and withdraw the funds beyond recall.

What should happen the moment fraud is suspected?

Contact both banks immediately to request a recall and freeze, notify law enforcement, and preserve the emails and approval trail. The recovery window is measured in hours, so acting fast beats a perfect investigation.

Go deeper

What to know alongside Wire transfer fraud