All insights
Construction5 min read

Wire fraud on a construction project: how the invoice email actually gets through

A payment redirect doesn't start with a hack. It starts with a mailbox someone has been quietly reading for six weeks. Here's the sequence, and where to break it.

Construction is a target because the money moves in large, expected, scheduled chunks. A six-figure progress payment doesn't raise an eyebrow. That's exactly what the attacker is counting on.

The sequence

  • A subcontractor's mailbox is compromised, usually through a reused password and no MFA.
  • Nothing happens for weeks. The attacker reads. They learn the project names, the draw schedule, the tone of the emails, who approves what.
  • A real invoice thread gets a reply (from the real address, in the real thread) with updated banking details and a plausible reason.
  • The payment goes out. Nobody notices until the sub asks where their money is, which can be a full cycle later.

Why 'be careful' isn't a control

The email is legitimate. It comes from the address you've corresponded with for two years, inside a thread you started. Vigilance training is worth doing, but you cannot ask an accounts payable clerk to out-detect a message that is, technically, genuine.

Where to break the chain

  • A hard rule: banking changes are confirmed by phone, on a number already on file, never a number from the email.
  • MFA everywhere, so the mailbox doesn't get read in the first place.
  • Alerting on mailbox forwarding rules, which is how attackers hide their tracks.
  • A second approver on any payment above a threshold you set.

None of those are expensive. All of them are cheaper than one redirected draw.

bNetworked Inc. · Serving Nova Scotia, New Brunswick, PEI, and Newfoundland & Labrador

Next step

Want to know how this applies to your business?

Book a Cyber Strategy Session. Thirty minutes, no pitch deck.