Construction is a target because the money moves in large, expected, scheduled chunks. A six-figure progress payment doesn't raise an eyebrow. That's exactly what the attacker is counting on.
The sequence
- A subcontractor's mailbox is compromised, usually through a reused password and no MFA.
- Nothing happens for weeks. The attacker reads. They learn the project names, the draw schedule, the tone of the emails, who approves what.
- A real invoice thread gets a reply (from the real address, in the real thread) with updated banking details and a plausible reason.
- The payment goes out. Nobody notices until the sub asks where their money is, which can be a full cycle later.
Why 'be careful' isn't a control
The email is legitimate. It comes from the address you've corresponded with for two years, inside a thread you started. Vigilance training is worth doing, but you cannot ask an accounts payable clerk to out-detect a message that is, technically, genuine.
Where to break the chain
- A hard rule: banking changes are confirmed by phone, on a number already on file, never a number from the email.
- MFA everywhere, so the mailbox doesn't get read in the first place.
- Alerting on mailbox forwarding rules, which is how attackers hide their tracks.
- A second approver on any payment above a threshold you set.
None of those are expensive. All of them are cheaper than one redirected draw.