All insights

Wire fraud

After a BEC wire loss, you risk a second incident while under investigation

Published
August 14, 2026
Read
6 min
Desk
Coffr Research Desk

After the recall request, fake helpers can ask for retainers, wire packets, mailbox exports, and vendor files.

Conference room table with a laptop, phone, bank recall notes, incident contact sheet, and closed folder.

After a wire fraud loss, don't let anyone who calls in take part in the response until a designated person inside the company checks them out first. Specific people own specific outside contacts, so there's no confusion about who's allowed to talk to whom:

  • Treasury or the controller is the only one who deals with the bank.
  • Legal counsel is the only one who deals with law enforcement and any recovery firms.
  • Risk or claims is the only one who deals with insurers.
  • The vendor owner is the only one who deals with vendors.

On top of that, to guard against scammers posing as "recovery" specialists after a business email compromise, add these rules before anyone moves money or shares files with someone claiming to help recover the funds:

  • Call them back only using a phone number you already had on file , and never a number they give you.
  • Get their authority to act in writing.
  • Get real case details/documentation, not just a claim that they're handling it.
  • Freeze any related payment until all of the above checks out.

The cleanup team can authorize the second loss

The second payment often starts inside the response effort. The fraudster no longer has to beat the invoice control. They have to sound like part of the recovery file.

In a common post-loss script, the victim searches for help, reports the crime, or waits for a bank recall. Then a caller borrows official language, references an investigation, promises to retrieve funds, and asks for a fee, credentials, documents, or a new transfer path.

Inside a company, that can feel real because the facts are fresh. The AP manager knows the loss happened. The controller knows the bank recall is pending. Counsel may be collecting records. Insurance may be asking for timelines and evidence.

A case number can feel safer than a bank account. That is the control failure.

The company may have segregation for vendor onboarding and payment release, while having no comparable rule for the week after a loss. A person who could not change a vendor bank account on Monday may be able to send a wire detail packet, mailbox export, or retainer payment on Thursday because everyone believes the emergency has already been authenticated.

Official names are fresh material for impostors

New government programs can help real investigators coordinate. They also give fraudsters better vocabulary for the call that comes after a company has already lost money.

ABA Banking Journal reported that President Trump directed federal law enforcement to create a program that partners with the private sector to target transnational criminal organizations responsible for ransomware attacks, phishing campaigns and other cybercrimes. The report says the program will sit within the Homeland Security Task Force's National Coordination Center, with oversight from executive directors from the Department of Justice and Department of Homeland Security, and will recruit private companies to provide services to combat cybercrime for private and public entities.

The same report said U.S. consumers reported losing more than $20.8 billion to cyber-related crime last year, according to the White House. It also said three in four adults have experienced some kind of online scam or attack.

For a finance team, the practical point is narrow. A caller who says they are tied to a task force, a private partner, or a federal cyber program is making a claim, not proving identity.

Rapid data sharing gives impostors another costume. ABA Banking Journal reported that a proposed FDIC rule would allow banks to share confidential information with certain parties without first obtaining FDIC authorization, if the sharing has a business purpose and both parties have a confidentiality agreement. A real rule like that can make urgent file movement sound normal. It does not make an inbound document demand legitimate.

The impostor does not need a perfect forgery. They need a plausible phrase at a plausible moment. A task force name. A private sector partner reference. A case intake portal. A demand for invoices, headers, bank records, or a small payment to release recovered funds.

Each item sounds like administration, not theft.

BEC recovery scam controls need an owner

The contact protocol should be assigned before the next incident. Each outside party needs one internal owner, one permitted channel, and one proof package before the company sends money or documents.

The protocol is not a phone tree. It is an authority map. It should say who can speak, who can receive documents, who can approve a fee, and who can tell the bank to act. It should also say who cannot.

  • Treasury or the controller takes the bank lane. Call back through a number already stored in treasury management records, bank documents, or a prior relationship file. Record the bank employee's name, department, callback path, reference number, time, and instruction given.
  • Insurer contact should begin in the policy file. Risk or claims opens the claim through the carrier contact or broker record already on hand. Inbound links and attachments sit untouched until someone verifies them outside the message.
  • Do not let counsel become a shared inbox. The general counsel or controller confirms any law firm through the engagement letter, known firm number, or preapproved outside counsel list. Sensitive files wait until the recipient, matter, and authority to receive them are written down.
  • For law enforcement, counsel makes the first verified contact. An agency name, badge line, case number, or email domain is not enough. Counsel confirms through a known agency switchboard or established agent contact, then records the office, matter number, and requested records.
  • Recovery firms stay outside the money path until legal and procurement clear them. No retainer, wire instruction, mailbox export, or bank packet moves until legal approves the engagement and procurement verifies the payment destination through an independent channel.
  • Vendor contact does not move just because the loss is real. The business owner uses master file data or prior contract records to make contact. AP rejects recovery instructions from a new sender, even when the sender quotes the loss amount or invoice trail.

This is where many incident plans are thin. They say to notify the bank, insurer, counsel, and law enforcement. They do not say which person can accept a return call, which proof must be captured, or whether an apparent investigator may receive AP ledgers and mailbox contents.

Proof beats caller status

A caller's claimed role should never be the control. Proof should come from records the company already had before the loss, or from a channel the company initiates independently.

That matters because post-loss files are unusually rich. They may contain wire confirmations, vendor tax records, email headers, insurance applications, screenshots, employee names, approval chains, and bank relationship details. A recovery scammer who obtains that file may not need a second payment today. They may have enough to build the next impersonation.

Tool access needs the same suspicion as a wire request. PYMNTS reported that an AI agent connected to a bank's internal systems, fraud tools, or payment APIs needs restricted credentials, network limits, transaction thresholds, tool allowlists, and independent logging. A recovery vendor's portal, mailbox collector, or agent does not get broader access because the matter is urgent.

Set a slower rule for recovery activity than for ordinary vendor maintenance. Nobody gets paid, added to a portal, granted mailbox access, or sent bank evidence because they arrived with the right language. The request has to survive identity proof, authority proof, file-scope approval, and payment approval.

A clean proof package is short: the internal owner, the callback source, the outside party's legal name and role, the requested action, the documents released or withheld, the approver for any payment, and a note tying the action to fund recovery, evidence preservation, or a legal duty.

That file may feel slow in the first hour. It is less slow than explaining why the team sent a second wire to someone who knew the case number.

If your incident plan stops at bank recall, police report, and insurance notice, it leaves the most confused week unowned. Change the plan so nobody gets trusted because they sound official, and nobody gets to be helpful outside the proof path.

Questions practitioners ask

Who should be allowed to speak after a company reports a wire loss?

The company should name specific incident contacts before any outside communication begins. Treasury or the controller should handle the bank. Counsel should handle law enforcement and recovery firms. Risk or claims should handle insurers. The vendor owner should handle vendor contact. AP should not accept new instructions from inbound callers during the recovery period.

Can we trust a law enforcement case number without a callback?

No. A case number, badge line, agency title, or government email format is not enough. Counsel should initiate contact through a known agency switchboard, prior agent contact, or documented reporting channel. The file should capture the office, matter number, person contacted, requested records, and why the company released or withheld information.

What proof belongs in the file before paying a recovery firm?

The file should show who approved the engagement, how the firm was selected, how its identity was verified, what it is authorized to do, and how its payment details were confirmed through an independent channel. A retainer or emergency fee should not move because the firm knows the loss details or claims to work with an agency.

Why is the week after the BEC loss a separate control problem?

The first fraud creates urgency and a real case file. That makes later callers sound more credible, especially if they cite the loss, the bank recall, an insurer, or law enforcement. Standard vendor change controls may not apply to recovery activity unless the company assigns owners and proof rules before the incident.

Share and cite

XLinkedInRedditEmail

Community newsletter

The Trust Layer Briefing

CFOs, controllers, and AP leaders subscribe for weekly research on BEC vectors, ERP gaps, and payment instruction security.

One email each Thursday. No spam, one-click unsubscribe.

Practitioners can also request a seat on The Coffr Research Panel.