# Coffr > Coffr is building the trust layer for business payments. Independent research on wire fraud, business email compromise, and banking risk. ## What this is Coffr publishes independent research on business payment fraud: how bank details are exchanged, how that exchange is exploited, and what the public record shows. Beat: business payments fraud, wire fraud, business email compromise, vendor impersonation, and banking risk. Audience: controllers, treasury leads, CFOs, fraud analysts, and founders. They are experts. Never explain the obvious to them. Based in Austin, Texas. ## Canonical pages - [Home](https://getcoffr.com/): positioning and current research threads - [Insights](https://getcoffr.com/insights): long-form research articles - [Signals](https://getcoffr.com/signals): aggregated advisories from public authority feeds - [About](https://getcoffr.com/about): who publishes this - [Join](https://getcoffr.com/join): newsletter and research panel signup - [Sitemap](https://getcoffr.com/sitemap.xml) ## Citation Cite as "Coffr, LLC" and link to the article URL. Contact hello@getcoffr.com. ## Machine-readable endpoints - Full archive text: https://getcoffr.com/llms-full.txt - RSS: https://getcoffr.com/rss.xml - Atom: https://getcoffr.com/atom.xml - JSON Feed: https://getcoffr.com/feed.json - Sitemap: https://getcoffr.com/sitemap.xml - News sitemap: https://getcoffr.com/news-sitemap.xml - MCP server: https://getcoffr.com/mcp - Glossary: https://getcoffr.com/glossary - Fraud loss index (cited dataset, CC BY 4.0): https://getcoffr.com/fraud-loss-index ## Definitions (18) Canonical glossary: https://getcoffr.com/glossary - **Business email compromise** (BEC, email account compromise, EAC, CEO fraud): Business email compromise is a fraud in which an attacker uses a real or spoofed business email account to convince someone with payment authority to send funds or change bank details for a legitimate obligation. Source page: https://getcoffr.com/glossary/business-email-compromise - **Vendor impersonation fraud** (supplier fraud, invoice redirection, payment diversion fraud): Vendor impersonation fraud is an attack in which a criminal poses as an existing supplier and submits new banking details so that legitimate invoice payments are redirected to an account they control. Source page: https://getcoffr.com/glossary/vendor-impersonation - **Account takeover** (ATO, corporate account takeover): Account takeover is unauthorized control of a legitimate account, such as an online banking profile or a business mailbox, which the attacker then uses to move money or manipulate payment instructions from inside a trusted identity. Source page: https://getcoffr.com/glossary/account-takeover - **Check fraud** (cheque fraud, check washing, altered check): Check fraud is the theft, alteration, forgery, or counterfeiting of a paper check in order to obtain funds from the account it draws on. Source page: https://getcoffr.com/glossary/check-fraud - **Authorized push payment fraud** (APP fraud, authorized fraud, scam payment): Authorized push payment fraud is any scam in which the victim is deceived into personally instructing a payment to an account controlled by a criminal, meaning the transfer is technically authorized and therefore rarely reversible. Source page: https://getcoffr.com/glossary/authorized-push-payment-fraud - **Wire transfer** (Fedwire, CHIPS, funds transfer): A wire transfer is a real time, credit push transfer of funds between banks that settles with finality, meaning it cannot be unilaterally reversed once the receiving bank accepts it. Source page: https://getcoffr.com/glossary/wire-transfer - **ACH** (Automated Clearing House, ACH credit, ACH debit, direct deposit): ACH is the batch based Automated Clearing House network used in the United States for direct deposits, vendor payments, and recurring debits, governed by the Nacha operating rules. Source page: https://getcoffr.com/glossary/ach - **RTP and FedNow** (instant payments, real time payments, RTP network): RTP and FedNow are the two United States instant payment rails that settle credit transfers in seconds, around the clock, with immediate finality for the receiving party. Source page: https://getcoffr.com/glossary/rtp-and-fednow - **Callback verification** (verbal callback, call back control, voice verification): Callback verification is the control of confirming a payment instruction or a bank detail change by telephoning the counterparty on a number already held on file, never a number supplied in the request itself. Source page: https://getcoffr.com/glossary/callback-verification - **Out of band verification** (OOB verification, second channel verification): Out of band verification confirms a request over a channel entirely separate from the one that carried it, so that compromise of a single channel cannot both make and confirm the request. Source page: https://getcoffr.com/glossary/out-of-band-verification - **Positive pay** (ACH positive pay, payee positive pay, reverse positive pay): Positive pay is a bank service in which the company sends the bank a file of issued payments so the bank can reject any item that does not match, most commonly used for checks and increasingly for ACH debits. Source page: https://getcoffr.com/glossary/positive-pay - **Bank account validation** (account verification, bank account ownership verification, micro deposits): Bank account validation is the process of confirming that a bank account exists, is open, and belongs to the party expected to own it, before that account is used to receive funds. Source page: https://getcoffr.com/glossary/account-validation - **Vendor master data** (supplier master file, vendor master file, vendor record): Vendor master data is the stored record of each supplier, including legal name, tax identifier, contacts, and remittance bank details, that a payment system reads when it pays an invoice. Source page: https://getcoffr.com/glossary/vendor-master-data - **Segregation of duties** (separation of duties, SoD, dual control, maker checker): Segregation of duties is the control principle that no single person can both create and approve a payment or a change to payment data, so that one compromised or coerced individual cannot complete a fraudulent transaction alone. Source page: https://getcoffr.com/glossary/segregation-of-duties - **UCC Article 4A** (Article 4A, UCC 4A, funds transfer law): UCC Article 4A is the body of United States commercial law that governs funds transfers between businesses and allocates loss from unauthorized payment orders based on whether a commercially reasonable security procedure was agreed and followed. Source page: https://getcoffr.com/glossary/uniform-commercial-code-4a - **Regulation E** (Reg E, 12 CFR Part 1005, Electronic Fund Transfer Act): Regulation E implements the Electronic Fund Transfer Act and gives consumers, not businesses, defined error resolution rights and liability limits for unauthorized electronic fund transfers from their accounts. Source page: https://getcoffr.com/glossary/regulation-e - **Suspicious activity report** (SAR, BSA reporting): A suspicious activity report is a confidential filing that financial institutions submit to FinCEN when a transaction is suspected to involve fraud or other illicit activity, under the Bank Secrecy Act. Source page: https://getcoffr.com/glossary/suspicious-activity-report - **Recovery Asset Team** (RAT, IC3 RAT, Financial Fraud Kill Chain): The Recovery Asset Team is the FBI IC3 unit that coordinates with receiving financial institutions to freeze funds from fraudulent domestic wire transfers reported quickly enough to intervene. Source page: https://getcoffr.com/glossary/recovery-asset-team ## Published research (14) - [Spend the fraud budget where it can still stop a payment, not after it's too late](https://getcoffr.com/insights/your-ai-bec-security-budget-has-to-name-the-wire) (2026-08-14, Wire fraud): New cyber spend should map to vendor changes, executive instructions, help desk resets, and payment file release controls. Markdown: https://getcoffr.com/llms/insights/your-ai-bec-security-budget-has-to-name-the-wire - [Your BEC wire recovery evidence has a deadline. Ensure you meet it.](https://getcoffr.com/insights/your-bec-wire-recovery-evidence-has-one-quiet-deadline) (2026-08-14, Wire fraud): What finance should preserve before calling the bank, law enforcement, or insurer after a suspected fraud payment. Markdown: https://getcoffr.com/llms/insights/your-bec-wire-recovery-evidence-has-one-quiet-deadline - [Even if a bank adds scam warnings, biometrics and extra friction, corporate BEC payment controls still have to prove the changed payee before release.](https://getcoffr.com/insights/corporate-bec-payment-controls-proved-the-login-not-the-payee) (2026-08-14, Architecture): Bank warnings and authentication cannot prove vendor instruction provenance when AP changes a payee, mandate or rail. Markdown: https://getcoffr.com/llms/insights/corporate-bec-payment-controls-proved-the-login-not-the-payee - [After a BEC wire loss, you risk a second incident while under investigation](https://getcoffr.com/insights/your-bec-recovery-scam-controls-trust-the-case-number) (2026-08-14, Wire fraud): After a wire loss, companies need named owners and proof rules before anyone sends money, credentials, or documents to a claimed helper. Markdown: https://getcoffr.com/llms/insights/your-bec-recovery-scam-controls-trust-the-case-number - [Your loyalty payment fraud control looked for the wrong file. Now what?](https://getcoffr.com/insights/your-loyalty-payment-fraud-controls-are-looking-in-the-wrong-file) (2026-08-14, Payments infrastructure): Finance teams should test profile edits, device binding, tender switching, and refund routing before a clean refund reaches settlement. Markdown: https://getcoffr.com/llms/insights/your-loyalty-payment-fraud-controls-are-looking-in-the-wrong-file - [Whoever gives the final "go" to release a payment needs to be approving the payment method that's actually being used](https://getcoffr.com/insights/where-multi-rail-payment-fraud-controls-should-sit) (2026-08-13, Payments infrastructure): Payment hub fraud controls need authority evidence at final release when routing moves a payable across rails. Markdown: https://getcoffr.com/llms/insights/where-multi-rail-payment-fraud-controls-should-sit - [The capital call was right. The bank account was not. Now what?](https://getcoffr.com/insights/private-credit-capital-call-fraud-sits-in-the-notice) (2026-08-11, Wire fraud): How treasury should verify capital calls, payoff letters, fee demands, and account changes before releasing private credit wires. Markdown: https://getcoffr.com/llms/insights/private-credit-capital-call-fraud-sits-in-the-notice - [You cleared the file. You did not prove the payee. Now what?](https://getcoffr.com/insights/your-payment-file-fraud-investigation-starts-too-late) (2026-08-11, Vendor risk): Release packets prove payee authority by preserving ownership checks, exception approvals, and payment instruction verification before settlement. Markdown: https://getcoffr.com/llms/insights/your-payment-file-fraud-investigation-starts-too-late - [Payment vendor acquisition controls still trust outdated tools.](https://getcoffr.com/insights/the-payment-vendor-acquisition-controls-still-trust-the-old-tool) (2026-08-11, Vendor risk): When a fraud tool changes owners, treasury must retest roles, tokens, alert labels, case IDs, retention, and SOC scope before payment release. Markdown: https://getcoffr.com/llms/insights/the-payment-vendor-acquisition-controls-still-trust-the-old-tool - [AI agent payment controls should require a close file that proves the named customer authorized the specific invoice before release](https://getcoffr.com/insights/ai-agent-payment-controls-are-not-the-receipt) (2026-08-11, Payments infrastructure): Coinbase can accept payments from agents, but AR still needs customer authority, invoice intent, wallet ownership, refunds, and screening. Markdown: https://getcoffr.com/llms/insights/ai-agent-payment-controls-are-not-the-receipt - [You secured the rail. The instruction stayed open.](https://getcoffr.com/insights/payments-trust-layer-architecture) (2026-07-02, Architecture): Payments moved faster than verification. A look at Layer 2, the trust and verification gap the fintech stack never closed. Markdown: https://getcoffr.com/llms/insights/payments-trust-layer-architecture - [You approved the PDF. Nobody verified the bank account](https://getcoffr.com/insights/business-email-compromise-2026) (2026-06-14, Wire fraud): BEC is the costliest form of cybercrime. How one edited PDF or spoofed vendor email redirects a payment, and the controls that stop it. Markdown: https://getcoffr.com/llms/insights/business-email-compromise-2026 - [You approved the vendor. The bank account came with it](https://getcoffr.com/insights/vendor-onboarding-risk) (2026-05-28, Vendor risk): Vendor onboarding is the highest risk window in accounts payable. Where the leaks are in those five minutes, and which controls close them. Markdown: https://getcoffr.com/llms/insights/vendor-onboarding-risk - [The routine ACH file is carrying more fraud than the wire](https://getcoffr.com/insights/ach-vs-wire-fraud) (2026-05-09, Payments infrastructure): Wires feel high risk and ACH feels routine. The fraud data says otherwise. A rail by rail look at where the losses actually land. Markdown: https://getcoffr.com/llms/insights/ach-vs-wire-fraud