Guide · Wire & Payment Fraud

Wire Transfer Fraud Prevention: 10 Red Flags Before You Send (2026)

July 2026 AP Clerks Bookkeepers Small Business 9 min read

Wire transfer fraud cost US businesses $3.046 billion in 2025 — and the problem is getting worse. Unlike ACH payments, wires have no built-in reversal mechanism. Once the money leaves your account, recovery depends entirely on how quickly you act and whether the receiving bank can freeze the funds before the attacker moves them. The FBI's Financial Fraud Kill Chain reported a 58% success rate freezing stolen wires in 2025 — but that rate depends entirely on reporting fast, and collapses within hours of the funds moving. This guide covers the 10 red flags to check before every wire, and the verification steps that stop the most common attacks before they cost you anything.

$3B
in BEC losses in 2025 — 86% transmitted via wire transfer or ACH — FBI IC3 2025 Annual Report
72 hrs
wire recall success rate — the FBI's Financial Fraud Kill Chain froze 58% of attempted theft in 2025 when reported quickly
26%
year-over-year increase in total cybercrime losses in 2025 — the highest annual figure in IC3's 25-year history
⚠️ Why wires are different from ACH

ACH payments can be returned within a defined window — typically 24 hours for unauthorized debits. Wire transfers have no equivalent mechanism. Once sent, reversal requires cooperation from the receiving bank and is never guaranteed. This makes the verification step before sending a wire the only reliable control. There is no meaningful recovery process to fall back on.

How Wire Transfer Fraud Works

Most wire fraud follows the same basic pattern: an attacker convinces someone with wire authorization to send money to an account they control, disguised as a legitimate payment. The disguise varies — a vendor invoice, a CEO request, a banking change notice — but the mechanism is almost always the same: a spoofed or compromised email with fraudulent wire instructions.

Attack type How it works The tell
Vendor impersonation Attacker spoofs or compromises a vendor's email and sends new wire instructions Routing or account number differs from your vendor file
CEO / executive fraud Email impersonating the CEO or CFO requests an urgent, confidential wire transfer Urgency, secrecy, and an email-only request with no prior relationship to the payee
Banking detail change An email "from" a known vendor requests a bank account update before the next payment Request arrived only by email, often with a new phone number to call for verification
Fake invoice from a new vendor A professional-looking invoice arrives from an unknown vendor for services that may or may not have been ordered No purchase order, no prior relationship, and bank details that can't be verified against a vendor file
Real estate wire fraud Attacker intercepts a closing email and substitutes fraudulent wire instructions for the title company or escrow agent Last-minute change to wire instructions, often with urgency to close on time

10 Wire Transfer Fraud Red Flags

Check these before every wire above your normal threshold — especially for new payees, changed banking details, or requests that arrived only by email.

1
Routing or account number changed from your vendor file
Critical

Any wire instruction that uses a different routing number or account number than the one already in your vendor file is the highest-risk signal in AP fraud. This is the core mechanism of vendor impersonation and banking detail change attacks — the invoice or email looks legitimate, but the money goes somewhere else.

What to look for
Routing number on the invoice: 021000021 — but your vendor file shows 021000089 for this payee.
Match confirmed: routing number matches your file exactly, no change since last payment.
Defense → Compare every wire's routing and account number against your vendor file before initiating. Any discrepancy requires a voice callback to a number already in your records — not one from the invoice.
2
Routing number fails ABA checksum validation
Critical

Every legitimate US routing number passes a mathematical checksum defined by the American Bankers Association. A routing number that fails this check cannot be a real bank routing number — it's either fabricated or contains a typo introduced by a fraudster. This is a hard stop before any wire is initiated.

Common fraud pattern
Routing number 000000001 on an invoice — fails ABA checksum, cannot be a legitimate routing number. Frequently seen in fraudulent wire instructions.
Defense → Validate the routing number before initiating any wire. PaySentinel validates ABA checksum automatically when you paste a routing number into the transaction or invoice check.
3
Banking change request arrived only by email
Critical

Legitimate vendors can always provide bank detail changes through a phone call or a documented process. An email-only banking change request — with no prior phone call, no documentation, and no second channel — is a red flag regardless of how the email looks. Attackers rely on the fact that most AP processes treat a professional-looking email as sufficient authorization.

Red flag wording
"Please update our banking details for future payments. New routing: XXXXXXX, Account: XXXXXXX. Please confirm by reply."
Defense → Treat all email-only banking change requests as unverified. Call the vendor at a number from your existing records and confirm verbally before updating anything in your system.
4
Urgency or confidentiality language
Critical

"Process today or we lose the deal." "This is confidential — do not discuss with anyone else." "Wire must go out before end of business." Urgency and secrecy are deliberate social engineering tactics, not coincidental features of a legitimate payment request. They're designed to pressure the AP person into bypassing the verification steps that would catch the fraud.

Classic CEO fraud wording
"I need you to process a wire transfer urgently. This is time-sensitive and confidential — please don't discuss with anyone until it's done."
Defense → Treat urgency and confidentiality language as a reason to slow down, not speed up. No legitimate payment request requires bypassing normal verification.
5
Sender email domain doesn't match known vendor domain
High

Wire fraud emails frequently arrive from lookalike domains — addresses visually similar to a real vendor but with a subtle difference: an extra letter, a different TLD, or a character substitution. The sender name may appear correct while the actual domain is fraudulent. This is particularly effective because most email clients display the sender name prominently and the domain address less visibly.

Lookalike domain examples
billing@northgate-it-solutions.net (vendor's real domain: northgateit.com)
accounts@acme-corp.co (vendor's real domain: acmecorp.com)
Defense → Check the full sender email address — not just the display name — against your vendor file before acting on any wire instruction. A single character difference means a different domain.
6
Wire instructions for a new or unverified payee
High

Any wire to a payee who isn't already in your vendor file — or who was added recently without full verification — carries significantly higher risk than a payment to an established vendor. Fraudsters use new vendor setup as a cover for ghost vendor schemes, and first payments to new accounts are the most common point of loss in AP fraud.

What to verify before a first wire
New vendor added last week, bank details provided only by email, no PO on file, first invoice above $10,000.
Vendor verified: business address confirmed, phone number called and answered, tax ID validated, PO on file.
Defense → Apply full vendor verification — business address, phone, tax ID — before the first wire to any new payee, regardless of invoice amount.
7
Wire instruction arrived without a matching purchase order
High

A wire instruction — or the invoice behind it — that has no corresponding purchase order is missing the most basic authorization trail. PO matching is the primary control that prevents fraudulent invoices from reaching the payment stage. Its absence doesn't confirm fraud, but it means the payment has no verified authorization in your system.

Defense → Require a PO match before any wire is initiated. Invoices or wire requests without a matching PO go to a hold queue for manual review, not to payment.
8
Wire to a personal account or non-business bank
High

Routing numbers identify the receiving bank, and some routing numbers are associated with consumer banks, prepaid card providers, or payment apps rather than commercial banking institutions. A vendor invoice routing to a personal bank account rather than a business bank account is a significant mismatch that warrants investigation before payment.

What this looks like
Invoice from "Premier Consulting LLC" with wire instructions routing to a consumer banking app or prepaid card provider.
Defense → Verify that the receiving bank matches the type of account you'd expect for this vendor. PaySentinel identifies the bank associated with any routing number as part of the transaction check.
9
International wire for a domestic vendor relationship
High

A domestic vendor relationship that suddenly requires an international wire transfer is a significant pattern break. International wires are far harder to reverse and recover than domestic ones — funds leaving US banking rails have limited recourse and can be nearly impossible to freeze once they reach foreign banks. Fraudsters specifically use international wire instructions because the recovery window is effectively zero.

Defense → Any request to wire internationally for a vendor you've previously paid domestically requires an independent phone verification before proceeding. Treat it as equivalent to a banking detail change — because it is one.
10
Round-number wire amount for a service invoice
Medium

Fraudulent invoices frequently use round numbers — $10,000, $25,000, $50,000 — because the attacker is setting a target amount rather than billing for actual services. Legitimate service invoices almost always include hourly rates, itemized line items, or project fees that produce non-round totals. A perfectly round number on an invoice for intangible services is a prompt to look more closely at the invoice's other details.

Lower risk vs. higher risk
Invoice total: $12,437.50 — based on 47.5 hours at $261.84/hr with itemized expenses.
Invoice total: $25,000.00 — "Consulting services, Q3" with no itemization.
Defense → Request itemized documentation for any round-number invoice above your threshold, particularly for intangible services where delivery can't be physically confirmed.
About to send a wire and something feels off? Check the routing number, vendor, and invoice details through PaySentinel before initiating — free, under a minute.
Check it now →

Verification Steps Before Every Wire

The single most effective wire fraud prevention measure is a structured pre-payment verification process. These are the steps that stop fraud independent of how convincing the email, invoice, or wire instruction looks.

If You Already Sent a Fraudulent Wire

Recovery is a race. In 2025, the FBI's Financial Fraud Kill Chain processed 3,900 wire fraud incidents involving $1.163 billion in attempted theft, and froze $679 million of it — a 58% success rate. After the recovery window closes, funds are typically split across multiple accounts, moved offshore, or converted to cryptocurrency, and the success rate collapses toward zero.

What's the actual wire transfer recall success rate?

The Financial Fraud Kill Chain's formal policy allows a 72-hour reporting window, but that's the outer edge, not the target. The real determinant of success is how much of that window is still open when your bank and the FBI actually act — stolen funds typically move out of the initial receiving account within hours, not days. Investigators' practical guidance is tighter than the formal policy: report within 48 hours, ideally the same day, for a realistic shot at recovery. Wires that stay within the US banking system and get reported same-day see meaningfully better outcomes than the 58% headline figure; wires that have already crossed into international accounts or cryptocurrency by the time they're reported rarely come back at all.

In short: the "success rate" isn't one fixed number — it's a curve that drops sharply with every hour of delay. Treat 58% as the ceiling for funds reported promptly within the US banking system, not a guarantee, and act as if every minute counts, because it does.

Timeframe What to do Recovery outlook
First hour Call your bank immediately — request a wire recall and fraud freeze on the receiving account Best chance — funds may still be in the receiving account
Hours 1–24 File an IC3 complaint at ic3.gov to activate the FBI's Financial Fraud Kill Chain Good — FBI can work with receiving bank to freeze funds
Hours 24–72 Preserve all documentation — emails, wire instructions, transaction records Declining — funds may have moved to secondary accounts
After 72 hours Engage legal counsel — recovery may require civil proceedings or insurance claims Low — funds likely moved offshore or converted to crypto
The Financial Fraud Kill Chain

When you file an IC3 complaint, the FBI's Recovery Asset Team can initiate a Financial Fraud Kill Chain — a process that contacts the receiving bank directly and requests a freeze on the account before funds are moved. This process is time-sensitive and only works while the funds are still in the initial receiving account. Filing immediately, before contacting anyone else other than your bank, maximizes the chance of activation.

What a Pre-Payment Check Catches

Signal How PaySentinel checks it Type
Routing number validityABA checksum validation before any wire is initiated Every routing number is validated against the ABA checksum algorithm — invalid numbers are flagged immediately Mechanical
Routing number mismatchChanged bank detail on a known vendor Compared against your prior payment history for this vendor — any change is flagged for verification Mechanical
Receiving bank identificationWhether the routing number routes to a commercial bank Bank name and type identified from the routing number — personal accounts and payment apps flagged Mechanical
Vendor domainLookalike or spoofed sender domain on the wire request Checked against the vendor's known domain for typosquatting patterns and character substitutions Mechanical
Urgency & BEC languagePressure tactics designed to bypass verification Flagged against BEC and social engineering language patterns from real fraud investigation workflows AI-assisted

Frequently Asked Questions

Can a wire transfer be reversed?

Wire transfers are not automatically reversible. Recovery depends on how quickly you act and whether the receiving bank can freeze the funds before they are moved. The FBI's Financial Fraud Kill Chain reported a 58% success rate freezing stolen funds in 2025 — but that rate collapses fast after the initial window closes as funds are split, moved offshore, or converted to cryptocurrency.

Contact your bank immediately and file an IC3 complaint at ic3.gov if you suspect a fraudulent wire.

What is the most common wire transfer fraud scheme?

Business email compromise (BEC) is the most common vector for wire transfer fraud. In 2025, BEC generated $3.046 billion in reported losses to the FBI's IC3, with 86% of those losses transmitted via wire transfer or ACH. The most common BEC pattern targeting wire payments is vendor impersonation — an attacker spoofs or compromises a vendor's email and instructs AP to send a payment to a new bank account.

How do you verify a wire transfer request?

Before sending any wire, verify the request by calling the payee at a phone number from your own records — not a number provided in the wire instructions or the email requesting the transfer. Confirm the routing and account number match your vendor file. If any banking detail has changed, treat the change request as unverified until you have spoken directly with the vendor.

How long does wire transfer fraud recovery take?

Recovery timelines vary significantly by how quickly the fraud is reported. Acting fast gives the best chance — the FBI's Financial Fraud Kill Chain reported a 58% success rate freezing stolen funds in 2025, and investigators' real-world guidance favors reporting within 48 hours rather than waiting out the full 72-hour policy window. Past that point, funds are often split across multiple accounts, moved offshore, or converted to cryptocurrency, and recovery extends into legal proceedings that can take 30 to 90 days or longer with significantly lower success rates.

What should I do immediately after sending a fraudulent wire?

Contact your bank immediately to request a wire recall — every minute matters. Then file a complaint with the FBI's Internet Crime Complaint Center at ic3.gov to activate the Financial Fraud Kill Chain, which can freeze funds at the receiving bank. Preserve all emails, wire instructions, and documentation. Do not contact the fraudster directly.

Check a wire before it goes out

Paste the routing number, vendor name, or wire instructions into PaySentinel for a risk score and red flag breakdown in under a minute. Free to start, no account required.

Run a free check →