Wire Transfer Fraud Prevention: 10 Red Flags Before You Send (2026)
Wire transfer fraud cost US businesses $3.046 billion in 2025 — and the problem is getting worse. Unlike ACH payments, wires have no built-in reversal mechanism. Once the money leaves your account, recovery depends entirely on how quickly you act and whether the receiving bank can freeze the funds before the attacker moves them. The FBI's Financial Fraud Kill Chain reported a 58% success rate freezing stolen wires in 2025 — but that rate depends entirely on reporting fast, and collapses within hours of the funds moving. This guide covers the 10 red flags to check before every wire, and the verification steps that stop the most common attacks before they cost you anything.
ACH payments can be returned within a defined window — typically 24 hours for unauthorized debits. Wire transfers have no equivalent mechanism. Once sent, reversal requires cooperation from the receiving bank and is never guaranteed. This makes the verification step before sending a wire the only reliable control. There is no meaningful recovery process to fall back on.
How Wire Transfer Fraud Works
Most wire fraud follows the same basic pattern: an attacker convinces someone with wire authorization to send money to an account they control, disguised as a legitimate payment. The disguise varies — a vendor invoice, a CEO request, a banking change notice — but the mechanism is almost always the same: a spoofed or compromised email with fraudulent wire instructions.
| Attack type | How it works | The tell |
|---|---|---|
| Vendor impersonation | Attacker spoofs or compromises a vendor's email and sends new wire instructions | Routing or account number differs from your vendor file |
| CEO / executive fraud | Email impersonating the CEO or CFO requests an urgent, confidential wire transfer | Urgency, secrecy, and an email-only request with no prior relationship to the payee |
| Banking detail change | An email "from" a known vendor requests a bank account update before the next payment | Request arrived only by email, often with a new phone number to call for verification |
| Fake invoice from a new vendor | A professional-looking invoice arrives from an unknown vendor for services that may or may not have been ordered | No purchase order, no prior relationship, and bank details that can't be verified against a vendor file |
| Real estate wire fraud | Attacker intercepts a closing email and substitutes fraudulent wire instructions for the title company or escrow agent | Last-minute change to wire instructions, often with urgency to close on time |
10 Wire Transfer Fraud Red Flags
Check these before every wire above your normal threshold — especially for new payees, changed banking details, or requests that arrived only by email.
Any wire instruction that uses a different routing number or account number than the one already in your vendor file is the highest-risk signal in AP fraud. This is the core mechanism of vendor impersonation and banking detail change attacks — the invoice or email looks legitimate, but the money goes somewhere else.
Every legitimate US routing number passes a mathematical checksum defined by the American Bankers Association. A routing number that fails this check cannot be a real bank routing number — it's either fabricated or contains a typo introduced by a fraudster. This is a hard stop before any wire is initiated.
Legitimate vendors can always provide bank detail changes through a phone call or a documented process. An email-only banking change request — with no prior phone call, no documentation, and no second channel — is a red flag regardless of how the email looks. Attackers rely on the fact that most AP processes treat a professional-looking email as sufficient authorization.
"Process today or we lose the deal." "This is confidential — do not discuss with anyone else." "Wire must go out before end of business." Urgency and secrecy are deliberate social engineering tactics, not coincidental features of a legitimate payment request. They're designed to pressure the AP person into bypassing the verification steps that would catch the fraud.
Wire fraud emails frequently arrive from lookalike domains — addresses visually similar to a real vendor but with a subtle difference: an extra letter, a different TLD, or a character substitution. The sender name may appear correct while the actual domain is fraudulent. This is particularly effective because most email clients display the sender name prominently and the domain address less visibly.
Any wire to a payee who isn't already in your vendor file — or who was added recently without full verification — carries significantly higher risk than a payment to an established vendor. Fraudsters use new vendor setup as a cover for ghost vendor schemes, and first payments to new accounts are the most common point of loss in AP fraud.
A wire instruction — or the invoice behind it — that has no corresponding purchase order is missing the most basic authorization trail. PO matching is the primary control that prevents fraudulent invoices from reaching the payment stage. Its absence doesn't confirm fraud, but it means the payment has no verified authorization in your system.
Routing numbers identify the receiving bank, and some routing numbers are associated with consumer banks, prepaid card providers, or payment apps rather than commercial banking institutions. A vendor invoice routing to a personal bank account rather than a business bank account is a significant mismatch that warrants investigation before payment.
A domestic vendor relationship that suddenly requires an international wire transfer is a significant pattern break. International wires are far harder to reverse and recover than domestic ones — funds leaving US banking rails have limited recourse and can be nearly impossible to freeze once they reach foreign banks. Fraudsters specifically use international wire instructions because the recovery window is effectively zero.
Fraudulent invoices frequently use round numbers — $10,000, $25,000, $50,000 — because the attacker is setting a target amount rather than billing for actual services. Legitimate service invoices almost always include hourly rates, itemized line items, or project fees that produce non-round totals. A perfectly round number on an invoice for intangible services is a prompt to look more closely at the invoice's other details.
Verification Steps Before Every Wire
The single most effective wire fraud prevention measure is a structured pre-payment verification process. These are the steps that stop fraud independent of how convincing the email, invoice, or wire instruction looks.
- Compare routing and account numbers against your vendor file — any discrepancy is a stop, not a flag to note and proceed anyway
- Validate the routing number — confirm it passes ABA checksum and corresponds to a legitimate commercial bank
- Verify the sender email domain — compare the full address against your vendor file, not just the display name
- Confirm a matching purchase order exists — no PO means a hold for manual review before payment
- Call the vendor at a known number — use a number from your own records, not one provided in the wire instructions or the email
- Get dual authorization — a second approver independent of the first for any wire above your threshold
- Run a pre-payment fraud check — submit the vendor and routing details through PaySentinel and document the result
If You Already Sent a Fraudulent Wire
Recovery is a race. In 2025, the FBI's Financial Fraud Kill Chain processed 3,900 wire fraud incidents involving $1.163 billion in attempted theft, and froze $679 million of it — a 58% success rate. After the recovery window closes, funds are typically split across multiple accounts, moved offshore, or converted to cryptocurrency, and the success rate collapses toward zero.
What's the actual wire transfer recall success rate?
The Financial Fraud Kill Chain's formal policy allows a 72-hour reporting window, but that's the outer edge, not the target. The real determinant of success is how much of that window is still open when your bank and the FBI actually act — stolen funds typically move out of the initial receiving account within hours, not days. Investigators' practical guidance is tighter than the formal policy: report within 48 hours, ideally the same day, for a realistic shot at recovery. Wires that stay within the US banking system and get reported same-day see meaningfully better outcomes than the 58% headline figure; wires that have already crossed into international accounts or cryptocurrency by the time they're reported rarely come back at all.
In short: the "success rate" isn't one fixed number — it's a curve that drops sharply with every hour of delay. Treat 58% as the ceiling for funds reported promptly within the US banking system, not a guarantee, and act as if every minute counts, because it does.
| Timeframe | What to do | Recovery outlook |
|---|---|---|
| First hour | Call your bank immediately — request a wire recall and fraud freeze on the receiving account | Best chance — funds may still be in the receiving account |
| Hours 1–24 | File an IC3 complaint at ic3.gov to activate the FBI's Financial Fraud Kill Chain | Good — FBI can work with receiving bank to freeze funds |
| Hours 24–72 | Preserve all documentation — emails, wire instructions, transaction records | Declining — funds may have moved to secondary accounts |
| After 72 hours | Engage legal counsel — recovery may require civil proceedings or insurance claims | Low — funds likely moved offshore or converted to crypto |
When you file an IC3 complaint, the FBI's Recovery Asset Team can initiate a Financial Fraud Kill Chain — a process that contacts the receiving bank directly and requests a freeze on the account before funds are moved. This process is time-sensitive and only works while the funds are still in the initial receiving account. Filing immediately, before contacting anyone else other than your bank, maximizes the chance of activation.
What a Pre-Payment Check Catches
| Signal | How PaySentinel checks it | Type |
|---|---|---|
| Routing number validityABA checksum validation before any wire is initiated | Every routing number is validated against the ABA checksum algorithm — invalid numbers are flagged immediately | Mechanical |
| Routing number mismatchChanged bank detail on a known vendor | Compared against your prior payment history for this vendor — any change is flagged for verification | Mechanical |
| Receiving bank identificationWhether the routing number routes to a commercial bank | Bank name and type identified from the routing number — personal accounts and payment apps flagged | Mechanical |
| Vendor domainLookalike or spoofed sender domain on the wire request | Checked against the vendor's known domain for typosquatting patterns and character substitutions | Mechanical |
| Urgency & BEC languagePressure tactics designed to bypass verification | Flagged against BEC and social engineering language patterns from real fraud investigation workflows | AI-assisted |
Frequently Asked Questions
Wire transfers are not automatically reversible. Recovery depends on how quickly you act and whether the receiving bank can freeze the funds before they are moved. The FBI's Financial Fraud Kill Chain reported a 58% success rate freezing stolen funds in 2025 — but that rate collapses fast after the initial window closes as funds are split, moved offshore, or converted to cryptocurrency.
Contact your bank immediately and file an IC3 complaint at ic3.gov if you suspect a fraudulent wire.
Business email compromise (BEC) is the most common vector for wire transfer fraud. In 2025, BEC generated $3.046 billion in reported losses to the FBI's IC3, with 86% of those losses transmitted via wire transfer or ACH. The most common BEC pattern targeting wire payments is vendor impersonation — an attacker spoofs or compromises a vendor's email and instructs AP to send a payment to a new bank account.
Before sending any wire, verify the request by calling the payee at a phone number from your own records — not a number provided in the wire instructions or the email requesting the transfer. Confirm the routing and account number match your vendor file. If any banking detail has changed, treat the change request as unverified until you have spoken directly with the vendor.
Recovery timelines vary significantly by how quickly the fraud is reported. Acting fast gives the best chance — the FBI's Financial Fraud Kill Chain reported a 58% success rate freezing stolen funds in 2025, and investigators' real-world guidance favors reporting within 48 hours rather than waiting out the full 72-hour policy window. Past that point, funds are often split across multiple accounts, moved offshore, or converted to cryptocurrency, and recovery extends into legal proceedings that can take 30 to 90 days or longer with significantly lower success rates.
Contact your bank immediately to request a wire recall — every minute matters. Then file a complaint with the FBI's Internet Crime Complaint Center at ic3.gov to activate the Financial Fraud Kill Chain, which can freeze funds at the receiving bank. Preserve all emails, wire instructions, and documentation. Do not contact the fraudster directly.
Check a wire before it goes out
Paste the routing number, vendor name, or wire instructions into PaySentinel for a risk score and red flag breakdown in under a minute. Free to start, no account required.
Run a free check →