Construction Invoice Fraud: How the Scam Works and How to Stop It
Learn how construction invoice fraud works and the steps AEC firms can take to stop payment scams before funds are lost.

An accounts payable person at your architecture firm receives an email from a subcontractor who just finished work on your Manhattan high-rise project, asking to update their bank details before the next progress payment goes out. The sender address looks right, the signature matches, and the thread includes real invoice numbers. Construction invoice fraud is a payment scam where a criminal poses as a trusted vendor, subcontractor, or client contact to redirect a legitimate payment to an account they control, most often through a compromised or impersonated email account. This scheme targets architecture, engineering and construction firms because project payments move through long chains, and a single weak link can divert six figures before anyone notices.
Construction invoice fraud succeeds when project teams treat a payment change as routine. The rest of this article breaks down how the scam works and the three-layer defense that stops it: email security that reduces the chance of a compromised account, a verification step that confirms any change through a second channel, and training for everyone who touches payments.
Key Takeaways
- Construction invoice fraud redirects payments through compromised or impersonated email accounts posing as vendors or subcontractors
- Preventing losses requires combining email security, mandatory verification of payment changes through a second channel, and training for all staff who handle invoices
- Once a fraudulent payment is sent, contacting your bank and reporting the incident within hours is the most critical response step
What Is Construction Invoice Fraud

Construction invoice fraud is a payment scam in which a criminal impersonates a legitimate subcontractor, supplier, consultant or even a project owner to redirect funds into an account the fraudster controls. Unlike routine disputes over quantities or approved change orders, invoice fraud involves deliberate deception and typically relies on compromised or spoofed email to insert fake payment instructions into an otherwise legitimate transaction.
How Invoice Fraud Differs From Ordinary Billing Disputes
Billing disputes are part of normal project operations. Your project manager might question a subcontractor invoice because the work hasn't been inspected yet, or your accounting staff might flag a duplicate line item on a supplier's draw request. Those conversations happen out in the open, and both parties have documentation to support their position.
Invoice fraud operates differently. The fraudster inserts themselves into an existing payment workflow, often by compromising an email account or creating a nearly identical address. You receive what looks like a routine update from your electrical subcontractor asking you to send the next payment to a new account. The email sits in the same thread you've been using for months. The tone matches. The signature block looks right. But the bank details now point to an account the scammer opened last week.
The distinction matters because your accounts payable procedures for handling a pricing disagreement won't catch a payment redirect scam. A billing dispute triggers a phone call to the PM or a review of the contract schedule of values. A fraudulent bank-detail change often sails through because it looks like administrative housekeeping rather than a claim requiring technical review.
The Roles Involved: Owners, GCs, Subcontractors, Consultants and Suppliers
Construction payments move through multiple parties, and invoice fraud can target any link in that chain. If you're a general contractor, you receive draw requests from the owner and pay subcontractors and suppliers against their invoices and lien waivers. Each of those subcontractors may have their own suppliers and lower-tier subs. Consultants submit invoices for design services, inspections or commissioning work.
Fraudsters exploit this complexity. They might compromise the email account of your HVAC subcontractor and send you revised W-9 and ACH forms. They might spoof the domain of a structural engineer and invoice the owner directly, hoping the owner's accounting staff assumes the GC already approved it. They might impersonate your firm and send a fake invoice to the project owner, redirecting a progress payment before it ever reaches your account.
Each role has different visibility into the payment chain. Your project executive approves the overall draw but may not see individual subcontractor invoices. Your accounts payable staff process payments but may not know which subs are active on which jobs. That gap in visibility is what the fraudster counts on.
Where Invoice Fraud Fits Among Broader Payment and Wire Fraud Schemes
Construction invoice fraud is one form of payment fraud, but the term covers a wider set of scams. Wire fraud includes any scheme that uses electronic communication to redirect funds. Business email compromise is the method behind most construction invoice fraud because project inboxes already contain the exact details a criminal needs: active vendor relationships, payment schedules and ongoing threads about invoices.
Other payment fraud schemes include phishing for bank credentials, fake vendor registration portals and social engineering phone calls that impersonate a project owner's CFO. What sets construction invoice fraud apart is that it hijacks a real transaction rather than inventing one from scratch. The subcontractor invoice is legitimate, the payment amount matches your approved schedule of values, and the only thing that changed is the destination account.
That narrow substitution makes invoice fraud harder to spot than an outright fake invoice for work that was never approved. It also means the window to catch the problem is short. Once your bank processes the wire, recovering the funds depends on how quickly you notice the fraud and contact both your bank and the receiving institution.
How the Scam Works: Anatomy of a Fake Invoice or Payment Redirect

Fraudsters follow a repeatable sequence: they compromise or impersonate a trusted contact, time their request to align with a real payment due date, and redirect the funds to an account they control. Detection gets delayed because the payment looks routine until someone downstream asks why they never received their money.
Step One: Gaining Access to an Inbox or Impersonating a Trusted Sender
The fraudster either takes over a real email account or creates a convincing lookalike domain. Email compromise starts with phishing, where an attacker sends a subcontractor or consultant a credential-harvesting link that appears to be a password reset or document-sharing request. Once they have access to the inbox, they sit quietly and read threads for days or weeks, learning project names, payment schedules, and who approves invoices.
Impersonation is simpler but easier to catch. The fraudster registers a domain that differs by one character from the legitimate vendor, such as replacing an "l" with an "i" or adding an extra letter. They copy the vendor's email signature and reply to an existing thread from the fake address. This works when your accounting staff reviews emails quickly or reads them on a phone where the full sender address is truncated.
Both methods succeed because project teams exchange hundreds of emails about invoices, draw requests, and schedule-of-values updates. One more message about banking details blends in unless someone checks the sender carefully.
Step Two: Timing the Request Around a Real Project Milestone
The fraudster waits until a legitimate payment is due. They monitor threads discussing subcontractor draws, retainage releases, or consultant invoices, and send the fake bank-change request days before the scheduled wire or ACH run. Timing matters because your accounts payable staff expects to process that payment, so a request to update wire instructions feels routine rather than suspicious.
A common scenario involves a subcontractor's monthly draw request. The attacker sees the approved schedule of values and knows the next progress payment is $85,000. Three days before payment is due, an email arrives from what appears to be the subcontractor's project manager, stating that their bank account has changed and providing new routing and account numbers. The email references the correct project name, invoice number, and amount.
Change orders and retainage releases create similar opportunities. Retainage sits on your books for months and releases in a lump sum at substantial completion or final payment, often without the same level of scrutiny applied to monthly draws. The fraudster knows nobody reviews those details closely after months of inactivity.
Step Three: Redirecting Payment to an Account the Fraudster Controls
The email provides updated banking details that route the wire transfer or ACH payment to an account the fraudster opened, often using a shell company name that sounds construction-related. These accounts are opened at institutions with minimal verification requirements or are themselves compromised accounts originally belonging to someone else. The fraudster may use multiple intermediary accounts to move funds quickly and obscure the trail.
Your accounting staff updates the vendor record in your accounting system or forwards the new details to whoever releases payments. If your process lacks a verification step, the payment goes out on schedule. Wire transfers move fastest and are hardest to reverse, which is why attackers prefer them over checks or ACH. Once the wire leaves your account, it typically lands in the fraudulent account within hours.
The payment approval chain usually remains intact. Your project manager approved the original invoice, and the payment amount matches what was approved. The only thing that changed was the destination account, which is a detail that often lives outside the formal approval workflow in your ERP or project management system.
Step Four: Covering Tracks and Delaying Discovery
Fraudsters delay discovery by continuing to monitor the compromised inbox and intercepting any follow-up emails. If the real subcontractor emails your accounts payable staff asking where their payment is, the attacker deletes the message before anyone sees it. They may also send a fake confirmation from the compromised account thanking you for the payment, buying themselves additional days before anyone realizes the money went to the wrong place.
Discovery usually happens when the legitimate vendor calls your project manager or sends a lien notice. By that point, days or weeks have passed since the fraudulent wire cleared. The fraudster has moved the money through multiple accounts or withdrawn it entirely, and your bank's recovery window has closed. The FBI Internet Crime Complaint Center reports billions in annual losses from business email compromise, and the majority involve scenarios where discovery took longer than 24 hours.
Your response time determines your recovery odds. Contacting your bank immediately after discovering the fraud sometimes allows them to recall a wire or freeze a receiving account before funds move again. Waiting until the following business day usually means the money is gone.
Business Email Compromise: The Engine Behind Most Invoice Fraud

Criminals rely on business email compromise because your project inbox already holds everything they need: real vendor names, open invoices, payment schedules, and email threads that everyone on the team recognizes. A hijacked or convincingly spoofed account lets a fraudster drop into an existing conversation and redirect a payment without raising immediate suspicion.
What Business Email Compromise Looks Like in a Project Inbox
Business email compromise in construction typically appears as a message inside an ongoing thread about a legitimate invoice or draw request. The email comes from an address you recognize, such as your MEP subcontractor, a structural engineer, or a materials supplier, and references work that was actually performed.
The message is short and plausible. It tells your accounts payable staff that the vendor has changed banks, updated their payment details, or needs the next progress payment sent to a new account. The invoice number matches your records. The amount is correct. The only thing that changed is the destination account.
This type of fraud works because the email fits the context. Your PM approved the invoice two days earlier. The subcontractor's retainage release is overdue. Your office manager has exchanged a dozen emails with this supplier over the past month. Nothing about the message feels like a generic phishing attempt, because it isn't generic.
Compromised Accounts Versus Lookalike Domains
Business email compromise attacks fall into two categories: compromised accounts and lookalike domains. A compromised email account means the fraudster has the vendor's actual username and password, either through phishing, credential reuse, or malware. When they send an email, it comes from the real address and appears in the same thread history you've been using.
A lookalike domain or spoofed email uses an address that resembles the real one but includes a small change: an extra letter, a different top-level domain, or a substituted character. Instead of [email protected], the fraudster registers [email protected] or [email protected] (with a capital I instead of a lowercase l). These messages arrive as new threads rather than replies, but they mimic the vendor's signature, logo, and tone.
Compromised accounts are harder to detect because the email passes through the vendor's own server and carries all the correct metadata. Lookalike domains can sometimes be spotted by a careful reader, but when your project executive is reviewing payment requests from a truck or your accounts payable clerk is processing thirty invoices in an afternoon, a single-character difference often goes unnoticed.
Why a Real, Hijacked Email Thread Is More Convincing Than a Cold Phishing Email
A hijacked thread carries context that a cold email cannot fake. The fraudster sees the project name, the invoice number, the amount your team already agreed to, and the names of everyone copied on the conversation. When they insert a payment-change request into that thread, it doesn't feel like an intrusion, it feels like the next logical step.
Your accounting staff has no reason to pause. The email address is correct. The thread subject matches the job number in your project management software. The vendor mentioned they were switching banks during last week's coordination call. The reply-to address, the signature block, and the embedded logo all match prior emails from the same sender.
Cold phishing emails, generic messages sent to a broad list, are easier to dismiss because they lack detail. A hijacked thread includes the detail your team relies on to move quickly, and that familiarity is exactly what makes business email compromise effective in construction payment workflows.
Why AEC Firms Are Prime Targets

Architecture, engineering, and construction firms handle large, frequent payments through extended chains of parties who already discuss bank details, dollar amounts and schedules in everyday email threads. Fraudsters exploit these natural workflows because a single weak link anywhere in the chain gives them an opening to redirect funds.
Large Payments Moving Between Many Parties on Every Project
Construction projects involve some of the highest payment values handled by small and mid-sized businesses. A single draw request from a general contractor can exceed six figures. Subcontractor invoices, supplier payments, change order payments and retainage releases all move through accounts payable on overlapping schedules.
Each payment represents a potential target. Fraudsters know that a project executive approving a $200,000 payment to a structural steel supplier this week is likely approving another large payment next week. The volume and value make construction invoice fraud more lucrative than targeting most other industries.
The multi-party structure adds risk. A typical project involves an owner, a general contractor, multiple subcontractors, material suppliers and outside consultants. Each party maintains its own accounting system and email domain. Any compromised inbox in that chain can be used to insert fraudulent wire instructions into an otherwise legitimate payment thread.
Long Subcontractor and Supplier Chains With Inconsistent Security
The subcontractor chain on a commercial project in New York City often extends three or four tiers deep. A general contractor hires a mechanical subcontractor. That subcontractor hires a controls installer. The controls installer orders equipment from a distributor. Each entity exchanges invoices, lien waivers and payment confirmations by email.
Not every firm in that chain maintains the same level of email security. A small specialty subcontractor may lack multi-factor authentication, spam filtering or domain spoofing protections. When a fraudster compromises that subcontractor's email account, they gain access to ongoing threads with the general contractor's accounts payable staff.
The fraudster can then monitor the thread, learn the project schedule and payment terms, and send a message at the right moment requesting updated wire instructions. Your accounting staff sees a familiar email address, a familiar project name and a plausible reason. The payment goes out before anyone realizes the account belongs to a criminal.
Project Emails That Already Discuss Dollar Amounts, Schedules and Bank Details
Construction project inboxes are different from most business email. A typical thread between a project manager and a subcontractor already includes invoice amounts, payment schedules, change order values and references to wire transfers or ACH payments. That same thread may sit in multiple inboxes across the owner, the general contractor, the subcontractor and your firm.
Fraudsters count on this. They do not need to introduce the topic of payments or make an unusual request. They simply need to send one more message in an existing thread. A spoofed or compromised email asking your accounts payable staff to "use the updated W-9 and wire instructions attached" fits naturally into the conversation.
Because legitimate payment changes do happen, especially on longer projects where subcontractors change banks or correct an error in earlier paperwork, your staff cannot assume every request is fraud. The context makes each fraudulent message harder to distinguish from the routine back-and-forth that happens on every job site and in every project coordination thread.
Field and Office Staff Working Across Devices Under Time Pressure
Construction projects operate under tight schedules. A project executive may approve an invoice from a mobile device between job site visits. An office manager may process a supplier payment while coordinating an RFI response and a permit filing. Accounts payable staff handle multiple projects simultaneously, each with its own payment deadlines and documentation requirements.
This time pressure reduces the likelihood that someone will pause to verify a payment change through a second channel. When a request arrives with the subject line of an active project and appears to come from a known contact, the instinct is to process it quickly and move to the next task.
The mix of devices adds another layer of risk. Email viewed on a phone shows fewer visual cues than the same message on a desktop. A spoofed sending address or a slightly altered domain is harder to catch on a small screen. Staff working remotely or from a job site trailer may not have immediate access to the accounting system or the contact information needed to verify a request by phone.
Common Construction Invoice Fraud Scenarios in AEC Projects

Invoice fraud in AEC projects follows predictable patterns because payment chains and approval workflows are similar across firms. The scenarios below describe how criminals exploit specific moments in the payment cycle when verification discipline typically weakens.
The Subcontractor Payment Redirect
A subcontractor completes work, submits a valid invoice through your usual channel, and your project manager approves it. Days before the payment is scheduled to go out, your accounts payable staff receives an email that appears to come from the subcontractor requesting a change to their banking details for this payment.
The email references the correct invoice number, project name, and payment amount. It often includes language about a new business account or a recent bank merger. Because the request arrives after approval but before payment release, it bypasses the normal verification that happens during vendor setup.
Your AP staff updates the wire instructions in the payment batch and releases the funds. The real subcontractor calls a week later asking where their money is. You discover the email came from a nearly identical domain, one letter different from the legitimate one, or from a compromised account the fraudster had been monitoring for weeks.
This variant succeeds because it attacks the window between approval and payment execution. The project manager already vouched for the work and the amount. The office manager or AP specialist processing the wire sees an approved invoice and what looks like routine banking housekeeping.
The Vendor or Supplier Impersonation
A fabricated vendor that never performed work on your project submits an invoice for materials or consulting services. The invoice is coded to a legitimate project, uses language consistent with your scope, and lands in an inbox during a busy billing cycle.
Sometimes the fraudster registers a business name similar to a supplier you actually use. Other times they create a completely new entity and rely on the fact that your vendor roster churns constantly and nobody can remember every name. They may submit a fake W-9, certificate of insurance, and references that look plausible at first glance.
The invoice gets routed to a project manager who assumes another PM brought the vendor on, or who is managing enough scopes that one more materials supplier seems reasonable. Once coded and approved, the payment processes normally. The fraud surfaces weeks or months later during reconciliation, often when the real vendor for that scope bills for the same work or when retainage review reveals a vendor nobody on the project team recognizes.
This scheme exploits high invoice volume and decentralized approval. When project managers approve invoices for their own jobs without a central gatekeeper verifying that the vendor actually exists in the master file, a plausible fake invoice can clear multiple desks.
The Owner or GC Payment Schedule Scheme
On a project where you are the subcontractor, you receive an email that appears to come from the general contractor or owner notifying you of a change to the payment process. The message explains that payments will now be handled by a third-party processor, a new accounting service, or a different department, and provides updated wiring instructions or a link to a payment portal.
The email tone matches prior correspondence, and it arrives around the time you expect a draw request or progress payment to be processed. You update your records and submit your next invoice to the new contact or portal. The payment never arrives. When you follow up with your usual contact at the GC or owner, they have no record of the message or the new process.
This variation works because subcontractors and consultants rarely have direct visibility into their client's internal AP workflows. A notice about a process change feels routine, especially on larger projects where payment administration does shift between departments or gets outsourced. The fraudster only needs access to one email account in the payment chain to send a convincing redirect to everyone downstream.
The Change Order and Draw Request Variant
A fabricated or inflated change order gets submitted for approval, often with documentation that mimics your standard format. The scope description references legitimate conditions, the pricing sits within a range that doesn't trigger automatic escalation, and it may carry a forged signature or be submitted during a period when the responsible PM is off-site or on leave.
Once approved, the change order increases the contract value and flows into your next draw request. Payment processes against the inflated schedule of values, and the overbilling doesn't surface until someone reconciles completed work against payments made. By then, recovery is difficult because the funds left your account weeks ago and the fraudulent vendor, if there was one, has disappeared.
A related variant involves inflated quantities or unit rates on legitimate line items within a progress billing. A subcontractor bills ahead of work in place, counting on the schedule of values being front-loaded and field verification being rushed. If the sub later stalls or exits the project, you've paid for work that doesn't exist, and clawback depends on contract terms and available retainage.
Both versions exploit the fact that change orders legitimately alter contract value mid-project. When documentation looks complete and arrives through normal channels, your approval workflow treats it the same way it treats valid changes. The fraud hides behind the volume and velocity of legitimate scope adjustments.
The Financial and Project Impact When Invoice Fraud Succeeds

When a fraudulent payment leaves your account, the immediate wire transfer is just the beginning of what unfolds. Your firm faces direct cash losses with slim recovery prospects, disputes over who absorbs the cost across the project team, schedule delays as real vendors wait unpaid, and lasting damage to bonding capacity and vendor relationships that affects future work.
Direct Loss of Funds and Limited Recovery Odds
The money typically moves through multiple accounts within hours, often crossing international borders before your accounts payable staff realizes the wire went to the wrong place. Once 24 hours pass, recovery odds drop sharply because fraudulent accounts are emptied and closed quickly.
Most firms recover very little of what they lose to construction invoice fraud, according to reports from the FBI's Internet Crime Complaint Center. Your bank may freeze the receiving account if you report the fraud within minutes to hours, but that window closes fast. The fraudster's bank has no obligation to return funds after the transfer clears, and legal action across state or international lines is slow and expensive.
The loss sits on your books as an expense that still leaves you owing the legitimate vendor. You've now paid twice for the same work: once to the fraudster and again to the subcontractor or supplier who actually delivered materials or labor and still expects payment.
Disputes Between Owner, GC and Subcontractor Over Who Absorbs the Loss
The question of who bears the cost becomes contentious immediately. If your firm is the general contractor and your accounts payable team sent the fraudulent wire, the subcontractor argues they never received payment and are still owed. If you're the sub and the owner or GC was defrauded, they may claim you should have verified the account change or caught the fake email.
Contract language rarely addresses payment fraud explicitly, so each party points to general payment clauses and their own internal controls to argue the other side was negligent. These disputes stall future draw requests, trigger mechanics lien threats, and pull project executives and office managers into meetings with attorneys rather than managing the build.
The owner may withhold retainage or future payments until the dispute resolves. The subcontractor may slow or stop work if they're not made whole. What began as a single fraudulent wire now threatens the schedule and the working relationships that keep the project moving.
Delays to the Project Once a Real Payment Is Also Missed
A subcontractor who hasn't been paid will eventually pause work, and suppliers who haven't received payment for materials will hold the next shipment. Your project manager now faces schedule slippage on critical path items because the steel fabricator or mechanical sub stopped mobilizing.
Change orders and pending invoices pile up as the accounting staff and project executive focus on investigating the fraud, freezing accounts, and working with the bank. Legitimate payments that should flow in the days following the fraud get delayed because your team is distracted and your accounts payable process is frozen pending a full review.
These delays cascade. A two-week pause in rough electrical work pushes drywall, then finishes, then punch list and certificate of occupancy. Liquidated damages clauses may trigger if substantial completion misses the contract date. The project that was tracking on time now carries delay costs and relationship damage that outlast the schedule itself.
Effects on Future Bids, Bonding and Vendor Trust
Surety underwriters review your financials when issuing payment and performance bonds for the next job. A five- or six-figure fraud loss weakens your balance sheet and raises questions about your internal controls, and the surety may reduce your bonding capacity or increase premiums to offset the added risk.
Subcontractors and suppliers talk, and word travels quickly in regional markets like New York City that a firm was compromised. Vendors may demand payment terms you haven't needed before, such as certified funds, progress payments held in escrow, or personal guarantees, because they no longer trust that a wire from your firm will reach the right account.
Your project executive and estimating team face tougher conversations during bid negotiations. Owners and construction managers ask pointed questions about your payment controls and cybersecurity during prequalification, and competitors who haven't suffered a public fraud incident gain an edge. The reputational cost compounds over months and years, affecting work you haven't even bid yet.
Warning Signs Your Team Can Catch Before Payment Goes Out

Most construction invoice fraud reveals itself through small breaks in routine before the payment leaves your account. The four patterns below show up consistently across business email compromise attempts targeting subcontractor payments, draw requests, and change-order invoicing.
Last Minute Changes to Bank Details or Payment Instructions
A bank-detail change that arrives days or hours before a scheduled payment is one of the clearest red flags your accounts payable staff will encounter. Fraudsters time these requests deliberately, betting that the combination of deadline pressure and a familiar project name will push the change through without verification.
You will often see this pattern when a large progress payment is due or when retainage is about to release. The email references the correct project, the correct invoice number, and sometimes even the correct payment amount. The new routing and account numbers look plausible.
What makes the request suspicious is the timing and the channel. A legitimate subcontractor who needs to update banking information typically handles it between payments, through a phone call or a visit to your office, not in an email sent the morning a wire is scheduled to go out. When the request shows up only in email and only at the last moment, stop and verify through a phone number you already have on file.
Urgency Language and Requests to Bypass the Usual Process
Pressure to skip steps is a defining feature of payment fraud. The email will frame the request as time-sensitive, often claiming the subcontractor needs the payment today to hold a crew, cover payroll, or avoid a lien. The language is polite but insistent, and it pushes your team to release the wire outside your normal approval process.
Legitimate vendors understand your payment schedule because they agreed to it in the contract. A subcontractor who suddenly needs an emergency wire, routed to a new account, is describing a scenario fraudsters engineer on purpose.
Watch for phrasing that discourages a callback. The sender may say they are off-site, traveling, or unavailable by phone, and they prefer to handle everything by email. That preference is the tell. A real vendor who needs money urgently will answer the phone when you call to confirm.
Small Inconsistencies in Domain Names, Signatures or Invoice Formatting
Invoice formatting that differs slightly from earlier invoices from the same vendor is easy to miss when your AP desk is processing dozens of subcontractor invoices in a day. The logo may be lower resolution, the font slightly different, or the invoice number out of sequence. The change is subtle enough that it doesn't register as wrong at first glance.
Domain inconsistencies are more specific. An email that appears to come from your mechanical subcontractor but originates from a domain one character different from the real one, such as an extra letter, a transposed character, or a different top-level domain, is a spoofed address. contractorllc.com instead of contractorco.com is the kind of variation that defeats a quick scan but fails under scrutiny.
Signature blocks also shift. A fraudster impersonating a vendor contact may use a generic signature with no phone number, or a phone number that doesn't match the one in your contract file. If the usual signer's email style changes suddenly, that is worth a second look.
Requests That Arrive Only by Email With No Other Confirmation
A banking change, a new payment instruction, or an urgent payment request that shows up only in email, with no follow-up call, text, or in-person mention, should trigger verification. Construction projects generate constant communication across multiple channels. When a vendor needs something important, you typically hear about it more than once and through more than one medium.
Fraudsters rely on email as the sole channel because they control only the compromised or spoofed email account. They cannot call your office from the subcontractor's real phone number, and they cannot walk into your trailer. The request stays in writing because writing is the only channel they have.
If your project manager has not mentioned the banking change, if the subcontractor has not called your office, and if the request exists only in a single email thread, pause the payment and verify out-of-band. Call the vendor using a number from your original contract file or your vendor master record, never a number provided in the email making the request.
Verifying Payment Requests: A Practical Process for Project Teams

Effective fraud prevention moves beyond awareness posters and becomes a repeatable step in how your team processes every draw request, change order payment, and vendor invoice. The strongest defenses combine callback verification using known contact information, multi-channel confirmation of any banking change, integration of these checks into your accounts payable workflow, and tailored scrutiny based on whether a vendor is new or established.
Calling Back on a Known Number, Not One Listed in the Email
When an invoice arrives with updated payment instructions or an unexpected request, your first action is to call the sender directly using a phone number you already have on file. This means reaching for your project directory, your signed subcontract, or your accounting system contact list, never the phone number printed in the email signature or listed in the message body.
Business email compromise schemes succeed when fraudsters control the email thread and supply their own callback details. A project manager who dials the number shown in a spoofed message will reach the fraudster, who will happily confirm the fake bank details.
Store verified contact information for every active subcontractor, supplier, and consultant outside the email application itself. Your project management software, your contracts folder, or a shared spreadsheet maintained by your accounts payable staff all serve this purpose better than an inbox.
If you cannot locate a known number, search your sent mail for earlier correspondence with that vendor, check the W-9 on file, or ask the project executive or PM who originally brought the vendor onto the job. Treat the absence of a verified number as a red flag that requires resolution before processing payment.
Confirming Bank Detail Changes Through a Second Channel
Any request to update direct deposit information, wire routing numbers, or payment addresses must be verified through a communication channel separate from the one that delivered the request. If the change arrived by email, confirm it by phone. If it arrived by phone from an unknown caller, verify it by emailing a known contact and following up with a callback.
This second-channel confirmation is your most reliable control against construction invoice fraud. Even if a criminal has compromised a subcontractor's email account, they rarely control the office phone line or the mobile number of the principal you worked with on previous projects.
Your accounts payable staff should treat every banking change as requiring this two-step verification, regardless of how routine the invoice otherwise appears. A legitimate vendor will expect the call and appreciate the diligence. A fraudster cannot complete the verification loop.
Document each confirmation in your payment approval notes or accounting software. Record who you spoke with, the date and time of the call, and the number you dialed. This record protects your firm if a dispute arises later and serves as evidence of due diligence for your insurer and your client.
Building Verification Into the Accounts Payable Workflow, Not Just Awareness
Relying on individual judgment to catch suspicious payment requests leaves too much room for a busy day, a trusted vendor name, or a well-crafted email to override caution. Effective fraud prevention embeds verification steps into your accounts payable process so that no payment instruction change can bypass review.
Implement a checklist or approval gate in your accounting software that requires a second person to confirm any new vendor setup or bank detail modification before the payment can be queued. This dual-approval step ensures that even if one staff member misses a warning sign, another set of eyes reviews the request.
Assign specific roles: your office manager or accounting staff initiates the payment entry, and your project executive or a designated principal approves it only after the callback verification is complete and documented. This separation of duties is a standard internal control, and it directly addresses the risk that a single compromised inbox or a single rushed decision becomes the point of failure.
Automate reminders where possible. If your accounting system flags a vendor record edit or a new ACH setup, configure it to send an alert to the approving principal or PM, prompting the required callback before the system releases funds.
What to Verify Differently for New Vendors Versus Long-Standing Ones
A new vendor setup presents higher fraud risk than a payment to a subcontractor you have worked with across multiple projects. For any first-time payee, verify the business registration, request a W-9 directly from the vendor rather than accepting one forwarded by email, and confirm the banking details through a phone call to a number you locate independently, not one provided in the vendor's introductory message.
Check that the vendor's website, business address, and phone number align with the information on the invoice. A mismatch between the email domain and the company name, or a generic free email address for a supplier claiming to be an established material vendor, warrants additional scrutiny.
For long-standing vendors, the risk shifts to account compromise and impersonation rather than outright fabrication. Your callback verification becomes critical here, because the fraudster is counting on your familiarity with the vendor name to bypass your usual checks.
Even with trusted subs, any deviation from normal payment patterns, such as an urgent request, a sudden banking change, or an invoice arriving outside the usual billing cycle, should trigger the same two-channel confirmation you would apply to a new vendor. Construction invoice fraud schemes specifically target established relationships because the trust already exists.
Email and Domain Controls That Stop Invoice Fraud Before It Starts

Email security controls reduce the likelihood that a fraudster gains access to your inbox or successfully impersonates a vendor's domain. These technical measures work best when layered together and configured before an attack attempt, not during a scramble after suspicious activity is spotted.
Reducing the Chance an Inbox Is Compromised in the First Place
Most construction invoice fraud starts when an attacker gains control of a real email account. That account might belong to someone on your project team, a subcontractor's office manager, or a supplier's accounts receivable contact. Once inside, the attacker reads existing threads about draw requests and change orders, learns the payment rhythm, and waits for the right moment to send a message redirecting funds.
Multi-factor authentication blocks the majority of account takeover attempts. Requiring a second factor beyond the password means that even if credentials are phished or leaked, the attacker still cannot sign in. Apply MFA to every email account, not just those belonging to your accounting staff or project executives.
Conditional access policies in Microsoft 365 let you block sign-ins from unexpected locations or flag activity that looks suspicious. A PM whose account suddenly logs in from overseas when your firm operates only in the New York metro area should trigger an alert, not silent access.
Mailbox rule alerts catch attackers who have already compromised an account. Fraudsters often create hidden inbox rules to forward messages or move emails to obscure folders so that the real account owner never sees replies. Alerting when a new forwarding rule or unusual filter appears gives you a chance to detect the compromise during the quiet observation phase, before any banking change email goes out.
Flagging Messages That Impersonate Your Domain or a Vendor's Domain
Domain spoofing is when an attacker sends an email that appears to come from a legitimate address, either by faking the sender field or by registering a lookalike domain. A message from "[email protected]" might actually originate from "[email protected]" or "[email protected]," and the difference is easy to miss when someone is reviewing a payment request quickly from a phone.
Email authentication protocols, SPF, DKIM, and DMARC, allow receiving mail systems to verify that a message genuinely came from the domain it claims. When these are properly configured on your own domain, it becomes much harder for someone to spoof your firm's address in messages to your subcontractors or consultants. When configured by your vendors, the same protocols protect you from receiving spoofed messages that appear to come from them.
External sender banners tag messages arriving from outside your organization, making it immediately visible when an email that looks internal is actually not. Lookalike domain detection built into modern email filtering can flag domains that are one character off from vendors you regularly correspond with, giving your accounts payable staff a warning before they act on a fraudulent banking change.
Why Email Security Needs to Be Set Up Before a Fraud Attempt, Not After
The value of these controls is that they reduce risk continuously, not only at the moment you suspect fraud. An attacker who compromises a subcontractor's inbox in March may not send the fraudulent banking change until June, when a large progress payment is due. If mailbox rule alerts are not configured until after you notice something suspicious, you have already missed the window when the compromise could have been detected early.
Similarly, an email authentication setup that rejects spoofed messages works only if it is in place before the spoofed message is sent. Configuring DMARC enforcement after a fake invoice arrives does nothing to stop that particular attempt. The technical layer must be routine infrastructure, not an emergency response.
Firms that treat email security as something to address only after a close call remain vulnerable during every payment cycle before that wake-up moment. The firms that avoid losses build these controls into their environment from the start.
Where This Fits Into a Firm's Broader Email Security Setup
These controls are part of a broader email security posture that also includes filtering, attachment scanning, and phishing protection. Invoice fraud prevention overlaps with but is not identical to general phishing defense. An attacker impersonating a subcontractor's office manager may send a perfectly clean message with no malicious link or attachment. The message itself is not technically malicious; the fraud lies in the instruction it carries.
That is why inbox compromise and impersonation matter as distinct threats. The first is about detecting unauthorized access to a real account. The second is about recognizing when an incoming message pretends to be from someone it is not. Both require specific configuration beyond generic spam filtering.
If your firm does not have internal IT staff to configure email authentication, conditional access, and alert rules, working with a managed IT provider who understands construction workflows ensures that the controls are set up correctly and tailored to how your project teams and accounting staff actually use email. You can learn more about how these protections are implemented at the email security service page.
Internal Controls and Approval Workflows That Add Friction for Fraudsters

Process-level controls add deliberate checks at the moment an invoice or payment instruction arrives in your workflow. They force a second look at details that a fraudster is counting on being waved through, and they separate who can request a payment from who can authorize it.
Separating Who Requests a Payment From Who Approves It
Segregation of duties means the person who submits a payment request cannot also be the one who approves it. In construction workflows, this applies to subcontractor invoices, supplier bills, change order payments and consultant fees.
A project manager who oversees a trade package should not also have the authority to approve that subcontractor's invoice for payment without a second review. The same applies to draw requests submitted to an owner. If the PM assembles the backup and the same PM releases the wire, a fraudster who compromises that PM's email can both submit a fake invoice and approve its payment.
Your approval workflow should route invoices from the requester to a separate approver, ideally someone in accounting or operations who can verify the request against contracts and prior payment activity. Many accounting platforms enforce this separation automatically once roles are configured. Without it, a single compromised inbox can authorize a fraudulent payment with no independent check.
Setting a Threshold for Payments That Require a Second Sign Off
A payment threshold defines the dollar amount above which a second approval is required, even when the first approval came from someone with authority. A common structure requires a project executive or principal to sign off on any payment over a set limit, such as $10,000 or $25,000.
This control is particularly relevant for retainage releases, milestone draws and change order payments that often exceed routine invoice amounts. A fraudster who sends a fake invoice for $45,000 is less likely to succeed if your workflow automatically routes the payment to a second approver who was not part of the compromised email thread.
The threshold should reflect your typical project scale and payment patterns. Setting it too high undermines the control. Setting it too low creates approval fatigue and delays legitimate payments. You can also apply a second threshold that requires dual approval from two principals or officers for payments above a higher limit.
Maintaining a Verified Vendor and Bank Detail List
A verified vendor list contains the names, addresses, tax IDs and bank details of every entity you pay, updated only through a controlled process. When a subcontractor, consultant or supplier is added, accounting confirms the information using a known phone number or meeting in person, not solely from details provided in an email.
This list should sit in your accounting system and be treated as the single source of truth for payment instructions. When an invoice arrives, the bank details on the invoice are checked against the vendor list. If they differ, payment is held until the discrepancy is resolved through a phone call to a verified contact.
Many payment fraud attempts rely on an email that asks your accounts payable staff to "update our banking information" with new routing and account numbers. If your process is to honor those changes without verification, the fraudster's job is simple. If your process is to cross-check every detail against a verified list and call the vendor using a number already on file, the fraud attempt is likely to fail before a payment is issued.
Auditing Changes to Vendor Records Periodically
Even with a verified vendor list, mistakes and unauthorized edits can occur. Periodic audits of vendor records identify when bank details, addresses or contact information have been changed, who made the change and whether proper verification was documented.
A monthly or quarterly review should pull a report of all vendor record changes during the period. Your accounting or operations lead checks each change against the documentation that authorized it: a signed vendor form, a call log note or an email confirmation sent to a known contact.
This control catches both honest errors and deliberate tampering. If a fraudster successfully social-engineered a change through your process weeks earlier, an audit surfaces the anomaly before the next payment is released. If an accounts payable staff member bypassed verification to save time, the audit identifies the gap in your process and provides a chance to retrain the team before a loss occurs.
Training Your Project Teams and Field Staff to Spot Invoice Fraud

Invoice fraud succeeds when anyone who touches a payment request accepts the information in front of them without a second step. Training must reach every role that routes, approves or processes vendor invoices and change orders, and it must reinforce verification as a standard step rather than an accusation.
Who Needs Training Beyond the Accounting Department
Your accounts payable staff are not the only people who see invoices before a payment goes out. Project managers approve subcontractor invoices and change orders in the field or on-site trailers, often forwarding them to the office with a quick email. Project executives sign off on draw requests and consultant invoices.
Office managers sometimes field vendor calls or emails asking about payment timing. Each of these roles can be the entry point for a fraud attempt, and each needs to recognize the warning signs.
Field staff who never process payments still matter because a fraudster may use their compromised email account to send fake invoices to your accounting team. If a project manager's inbox is hijacked, the criminal has access to real project threads, vendor names, and payment schedules. Training your project team to protect their email accounts and report anything suspicious helps close that exposure before it reaches accounts payable.
Making Verification a Normal Step Rather Than an Awkward One
Many project managers and accounting staff hesitate to call a vendor and confirm a bank account change because it feels like questioning someone's honesty. This hesitation is exactly what invoice fraud relies on. Your training should frame verification as a routine control step, no different from checking lien waivers or requiring backup for a change order.
Emphasize that a phone call to the vendor using a number you already have on file takes less than two minutes and protects both parties. Make it clear that a legitimate vendor expects this step and will not be offended.
Show your team how to verify through a second channel. If the email says to update the bank account, call the contact using the number from your contract or your prior correspondence, not the number in the email. If the phone number has changed, look it up independently rather than accepting the one provided in the request. This simple habit stops most business email compromise attempts before a payment leaves your account.
Using Real, Anonymized Industry Examples in Training
Generic phishing training that shows a fake Amazon order or a lottery scam does not prepare your project team for construction invoice fraud. Your training should walk through scenarios that match how payments actually move through your firm. Show an email thread where a subcontractor asks to update direct deposit information halfway through a project, or a message that appears to come from the owner requesting an urgent wire for a consultant invoice.
Use examples that mirror the tools and language your team sees every day: Procore notifications, forwarded invoices with familiar logos, and payment requests that reference real project stages like retainage release or final draw. Anonymize any real attempts your firm has encountered and include them in the training so your staff can see what a live scam looks like in context.
Point out the subtle signs: a reply-to address that does not quite match the display name, a new sense of urgency in an email from a long-time vendor, or a request to update payment details that arrives outside the normal invoicing cycle.
Keeping Training Current as Project Teams Change
Construction firms see steady turnover in project staff and field roles, and subcontractors rotate from job to job. A single training session during onboarding will not reach everyone who touches invoices six months later, and it will not account for new fraud tactics that emerge as criminals adapt.
Schedule refresher training at least twice a year for all roles that approve or process payments, and make it part of onboarding for new project managers and accounting hires. When your firm adds a new subcontractor to a project or brings on a consultant, share a brief reminder about verifying any payment changes through a second channel before updating your records.
Keep training sessions short and specific. A 15-minute review of recent scam attempts and a reminder of your verification process is more effective than an hour-long presentation that covers every possible threat. Use your project management software or email to send quick reminders when fraud attempts spike in the industry or when your firm receives a suspicious email that did not result in a loss.
What to Do If Your Firm Sends a Fraudulent Payment

Speed matters more than any other factor once a fraudulent wire transfer leaves your account. The first hours determine whether funds can be frozen at the receiving bank or are lost for good, so your priority is contacting your bank and then reporting the incident to law enforcement and your insurer.
Acting in the First Hours: the Bank Before IT
Call your bank immediately after discovering a fraudulent payment. Request that the bank contact the receiving institution through the SWIFT network to attempt a recovery or freeze on the account. Most fraudulent wire transfers move out of the first receiving account within hours, so delays measured in even a few hours can mean the difference between recovery and total loss.
Provide your bank with the transfer details: the payment amount, the date and time it was sent, the receiving account name and number, and the wire reference. If the payment was tied to a specific draw request, subcontractor invoice, or retainage release, include that context so the bank understands it was a legitimate construction payment redirected by fraud.
Do not wait for internal meetings or approval chains before you make the call. The project executive or accounts payable staff member who discovers the fraud should contact the bank directly, then notify management and your IT provider.
Reporting to Law Enforcement and the FBI's Internet Crime Complaint Center
File a report with the FBI's Internet Crime Complaint Center (IC3) as soon as you have contacted your bank. The IC3 collects reports of internet-enabled fraud and routes them to the appropriate federal, state, and local agencies. Filing early creates a record that supports your insurance claim and may assist law enforcement in tracking the funds.
You will need the same details you gave your bank: payment amount, date, receiving account information, and a description of how the scam occurred. If the fraudulent payment instruction came through email, include the sender's address, the subject line, and any attachments or embedded links. Save the original email and any related messages without forwarding them, so headers and metadata remain intact.
Also report the incident to your local police or district attorney if the amount is significant. Some jurisdictions prioritize business email compromise cases, and a local report may be required for your insurer.
Notifying Your Insurer and Reviewing What Your Policy Covers
Contact your insurance carrier or broker the same day you discover the fraud. Most crime and cyber policies require prompt notice, and delays can jeopardize coverage. Your policy may cover social engineering fraud, funds transfer fraud, or computer fraud, each with different definitions and sublimits.
Ask your broker to confirm what is covered under your policy and what documentation the carrier will need to process the claim. Some insurers require a police report or IC3 filing, proof that you followed your internal payment verification procedures, and evidence of the fraudulent communication.
If your firm carries professional liability or general liability coverage, confirm with your broker whether those policies respond to this type of loss. Most do not cover invoice fraud directly, but clarifying coverage early avoids confusion later. If the fraudulent payment was tied to a project funded by a client advance or construction loan, notify your client and lender as your contract or loan agreement may require.
Documenting the Incident for the Bank, Insurer and Any Legal Review
Preserve all records related to the fraudulent payment before anything is deleted or overwritten. This includes the original email or message that contained the fraudulent payment instruction, the payment authorization or approval record from your accounting system, wire transfer confirmations from your bank, and any correspondence with the purported vendor or subcontractor.
Have your project manager, accounts payable staff, or whoever else was involved document what happened in a written statement while the details are fresh. Include who received the payment change request, how it was communicated, what steps were taken to verify it, and when the fraud was discovered. These statements support your insurance claim and may be needed if the matter escalates to litigation.
Store these records in a secure location separate from your regular project files, and limit access to your office manager, your attorney, and your IT provider. Treat the documentation as confidential, especially if it will be reviewed by counsel, so you preserve any legal protections that may apply.
Building a Long-Term Defense Against Construction Invoice Fraud

Stopping construction invoice fraud demands more than a single new policy or tool. Email filters, approval workflows and employee awareness each close gaps, but only when revisited regularly and scaled as your firm takes on larger contracts or new project types.
Combining Email Security, Approval Workflows and Training
Layered defense means pairing technical controls with human checks at every payment step. Start with email authentication protocols that reduce spoofing, add spam and phishing filters that flag suspicious sender addresses, and configure alerts for out-of-pattern messages requesting payment changes.
Your accounts payable workflow should require every bank detail update to be verified through a second channel. That means calling the subcontractor or supplier using a number from your original contract or vendor file, not one listed in the email that arrived. The person approving the payment confirms the change directly before releasing funds.
Training rounds out the defense. Project executives, project managers, accounting staff and anyone answering vendor inquiries need regular updates on what invoice fraud looks like in construction contexts: compromised email threads about draw requests, fake change order approvals, or urgent messages about retainage releases. Run scenarios specific to your workflow so each role understands the verification step they own.
Schedule refreshers quarterly rather than once at onboarding. Tactics evolve, new team members join, and old habits slip without reinforcement.
Revisiting Controls as the Firm Takes on New Project Types or Larger Contracts
Growth changes risk. A firm bidding its first multi-million-dollar public project or entering design-build work introduces longer payment chains, more consultants, and higher-value wire transfers, all of which raise the stakes for payment fraud.
When contract size or project delivery method shifts, audit your internal controls. Ask whether approval thresholds still make sense, whether the project executive or PM has visibility into payment instructions sent downstream, and whether your accounting staff knows the names and roles of every subcontractor and consultant the project team has engaged. If a $500,000 mechanical subcontractor invoices early and the office manager does not recognize the name, verification becomes guesswork.
Document payment workflows for each contract type your firm handles. Who receives invoices, who approves them, who enters banking details, and who initiates the wire? Make the handoffs explicit so no step relies on memory or assumption.
Where Invoice Fraud Prevention Fits Into Broader Cybersecurity Planning
Construction invoice fraud sits inside a larger cybersecurity picture that includes endpoint security, data backup, access control and incident response. Your email authentication and phishing filters work alongside antivirus software, patch management and multifactor authentication to limit what a compromised account can do.
Cybersecurity planning for a small or mid-sized AEC firm should address how invoice and payment data move through your systems. Map where bank details are stored, who has access to payment platforms, and how you protect client and employee records alongside project files.
Set up logging and audit trails so you can trace who changed a vendor record or approved a wire transfer. These logs also support cyber insurance claims and help your IT partner or managed service provider spot anomalies before funds leave the account.
Signs Your Current Payment Process Needs an Outside Review
If your accounting staff routinely updates bank details by copying information from an email, your process has a structural weakness. The same applies when payment approvals happen without a phone call or second-channel confirmation, or when new vendors are added to your system based solely on an invoice attachment.
Other red flags include a lack of documented approval workflows, inconsistent use of verification steps, or uncertainty about who owns each stage of the payment process. If your project manager does not know whether accounts payable called the subcontractor to verify the account change, coordination has broken down.
Bring in an outside review when your firm grows past ten employees, takes on public or federal contracts, or experiences a near-miss: an email that looked legitimate until someone questioned it at the last moment. An MSP with AEC experience or a fractional IT advisor can audit your controls, compare them against industry norms, and recommend specific workflow changes without the sales pitch that accompanies vendor consultations.

Construction invoice fraud raises practical questions about how the schemes work, what recovery looks like, and whether your firm's size or payment processes make you more or less vulnerable.
