← All terms

Wire Transfer Fraud

Wire transfer fraud manipulates a person or process into sending an irrevocable bank transfer to an attacker-controlled account.

Wire transfer fraud is any scheme that manipulates a person or a payment process into sending funds by bank wire to an account the attacker controls. Wires are the preferred cash-out channel for corporate fraud because they are fast, high-value and, once settled, effectively irrevocable — unlike card payments there is no chargeback mechanism, and recovery depends on freezing the money before it is moved on through mule accounts.

How it works

Most corporate wire fraud is social engineering aimed at the people who move money. In business email compromise, the attacker impersonates or hijacks a trusted mailbox and redirects a payment that was going to happen anyway — a vendor's "updated" bank details, a closing payment on a property, a payroll change. In CEO fraud, an urgent request that appears to come from an executive pressures a finance employee into an unscheduled transfer, increasingly reinforced by cloned voices on the phone. Invoice fraud slips a fraudulent or altered bill into the normal accounts-payable flow. The common structure: establish or steal trust, create urgency or routine, change the destination account, and rely on the transfer being executed exactly as the process allows. Funds land in mule accounts and are dispersed within hours.

How to defend against it

Process beats vigilance alone. Require out-of-band verification — a call to a number already on file, never one from the email — for any new payee or change to bank details, and dual approval above a value threshold. Make the callback rule absolute precisely so that urgency, hierarchy and a familiar voice cannot waive it: a policy with exceptions is a policy attackers will find. Reconcile vendor master-data changes on a delay, and give finance teams targeted training and simulations built on real payment-fraud pretexts, since they are among the most targeted roles a human risk program measures. Speed matters on the response side too: a wire reported to banks and law enforcement within the first 24–48 hours can sometimes be frozen; the FBI's IC3 operates a Recovery Asset Team for exactly this. Our guide to defending against business email compromise covers the full playbook.

Related terms

Business Email Compromise (BEC)Business email compromise is a targeted attack where criminals impersonate executives or trusted partners via email to trick employees into transferring money or sensitive data.Invoice FraudInvoice fraud tricks a company into paying a fake or altered invoice, typically by impersonating a real supplier and changing the bank account details.CEO FraudCEO fraud is a social engineering attack where criminals impersonate a senior executive to pressure an employee into urgent wire transfers or data disclosure.Authorized Push Payment (APP) FraudAPP fraud manipulates a victim into sending a payment themselves — the transfer is authorized, so standard fraud controls and recalls often fail.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo