How Thieves Manipulate Wire Transfers

Unmasking the Threat: How Business Email Compromise and Typosquatting Lead to Wire Transfer Fraud

In an increasingly digital world, businesses and their clients face a growing and sophisticated threat: the Business Email Compromise (BEC) scam, often exacerbated by a deceptive tactic known as typosquatting. These insidious schemes exploit the trust inherent in business communications, leading to substantial financial losses and severe reputational damage. This article delves deep into the mechanics of these prevalent frauds, offering a comprehensive look at how they operate, the real-world impact they inflict, and, most importantly, actionable strategies to prevent your organization from becoming the next victim.

Image of man with phone in front of him and the words 'scam alert'

The Pervasive Threat of Business Email Compromise (BEC)

Business Email Compromise, or BEC, is a category of cybercrime that involves sophisticated phishing attacks targeting businesses that regularly perform wire transfers and have suppliers abroad. The scam is particularly effective because it doesn’t rely on malware or technical exploits in the traditional sense; instead, it leverages social engineering to manipulate victims into making fraudulent payments. Cybercriminals impersonate a legitimate party—such as a CEO, a vendor, or a legal firm—and trick employees or clients into sending money to an account controlled by the fraudsters.

The core of a BEC scam lies in its ability to convincingly mimic legitimate communication. Scammers conduct extensive reconnaissance, often gaining unauthorized access to email systems to study communication patterns, identify key individuals, and understand payment processes. This intelligence allows them to craft highly convincing emails that appear to originate from a trusted source, directing funds to a fraudulent account. The financial stakes are incredibly high, with the FBI reporting billions in losses annually due to BEC schemes globally.

Anatomy of a Typosquatting Wire Transfer Scam: A Case Study

A particularly dangerous variant of the BEC scam incorporates typosquatting, also known as URL hijacking or a “fake URL” attack. This technique involves registering a domain name that is a common misspelling or slight variation of a legitimate company’s website. The subtle difference is often overlooked by even vigilant individuals, allowing scammers to intercept or initiate fraudulent communications. A revealing lawsuit filed by law firm Revision Legal provides a stark illustration of this exact modus operandi:

12. On or prior to May 14, 2019, Defendant obtained improper and unauthorized access to Client’s email system.

13. Defendant then located emails between Plaintiff and Client pertaining to Client’s outstanding balance with Plaintiff for legal services.

14. Defendant then Defendant (sic) registered the “Infringing Domain” (revisoinlegal.com) which is a typosquatting registration as it transposes the “o” and “i” in “revision” and is intended to appear as Plaintiff’s URL, revisionlegal.com.

15. Defendant then inserted himself in the email thread while removing Plaintiff’s attorneys from the email thread.

16. Defendant then emailed Client falsely informing Client that Plaintiff was changing how it was accepting payments and attached an altered invoice instructing Client to send payment via wire transfer to Premier Bank, located at [removed] (“Fraudulent Account”).

17. Client, believing this information was accurate, wired in excess of $25,000 to the Defendant’s Fraudulent Account

This detailed account dissects the scam into several critical phases:

  • Initial Compromise: The scam begins with unauthorized access to a client’s email system. This could be achieved through various methods, including phishing for credentials, exploiting weak passwords, or leveraging unpatched vulnerabilities.
  • Information Gathering: Once inside, the perpetrator meticulously sifts through email correspondence, identifying ongoing transactions, outstanding invoices, and key individuals involved in payment processes. This reconnaissance phase is crucial for building a credible narrative for the impending fraud.
  • Typosquatting Domain Registration: The criminals register a domain name that is a cunning misspelling of the legitimate company’s domain. In the Revision Legal case, “revisoinlegal.com” was registered, subtly transposing letters from “revisionlegal.com.” This minor alteration is incredibly effective in deceiving recipients who quickly glance at email addresses.
  • Impersonation and Interception: The scammer then inserts themselves directly into an existing email thread, effectively hijacking the communication. They remove the legitimate parties, ensuring all subsequent replies go directly to them. This makes the fraudulent communication appear seamless and continuous.
  • Fabricated Instructions: The scammer sends a convincing email, often with an altered invoice, claiming a change in payment methods. The new instructions direct the victim to wire funds to a “Fraudulent Account” controlled by the criminals. The urgency and professional tone often prevent victims from scrutinizing the details thoroughly.
  • Execution: Believing the instructions are legitimate, the client proceeds to wire a significant sum—in this instance, over $25,000—directly into the scammer’s bank account. Once the money is wired, it becomes incredibly difficult, if not impossible, to recover.

Real-World Consequences: Beyond Financial Loss

The immediate consequence of such a scam is, undeniably, significant financial loss. However, the ripple effects extend much further. Companies that fall victim can suffer severe damage to their reputation and client trust. Clients may question the security protocols and reliability of their business partners, leading to strained relationships or even loss of future business. The legal costs associated with investigating and attempting to recover funds, alongside potential litigation, can be substantial.

A private equity group with which I’m involved recently experienced a similar attempt this year. Fortunately, one of their astute clients identified subtle discrepancies within the fraudulent email, flagging it before any funds were transferred. This close call underscores the critical importance of client vigilance and robust internal verification processes. It’s a sobering reminder that these threats are not theoretical but active and persistent dangers to every sector of the economy.

Fortifying Your Defenses: Proactive Prevention Strategies

Preventing BEC and typosquatting scams requires a multi-layered approach, combining technical safeguards with comprehensive human awareness and stringent procedural controls.

Technical Safeguards

  • Multi-Factor Authentication (MFA): Implement MFA for all email accounts and critical systems. This adds a crucial layer of security, making it exponentially harder for unauthorized users to access accounts even if they have stolen passwords.
  • Email Security Solutions: Utilize advanced email filtering solutions that can detect phishing attempts, spoofed domains, and malicious attachments. These systems can identify anomalies and block suspicious emails before they reach employee inboxes.
  • Domain Protection (DMARC, SPF, DKIM): Configure DMARC (Domain-based Message Authentication, Reporting, and Conformance), SPF (Sender Policy Framework), and DKIM (DomainKeys Identified Mail) records for your domain. These protocols help prevent email spoofing by verifying the authenticity of sender domains.
  • Endpoint Security: Ensure all devices are protected with up-to-date antivirus and anti-malware software. Regular security patches and updates are essential to close vulnerabilities that attackers might exploit.
  • Monitor Domain Registrations: Consider services that monitor new domain registrations similar to your own, allowing you to identify potential typosquatting attempts early.

Human Firewalls: Training and Awareness

  • Employee Training: Conduct regular and mandatory cybersecurity awareness training for all employees. Emphasize the dangers of BEC, phishing, and social engineering tactics. Teach them how to identify red flags in emails, such as unusual sender addresses, grammatical errors, urgent requests, or changes in payment instructions.
  • Verify Payment Changes: Establish a strict protocol for verifying any requests to change payment instructions or bank accounts. This protocol should always involve an out-of-band verification method, such as a direct phone call to a known, verified number (not a number provided in the email) or an in-person confirmation.
  • Scrutinize Email Addresses and Links: Educate employees to look beyond the display name in an email and carefully inspect the full email address for any subtle misspellings or variations. Hovering over links to reveal their true destination before clicking is also a vital habit.
  • Awareness of Social Engineering Tactics: Help employees understand the psychological manipulation used in these scams, such as creating a sense of urgency, authority, or secrecy.

Robust Payment Protocols

  • Dual Control for Payments: Implement a system requiring at least two individuals to authorize and process wire transfers or significant financial transactions. This separation of duties adds a critical internal control.
  • Formal Change Request Process: Any requests for changes to vendor bank details or payment instructions must go through a formal, documented process that includes multiple layers of verification. Never rely solely on email for such critical changes.
  • Secure Communication Channels: Use encrypted and secure communication channels for sensitive financial discussions, especially when dealing with new vendors or high-value transactions.

What to Do If You Suspect or Fall Victim to a Scam

Time is of the essence if you suspect a BEC scam or realize you’ve fallen victim. Act immediately:

  • Contact Your Bank: Immediately notify your bank and the recipient bank (if known) to request a recall of the wire transfer. The faster you act, the higher the chance of recovery.
  • Contact Law Enforcement: File a report with federal law enforcement agencies, such as the FBI (via the Internet Crime Complaint Center – IC3) in the United States, or your local police department. Provide all available evidence, including email headers and transaction details.
  • Isolate and Investigate: Engage cybersecurity experts to investigate the extent of the email system compromise, identify how the breach occurred, and secure your systems. Change all affected passwords and implement MFA.
  • Preserve Evidence: Do not delete any suspicious emails or related communications. Preserve all evidence for the investigation.
  • Notify Affected Parties: Inform clients, vendors, and partners about the incident to warn them and prevent further compromise.

The Evolving Landscape of Cyber Threats

The ingenuity of cybercriminals continues to evolve, adapting to new technologies and security measures. The rise of sophisticated AI tools could potentially make impersonation even more convincing in the future. Therefore, continuous vigilance, ongoing education, and a commitment to robust cybersecurity practices are not merely good ideas—they are essential for survival in the modern business landscape.

By understanding the tactics employed in BEC and typosquatting scams, and by implementing strong preventive measures, businesses can significantly reduce their vulnerability. Protecting your financial assets and reputation starts with an informed and proactive defense strategy.