Wire fraud is the most expensive fraud a bank or its customers will experience, for one structural reason: wires are final. There is no chargeback, no return window, and no right of recall. Recovery depends entirely on the receiving institution and the beneficiary choosing to cooperate, and on speed measured in hours.
That finality means prevention is essentially the whole control. Detection after the fact is a recovery effort, not a control.
Almost no wire fraud involves breaking into a bank's systems. It involves persuading someone with authority to send the money.
An attacker gains access to, or convincingly imitates, an email account — an executive's, a vendor's, or an attorney's — and sends a payment instruction. The characteristic features are urgency, confidentiality, and a plausible reason the normal process cannot be followed.
The most effective variants use a genuinely compromised account rather than a lookalike domain, so the email arrives in an existing thread, in the sender's actual writing style, referencing real transactions. Nothing about it looks wrong because nothing about it is fake except the instruction.
A supplier notifies the customer that its banking details have changed. The notice arrives on convincing letterhead, from a plausible address, sometimes following a phone call. The next legitimate invoice is paid to the fraudster's account.
This is the highest-value pattern because the payment itself is expected. Nobody questions a wire to a known vendor for an invoice that exists.
An attacker monitoring a transaction — usually through a compromised email account at a title company, brokerage, or law firm — sends the buyer altered wiring instructions shortly before closing. The buyer wires their entire down payment to the fraudster. These losses are frequently catastrophic and uninsured at the individual level.
An employee's credentials are phished and used to change direct deposit details, or a customer's online banking is taken over and a wire initiated. The account takeover variant is the one where Reg E may apply for consumers, unlike the induced-payment cases above.
A message purporting to come from a senior executive instructs a finance employee to send funds urgently and confidentially, often referencing an acquisition or a regulatory matter. It exploits hierarchy — the employee is being asked not to follow the process by someone who can waive it.
Out-of-band verification. Any new or changed payment instruction is confirmed by calling a number already on file — never a number in the request, never a number on the invoice that came with the request.
Everything else supports this. If a bank or a business implements a single control against wire fraud, this is the one, and it defeats every pattern above except account takeover.
Implementation details that determine whether it actually works:
The number must come from an independent record. Attackers include phone numbers in their requests specifically because people call them.
It applies to changes, not just new payees. Vendor redirection targets existing relationships.
It cannot be waived for urgency. Urgency is the attack, not a reason to skip the step. Any process where sufficient pressure removes the verification has no verification.
It cannot be waived by seniority. An executive who instructs staff to bypass the callback has created the exact condition executive impersonation exploits. The policy has to bind the executive, and the executive has to say so publicly.
Wires are governed by UCC Article 4A. The core rule: if the bank and the customer agreed to a commercially reasonable security procedure, and the bank accepted the payment order in good faith and in compliance with that procedure, the order is effective as the customer's — even if it was fraudulent.
The consequences follow directly:
This is why the customer conversation belongs at onboarding rather than after a loss. A treasury customer who understands that a wire cannot be reversed, and who has therefore adopted callback verification and dual control, is far better protected than one who learns it during a $340,000 loss.
Speed dominates everything. Within the first hours, recovery is plausible; within days, it is unlikely.
Structured coverage is available through our ACH and wire transfer training, the Certificate in Fraud Prevention, and Financial Crimes Red Flags Training.
It is worth training staff on the psychology, because the standard framing — "be careful, verify requests" — has not reduced losses and treating victims as careless is both wrong and counterproductive.
These attacks work by supplying authority, urgency, and isolation simultaneously. The instruction comes from someone entitled to give it. There is a deadline that makes deliberation feel costly. And the request includes a reason not to discuss it with anyone — a confidential acquisition, a regulatory matter, an embarrassing error being quietly fixed. Each element alone is manageable; together they disable the normal checks a competent person would apply.
The attacks also arrive at chosen moments. Volume spikes around quarter end, before holidays, and during known transitions like a system conversion or a finance team departure — periods when the process is already under strain and exceptions are already being made.
The defense that follows is structural rather than attitudinal. Make verification the path of least resistance, so following it is easier than skipping it. Remove the isolation by making it explicit policy that any request for confidentiality about a payment is itself a red flag, and that no employee will ever be criticized for confirming. And rehearse it — a five-minute tabletop where the finance team walks through a realistic request does more than an hour of slides, because the point is not knowing the rule but having already felt the pressure once.
Callback verification fails in practice for predictable reasons, and each has a design fix.
Nobody can find the number. If verifying requires hunting through email for a contact, staff will use the number in the request. The fix is a maintained vendor and counterparty contact record, populated at onboarding, with changes to it treated as a controlled event requiring its own verification.
The verifier is the requester. Where the same person who received the instruction performs the callback, a compromised or complicit party controls both sides. Assign verification to someone outside the payment initiation chain.
It happens after approval. A callback performed once the payment is already queued for release becomes a formality that a busy approver clears. Sequence it before approval so it gates the transaction rather than decorating it.
No record survives. The verification needs a log entry — who called, which number, who answered, what was confirmed, and when. Without it there is no evidence the control operated, which matters both for internal review and for any subsequent liability discussion.
Voice is no longer proof. Synthetic voice has reached the point where hearing a familiar voice confirms nothing on its own. Callbacks should go to a number of record rather than accepting an inbound call claiming to be the counterparty, and higher-value changes warrant a second factor beyond the call — a known reference detail, a second approver, or a delay window.
For the bank's own customers, the equivalent conversation is worth having at onboarding for every treasury relationship. A customer who has heard the bank explain that wires are final, that the bank cannot reverse an authorized payment, and that the callback is what stands between them and an unrecoverable loss will implement the procedure. A customer who first hears it during a loss will remember only that the bank did not stop it.
One further point for institutions serving title companies, law firms, and escrow agents: these customers hold other people's money in transactions with known dates and known amounts, which makes them the highest-value targets in most community bank portfolios. They warrant a dedicated conversation about dual control, beneficiary allow-lists, and delay windows, and several institutions have found it worth declining to originate same-day wires for these customers entirely — trading a service feature for the elimination of the pattern that produces catastrophic, uninsured losses for their clients.
Not as of right. Wires are final on acceptance under UCC Article 4A — there is no chargeback and no return window. Recovery depends on requesting a recall and the receiving institution and beneficiary cooperating, which is realistic within hours and unlikely within days.
No. Reg E covers electronic fund transfers to and from consumer accounts and expressly excludes wire transfers, which fall under UCC Article 4A instead. Consumers who assume their debit card protections extend to wires are mistaken, and this misunderstanding is common in real estate closing fraud.
A scheme in which an attacker impersonates or takes over an email account — an executive's, a vendor's, or an attorney's — to induce a payment or a change of payment instructions. The most effective versions use a genuinely compromised account, so the message arrives in a real thread in the sender's own style, with nothing false except the instruction.
Out-of-band verification: confirming any new or changed payment instruction by calling a number already on file, never one supplied in the request. It defeats business email compromise, vendor redirection, closing fraud, and executive impersonation. It only works if it cannot be waived for urgency or by seniority.
Generally the customer. Under UCC Article 4A, a payment order the customer authorized is effective even if the authorization was induced by deception, and an order authenticated under an agreed commercially reasonable security procedure generally binds the customer as well. This is why the risk conversation belongs at onboarding.
Contact the receiving bank and request a recall or hold immediately, before internal review is complete; file promptly with law enforcement including the FBI's Internet Crime Complaint Center, which operates a recovery process for fast reports; and preserve the payment message, email headers, and session logs. Recovery probability falls sharply with each hour.


