Skip to main content

← All posts

Wire fraud hit your business: the first 48 hours

A step-by-step response plan for the first 48 hours after a fraudulent wire transfer leaves your account, from bank recall to IC3 to preserving evidence.

· Jake Schaaf, Founder of Atticus Rowan

The controller approved a $84,000 wire to a familiar vendor on Tuesday morning. On Thursday the real vendor calls asking why the invoice is past due. The account number on the “updated banking details” email was the attacker’s. The money left 2 days ago and everyone in the office is now staring at the same question: what do we do right now?

The honest answer is that the next few hours matter more than anything else you will do in this incident. Wire fraud recovery is a race. Funds typically sit in the first receiving account for a short window before they are split and moved through secondary accounts, converted to crypto or pulled out as cash. Once that happens, recovery odds fall off a cliff. Here is the sequence we walk businesses through, hour by hour.

Hour 0 to 1: call your bank’s fraud department

Not your branch contact. Not the relationship manager who helped you open the account. Ask specifically for the fraud or wire recall department and tell them you need to initiate a recall on a fraudulent wire.

What to have in front of you when you call:

  • The exact amount and date of the transfer
  • Your account number and the destination account and routing numbers
  • The wire confirmation or transaction ID
  • A 1-sentence statement that this was a fraudulently induced transfer

Ask 3 things explicitly. First, initiate the recall (for international wires, a SWIFT recall). Second, contact the receiving bank’s fraud department directly, bank to bank. Third, give you a case number and a direct callback contact.

Banks are not obligated to recover your money and business accounts do not carry the consumer protections personal accounts do. But receiving banks will often freeze an account flagged for fraud while they investigate, and that freeze is what buys you time. The earlier the call, the more likely the funds are still sitting there.

Hour 1 to 4: file with the FBI’s IC3

File a complaint at ic3.gov as soon as the bank call ends. Do not wait for a lawyer, do not wait for a meeting, do not wait to be sure about every detail. You can supplement later.

This step is not bureaucratic box-checking. The FBI’s Recovery Asset Team runs a process called the Financial Fraud Kill Chain, which coordinates with financial institutions to freeze fraudulent transfers. It works best when the complaint is filed within 72 hours of the transfer, for domestic wires, and for amounts of $50,000 or more, though you should file regardless of the amount. In its 2023 report, IC3 said the kill chain process froze roughly 71% of the targeted funds in the cases where it was initiated. Speed is the difference between being in that group and not.

Your IC3 complaint should include the same details you gave the bank, plus the sender address of the fraudulent email, the spoofed or lookalike domain if there was one and copies of the altered invoice.

If your business banks with a smaller community bank, tell them you filed with IC3 and give them the complaint number. It helps them escalate on their side.

Hour 4 to 24: preserve the evidence before you clean anything

The instinct after fraud is to purge. Delete the emails, wipe the rules, reset everything and move on. Resist it for a few hours. Your insurer, your bank and law enforcement will all want evidence, and some of it is fragile.

Preserve, in this order:

  • The fraudulent emails themselves, with full headers exported, not just screenshots of the body
  • Any mailbox rules in the affected account. Attackers who compromise a mailbox almost always create a rule that forwards or hides replies. Screenshot the rule before deleting it
  • The altered invoice or payment instruction document, plus the legitimate version for comparison
  • Sign-in logs for the affected mailbox covering at least the past 30 days
  • A timeline written while memories are fresh: who received what, who approved what, when

If the fraud involved a compromised mailbox on your side (as opposed to the vendor’s side), the sign-in logs matter enormously. They establish when the attacker got in, from where and what else they may have touched. If nobody on your team knows how to export headers or audit logs from Microsoft 365, this is the moment to call whoever manages your IT. We cover what that support relationship should look like in our post on incident response without an in-house team.

Hour 24 to 48: insurer, counsel and the uncomfortable phone calls

Notify your cyber insurer even if you are not sure the loss is covered. Many cyber policies handle wire fraud under a social engineering or cybercrime rider with its own sub-limit, often $100,000 to $250,000 rather than the full policy limit, and with notice requirements measured in days. Reporting late is one of the most common reasons these claims get denied. Give your broker the timeline, the IC3 number and the bank case number.

Loop in counsel, particularly if the fraudulent instruction came from a vendor’s compromised mailbox rather than yours. Who bears the loss in that scenario is a genuinely contested legal question, and courts have gone different directions based on which party was in the best position to prevent the fraud. Do not make admissions to the vendor about fault, in either direction, before you have advice.

Then make the calls you do not want to make. If the attacker used your compromised mailbox, other customers and vendors may have received fraudulent payment instructions too. Warning them early is both the right thing and the thing that limits your exposure.

After the money: close the door they came in through

Somewhere in this timeline, usually once the recall and IC3 filings are in motion, shift to containment. This is where business email compromise incidents usually reveal their root cause: a phished password, no MFA on the mailbox or a lookalike domain nobody noticed.

At minimum:

  • Reset the affected account’s password and revoke all active sessions
  • Remove malicious inbox rules and check every other mailbox for similar rules
  • Review and revoke suspicious OAuth application grants
  • Enforce MFA on every mailbox if it is not already there
  • Add a verification callback policy: any change to payment details gets confirmed by phone, using a number you already had on file, before a dollar moves

That last control is the one that would have stopped the whole thing, and it costs nothing.

The 48-hour window is a plan, not a panic

None of this is complicated. All of it is time-sensitive, and businesses lose recoverable money every week simply because nobody knew the sequence and the first day went to meetings instead of phone calls. Write the sequence down now, while nothing is wrong, and put your bank’s fraud department number in it.

If you would rather not build that plan alone, or you want someone who has run this playbook on call when the bad Tuesday comes, talk to Atticus Rowan. We help small and mid-size businesses put the controls and the response plan in place before they are needed.