Nearly every wire fraud matter I have worked contained a moment where someone could have stopped it with a phone call. Not a sophisticated control, not a software tool — a call to a number that was already on file, asking a question that took ninety seconds to answer.
The reason the call does not happen is rarely negligence. It is that the request looked normal. Pass-through entities are built to look normal. What follows is what tends to be true about them anyway, drawn from years of examining these structures after the money was gone.
One caveat before the list: no single item below proves anything. Legitimate businesses are newly formed, use registered agents, and bank in unexpected places. What matters is the cluster. Three or four of these together, on a payment of consequence, is a different picture than any one alone.
Signals in the entity itself
- Formation date close to the transaction. An entity organized weeks before it invoiced you for a substantial sum deserves a look. Check the state's business registry — it is free and takes two minutes.
- An address that is a mail drop or shared suite. A registered agent address hosting hundreds of entities, a virtual office, or a residential address inconsistent with the claimed operation.
- A footprint that does not match the claimed scale. A company billing seven figures with no meaningful web presence, no employees findable anywhere, and no history of prior contracts.
- Names built for confusion. A near-match to a legitimate company — an added “Group” or “Holdings,” a transposed word, a different suffix. This is designed for the moment when someone glances at an invoice rather than reading it.
- Ownership that goes nowhere. Filings listing only a nominee or an agent, with no natural person identifiable behind the entity.
Signals in the payment instructions
- A change of instructions mid-relationship. This is the single most reliable indicator in the entire list. New account, new bank, new beneficiary name, delivered by email, often with a plausible explanation about an audit or a banking transition.
- Beneficiary name that does not match the invoicing entity. Payment directed to an individual, or to an entity with no stated relationship to your counterparty.
- A banking jurisdiction unrelated to the business. A domestic vendor with domestic operations requesting payment to an account in a country with no apparent connection to the work.
- Urgency attached to the change. A deadline, a closing, a penalty for delay, a request to bypass the normal approval path. Time pressure is a technique, not a coincidence.
- Communication drift. Replies arriving from a lookalike domain, a changed reply-to address, or a sudden preference for email over the phone.
The control that actually works
Out-of-band verification is unglamorous and close to unbeatable. Before acting on any new or changed payment instruction, call a known contact at a number from your own records — the contract, the vendor master file, a prior invoice — and confirm the change verbally. Do not use the number in the email. Do not reply to the email. Do not accept a callback from a number you cannot verify.
Compromised email accounts are common, and an attacker sitting inside a real mailbox will answer your written questions convincingly, in the right voice, with the right history. What they cannot do is answer a phone that rings somewhere they are not.
A workable pre-payment check
- Look up the entity in the state business registry: formation date, agent, status.
- Confirm the beneficiary name matches the entity on the invoice and the contract.
- Verify any change of instructions by voice, using a number from your own records.
- Require a second approver for changes above a set threshold — and make the threshold low enough to matter.
- Document who verified, with whom, and when. If it later goes wrong, this file is what supports your insurance claim.
If the wire already went out
Hours matter more than anything you will do later. Funds that sit in a receiving account for a day or two are recoverable far more often than funds that have been moved onward to other accounts or converted.
- Call your bank immediately and ask them to initiate a recall and to contact the receiving institution. Do this before internal discussion — the investigation can wait, the recall cannot.
- Report to the FBI's Internet Crime Complaint Center at ic3.gov. There is an established process for attempting to freeze fraudulent domestic wires, and it depends on speed.
- Preserve everything. Full email headers, the invoice, the instructions, and the account of who did what and when. Do not delete the fraudulent messages, and do not let anyone clean up the mailbox.
- Treat the mailbox as compromised until proven otherwise, on your side or your counterparty's. Reset credentials, check forwarding rules, and pull login logs.
- Notify your insurer and counsel early. Crime and cyber policies carry notice requirements, and claims fail on documentation more often than on the merits.
The investigation that follows — tracing where the funds went after the first hop, identifying who controlled the receiving accounts, and supporting recovery — is real work and often productive. But it operates on whatever is left. The controls above are cheaper than any of it.