Call the requester back on a number you already hold, not one supplied in the message, and confirm the amount and the destination account aloud. That single step defeats almost every documented wire-fraud case in this library.
The reason it works is that the attacker controls the channel the request arrived on. They can answer a reply, spoof a domain, and mimic a writing style. What they cannot do is answer a phone number your records held before they appeared.
Documented cases
- Medidata Solutions sent $4.8 million in 2014 after emails that appeared to come from its own chief executive.
- Argan Inc. lost $3 million to a phishing-led wire fraud in 2023.
- Mattel shows the recovery path: $3 million out, and $3 million back, because the company moved before the funds dispersed.
The control that breaks it
- Callback on a stored number. Never a number, extension or link inside the request.
- Read the account number back digit by digit. Attackers often change only one or two.
- Confirm in a second channel the requester did not choose.
- Escalate immediately if a transfer is disputed. Recovery windows are measured in hours.
Related: how to prevent BEC · how to prevent invoice fraud · Business email compromise
Related