How the attack works
- Entry: a compromised mailbox, a vishing call, or an impersonated executive (CEO fraud).
- Redirection: either a new "urgent" payment or — more commonly — changed bank details on a payment you were going to make anyway.
- Under-the-radar sizing: amounts placed below dual-approval thresholds to need only one deceived person.
- Dispersal: funds hop through mule accounts within hours; after ~72 hours, recovery odds collapse.
Warning signs
- Any change to payment details, however routine it looks.
- Urgency plus confidentiality in a payment request.
- Requests arriving when the purported requester is known to be unreachable.
- New instructions "confirmed" only through the same channel they arrived on.
Prevention
One control dominates: out-of-band callback verification, enforced so payments cannot release without it. See the full checklist in how to prevent wire transfer fraud.