The Wire-Change Call That Can Stop a Costly Cyber Fraud
An email that says a supplier has updated banking information can look entirely routine. It may arrive in an existing email thread, use the supplier’s logo and signature, and refer to a real invoice or project.
That is what makes business email compromise so effective. The attacker does not need to break into a payment platform. They need one person to accept a new instruction without independently confirming it.
For tribal enterprises, casinos, and growing businesses, a misdirected payment can disrupt vendors, payroll, construction, procurement, and community-facing operations. It can also create pressure to share financial records or sensitive information while staff try to unwind the fraud. A simple control can sharply reduce that risk: no payment or banking change takes effect until someone verifies it using a known, independent contact method.
The FBI’s Internet Crime Complaint Center continues to identify business email compromise as a major source of reported cyber-enabled financial loss. The practical lesson is not to treat every email as suspicious. It is to treat changes to where money goes as high-risk events that require a second channel of trust.
Make one rule clear
Adopt a short rule that every employee can remember: Never accept new or changed payment instructions from email alone.
This applies to supplier bank-account changes, requests to alter a wire recipient, payroll direct-deposit changes, refund instructions, urgent executive requests, and any message asking finance to bypass normal approval.
The rule should cover both new vendors and familiar ones. A message from a known contact may still be unsafe if their mailbox has been compromised or an attacker has created a convincing look-alike address.
Do not rely on the phone number in the message requesting the change. Call a number from your vendor master record, signed contract, official website, or a prior verified contact. For a high-value or unusual payment, require a second person to confirm the change and document who completed the call.
Use a five-step verification playbook
1. Pause the transaction. Flag the request and prevent release of the payment until verification is complete. Urgency is a common pressure tactic, so the process must work even when the vendor says a deadline is near.
2. Compare the request with the known record. Check the sender address closely, but do not stop there. Compare the legal vendor name, invoice, purchase order, prior payment details, and account contact with the information already on file. A small change in a domain name or bank beneficiary can be meaningful.
3. Verify out of band. Call a trusted vendor contact using a number already verified by the organization. State only what is needed: We received a request to change payment details. Can you confirm whether that request is legitimate? Do not read back the proposed account number before the contact independently confirms the request.
For tribal enterprises and casinos, the same approach should apply to internal requests that affect gaming operations, property systems, grants, benefits, or other sensitive funds. The authority to make a change should be clear, documented, and separated from the person who executes it when practical.
4. Require a second approval. Set a dollar threshold and a list of change types that require dual approval. One person can verify the vendor; another can approve the record update or payment release. This makes it harder for a single compromised mailbox, rushed employee, or overlooked anomaly to move money.
The control is not a sign of distrust. It is a business safeguard that protects employees who are working under real time pressure.
5. Record the decision. Keep a brief note with the vendor record: who requested the change, who called, the independent number used, the date and time, the person who confirmed it, and the approver. Never place full banking details in ordinary email or unprotected notes.
That record makes the process repeatable and gives leadership a way to review exceptions. It also helps when an incident requires a quick timeline.
Prepare before the next request arrives
The strongest payment controls are put in place when no invoice is waiting. Identify the people authorized to request, verify, approve, and enter payment changes. Clean up vendor master records so trusted contact information is current. Turn on multifactor authentication for email, finance, payroll, and banking accounts. Train staff to report suspicious requests immediately, even if no money moved.
The NIST Cybersecurity Framework 2.0 frames these actions as governance, protection, detection, and response working together. The technical safeguards matter, but so do clear roles and a process people can follow without improvising.
Data sovereignty belongs in this process as well. A payment investigation can involve invoices, vendor contracts, employee information, and operational records. Leadership should know who may access those records, what outside parties may be involved, and how information will be handled if an incident crosses organizational or jurisdictional boundaries.
If money was sent, act fast
Contact your bank or payment provider immediately and ask it to recall or freeze the transaction. Preserve the original messages and payment records, alert internal leadership, and report the incident to the FBI’s Internet Crime Complaint Center. Do not delete the suspicious email, even if it appears obvious in hindsight.
NativeCyber helps tribal enterprises, casinos, and growing businesses turn common cyber fraud risks into clear, workable controls. A focused review of payment-change approvals can help protect both operating revenue and the trust behind it.
Sources
FBI Internet Crime Complaint Center: 2024 Internet Crime Report: https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf
FBI Internet Crime Complaint Center: Business Email Compromise: https://www.ic3.gov/CrimeInfo/BusinessEmailCompromise
CISA: Cross-Sector Cybersecurity Performance Goals: https://www.cisa.gov/cybersecurity-performance-goals
NIST Cybersecurity Framework 2.0: https://www.nist.gov/cyberframework

Comments