Employee Owned Since 2022  |  Serving Chicagoland since 1996Support: 630-523-0220Sales: 630-526-8030Remote support

Cybersecurity whitepaper | Engineering

Preventing Wire Fraud at Engineering Firms

Protect client payments and subconsultant invoices from email-based payment scams

  • Published September 25, 2026
  • 4 min read

Engineering firms move a lot of money through invoices. Clients pay fees, and firms pay subconsultants, surveyors, testing labs, and vendors. Criminals know this, and wire fraud aimed at those payments is one of the most direct threats a firm faces.

How wire fraud schemes target engineering firms

Most schemes start with email. An attacker gains access to a mailbox at your firm, a client, or a subconsultant. Then they quietly read project threads and learn who sends invoices, who approves them, and when payments are due.

At the right moment, they send a message that looks routine. For example, a “subconsultant” says their bank changed and asks you to update payment details. Or your client receives an email that appears to come from your firm, with new remittance instructions for a large invoice.

Because the message fits a real conversation, it rarely looks suspicious. Sometimes it even comes from the real account.

Why the usual warning signs fail

Training often tells staff to look for spelling errors and strange addresses. However, these attacks may use a compromised real mailbox or a lookalike domain with one character changed. The tone and timing also match normal business.

Urgency is another common tactic. Messages often claim a payment must go out today to avoid a project delay, which pressures staff to skip checks.

So the defense cannot depend on spotting a bad email. Instead, it has to depend on a process that verifies payment changes no matter how legitimate the request looks.

Build a payment verification process

The strongest control is simple: never change payment details based on email alone. Verify every change by calling a known phone number from your own records, not one in the message. Keep a note of each call, including who you spoke with and when.

Also require a second person to approve new payees and changes to bank details. Then add a short waiting period for changes on large payments. These steps slow attackers down, and slowing them down often stops them.

Write the process down and make it apply to everyone, including principals. Attackers often pose as a senior leader who needs an urgent payment, so no one should be able to skip the steps.

Payment protection checklist

  • Verify any change to bank details with a call to a number already on file.
  • Require two people to approve new payees and payment changes.
  • Tell clients in writing that your firm will never change remittance details by email.
  • Ask your bank about fraud controls such as payee verification and positive pay.
  • Require multifactor authentication on all email accounts, especially for accounting staff.
  • Block automatic forwarding of email to outside addresses.
  • Register common lookalike versions of your domain when practical.
  • Train staff who handle payments on these schemes at least once a year.

Protect your clients too

Your firm can be the entry point even if your firm never loses money. When an attacker uses your mailbox to redirect a client payment, the client’s trust in your firm suffers. That relationship damage can outlast the financial loss.

So put a clear statement on invoices and in contracts about how you accept payment. In addition, encourage clients to call your office before they act on any change. This small step protects both sides.

You can also add the same notice to email signatures for your accounting team.

Act fast if a payment goes astray

Speed matters when a fraudulent transfer happens. First, call your bank immediately and ask them to attempt a recall.

Next, contact the receiving bank if you know it. Then report the incident to the FBI’s Internet Crime Complaint Center and notify your cyber insurer.

At the same time, have your IT provider check for compromised mailboxes. If an attacker still has access, they may try again or target other contacts.

Afterward, review how the request got through. Use what you learn to tighten the process, rather than blaming the person who made the payment.

How WEBIT helps

WEBIT helps engineering firms reduce wire fraud risk by securing email and supporting better payment habits. Our Security Advanced add-on includes email security, Microsoft 365 threat detection and response, security awareness training, and dark web monitoring. We also offer Duo MFA to protect accounting and leadership accounts.

Learn about our cybersecurity services, or contact us for a review of your email and payment controls.

Key takeaways

  • Wire fraud usually starts with a compromised or spoofed email account.
  • Never change payment details based on email alone.
  • Verify changes by calling a known number, and require dual approval.
  • Tell clients how you accept payment so they can spot fake requests.
  • Call your bank immediately if a fraudulent payment goes out.

Talk to an owner

Want help putting this guide into practice? A 30-minute discovery call gets you honest advice for your environment.

Schedule a discovery call

Engineering IT services

See how WEBIT supports engineering organizations across Chicagoland.

Explore Engineering IT →

More Engineering whitepapers

Browse the full library of guides for your industry.

All Engineering whitepapers →

Two new clients per month. Maximum.

Ready to talk to an owner?

Every conversation starts with an honest look at where you are today. No pressure, no pitch deck, and no obligation.