What it means
The mechanics are usually social rather than technical. Someone impersonates a trusted party, creates urgency, and persuades a member of staff to authorise a payment through the normal channels, so no system is actually broken into.
The most expensive variant is business email compromise, where an attacker either accesses or convincingly imitates a real mailbox. Because the request arrives in a genuine-looking thread with correct names and context, standard scepticism often fails.
What makes wire fraud especially damaging is speed and finality. A domestic transfer can be irreversible within hours and an international one is frequently gone for good, so the recovery window is measured in hours rather than days.
The controls that work are unglamorous and procedural. Verifying any change of bank details by phone on a previously known number, requiring two approvers above a set threshold, and refusing to treat urgency as a reason to skip a step will stop most attempts.
Insurance is a partial answer, not a complete one. Many policies cover only certain fraud types, carry a deductible, and cap payouts well below a large transfer, and insurers increasingly expect to see documented verification controls before they pay a claim.
Recovery depends heavily on how the payment was made and where it went. Domestic transfers within the same banking system stand a reasonable chance of being frozen if reported the same day, whereas funds routed overseas and split across several accounts are rarely seen again.
In practice
Real-world examples.
Example
A property buyer receives an email that appears to come from her conveyancing solicitor, giving updated account details for the deposit. She transfers $65,000 to a fraudster's account, and only $8,000 is recovered.
Example
A finance assistant at a manufacturing company receives a text message purporting to be from the chief executive, asking for an urgent supplier payment while he is on a flight. A mandatory callback policy catches it, and no money leaves the account.
Example
A charity's payroll file is intercepted and bank details for eleven employees are altered before submission. The bank's name-matching service flags nine mismatches, and the charity's own reconciliation catches the remaining two before the next run.
Formula
Calculation
Net loss from a wire fraud incident = Amount transferred - Amount recovered - Insurance proceeds, where insurance proceeds are the lower of the policy limit and the loss after the deductible.
A construction firm's accounts payable clerk receives a convincing email appearing to come from a long-standing subcontractor, giving new bank details, and pays an invoice of $480,000. The fraud is discovered nine days later. A rapid recall through the bank freezes and returns $95,000, leaving an unrecovered loss of $480,000 - $95,000 = $385,000. The firm holds crime insurance with a $250,000 limit and a $25,000 deductible, so the insured amount is $385,000 - $25,000 = $360,000, capped at the $250,000 limit. Net loss = $385,000 - $250,000 = $135,000, before the cost of investigation and management time.Case study
Seen in the real world.
The following is an illustrative and fictional scenario. Ambleton Facilities Group paid roughly 900 supplier invoices a month and allowed bank detail changes to be actioned by any of four accounts staff on the strength of a signed letterhead attached to an email. An attacker who had monitored a supplier's mailbox for six weeks sent a change request at month end, when the team was busiest.
Over the following three weeks Ambleton paid $612,000 to the fraudulent account across four invoices before the genuine supplier chased for payment. The bank recovered $140,000, insurance paid $250,000, the full limit on the policy, after a $50,000 deductible was applied, and the fictional company absorbed a net loss of $222,000, calculated as $612,000 - $140,000 - $250,000.
The remediation cost almost nothing by comparison. Ambleton introduced a rule that no bank detail change is actioned without a callback to a number held in the supplier master file before the request arrived, plus a second approver for any payment above $25,000, and it ran a short training session using the actual fraudulent emails as the teaching material.
Watch out
Common mistakes.
- Verifying a change of bank details using the contact details supplied in the request itself. Always call a number you already held before the request arrived.
- Treating wire fraud as a technology problem to be solved by the IT team. Most incidents exploit process and human trust, so the controls belong in the finance function.
- Assuming insurance will make the company whole. Limits, deductibles and policy exclusions usually leave a significant uninsured balance.
Questions
People also ask.
How quickly must a fraudulent payment be reported?
Immediately, ideally within hours, because banks can sometimes freeze funds that have not yet been moved on through further accounts.
Is business email compromise the same as wire fraud?
Business email compromise is one of the most common methods used to commit wire fraud, so the two overlap heavily but are not identical.
What single control prevents the most losses?
A mandatory verbal callback on any change of payment details, using a number verified independently of the request.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%