top of page
Search

Vendor Payment Fraud: What Contractors and Manufacturers Need to Know

3 hours ago
6 min read

Oct 7, 2026 · @Lucinda

Much has changed with the advent of the world wide web and continued to changed quickly with the rise and necessity of technology. This changing landscape has altered the threats that business owners face on a daily basis. If you run a construction company or a manufacturing operation, one of your biggest financial risks may not be on the jobsite or the plant floor. It may be sitting in your inbox.


Vendor payment fraud, sometimes called business email compromise, has become one of the most common and costly scams targeting businesses. It doesn't require a hacker to break into your systems. It only requires one convincing email and one well-meaning employee trying to pay a bill on time.


The good news: a few simple habits can stop most of these scams before any money leaves your account. Here's how the scam works, how to protect your business, and why your insurance policy may not cover it the way you think.


How the Scam Works

Most vendor payment fraud follows the same pattern:

  1. A vendor's email gets compromised. A criminal gains access to the email account of one of your suppliers, subcontractors, or other vendors, often through a phishing link or a stolen password.

  2. They watch and wait. The criminal reads past conversations to learn who you pay, how much, and when. They pick up names, invoice formats, and project details.

  3. They strike at the right moment. When a large invoice, progress payment, or materials order comes due, they send an email that looks completely normal: "We've changed banks. Please send this payment to our new account."

  4. Your team updates the banking info and sends the payment. The real vendor never receives it, and by the time anyone notices, the funds have usually been moved and are very difficult to recover.

Sometimes the email comes from the vendor's real account. Other times it comes from a look-alike address that differs by a single letter. Either way, it's designed to look routine.


Why Construction and Manufacturing Are Targets

Criminals go where the money is and where the scam is easiest to hide. Contractors and manufacturers check both boxes:

  • Large payments. Progress draws, equipment purchases, and bulk materials orders mean a single fraudulent payment can be worth tens or hundreds of thousands of dollars.

  • Long vendor lists. With dozens of subcontractors, suppliers, and service providers, one more invoice or a change in banking details doesn't stand out.

  • Public information. Project awards, permits, bid results, and supplier relationships are often easy to find, which helps criminals craft believable emails.

  • Busy, lean offices. A small accounting team juggling deadlines is under pressure to pay quickly, which is exactly what scammers count on.


Best Practices to Protect Your Business

You don't need an IT department to stop most payment fraud. You need clear procedures that everyone follows every time.

  1. Verify every banking change by phone. Call the vendor using a number you already have on file, not one listed in the email asking for the change. This single step stops most of these scams.

  2. Require two approvals. Have two people sign off on wire transfers, ACH payments, and any change to a vendor's banking information.

  3. Write down your payment-change procedure. Put the steps in writing, train your team on them, and make it clear there are no exceptions, even for "urgent" requests from people you know.

  4. Turn on multi-factor authentication (MFA). Use it for email, online banking, and accounting software. It makes it much harder for criminals to take over your accounts or your vendors' accounts.

  5. Know the red flags. Be cautious of urgency, pressure to keep things quiet, slightly misspelled email addresses, new bank accounts in a different state or country, or changes requested right before a big payment.

  6. Use your bank's fraud tools. Ask about positive pay, payment alerts, and callback verification for large transfers.

  7. Train your team regularly. Short, recurring reminders work better than a one-time training. Make sure employees know it is always okay to slow down and double-check.

  8. Review your vendor records. Log every change to vendor banking details, note who approved it, and review the log periodically.


What to Do If It Happens

If you think a fraudulent payment went out, speed matters more than anything else.

  1. Call your bank immediately. Ask them to recall or freeze the transfer and contact the receiving bank. The sooner you call, the better the chance of recovering funds.

  2. Report it to the FBI. File a complaint through the FBI's Internet Crime Complaint Center at ic3.gov.

  3. Call your insurance agent. Report the loss right away, even if you aren't sure it's covered. Late notice can create problems with a claim.

  4. Preserve the evidence. Keep the emails, invoices, and payment records. Don't delete anything.

  5. Notify the real vendor. Let them know their email may be compromised so they can secure it and warn their other customers.


Does Insurance Cover Vendor Payment Fraud?

This is where many business owners get an unpleasant surprise. Coverage for this type of loss depends heavily on the specific policy forms and endorsements you carry, and it is often limited or missing entirely.


Commercial crime policies. The standard computer fraud and funds transfer fraud coverages are generally designed for unauthorized transfers, like a hacker breaking into your bank account. In a vendor payment scam, your own employee authorizes the payment after being tricked, and many carriers have denied claims on that basis. To close that gap, most carriers offer a separate social engineering fraud endorsement.


Cyber policies. A cyber policy typically focuses on data breaches, ransomware, system restoration, and business interruption. Social engineering and funds transfer fraud coverage is often an optional add-on rather than part of the base policy.


General liability, property, and business owner's policies. These policies are generally not designed to cover a payment your business voluntarily sent to a criminal.


Even when social engineering coverage is in place, watch for these details:

  • Sublimits. Coverage is often capped well below the policy's main limit, which may be far less than a single large payment.

  • Verification conditions. Many policies require you to verify payment changes, often with a callback to a known phone number. If that step is skipped, the claim may be denied.

  • Invoice manipulation. This covers the reverse scenario, where your email is hacked and your customers pay the criminal instead of you. Many policies don't include it unless it's specifically added.

The bottom line: don't assume you're covered. The only way to know is to review the actual policy language.


How Southern Insurance Associates Can Help

At Southern Insurance Associates, we work with contractors, manufacturers, and other businesses across to make sure their coverage matches the real risks they face. When it comes to payment fraud, we can help you:

  • Review your current cyber and crime policies to see exactly what is and isn't covered for social engineering, funds transfer fraud, and invoice manipulation.

  • Identify gaps before a claim happens, including low sublimits, missing endorsements, and verification conditions your team needs to follow.

  • Find the right coverage for how your business actually operates, whether that's adding a social engineering endorsement, increasing limits, or placing a standalone cyber or crime policy.

  • Connect you with carrier resources, since many cyber carriers offer employee training, phishing awareness tools, and incident response support to policyholders.

  • Support you if something goes wrong, from reporting the claim to working with the carrier through the process.

We're an independent agency, which means we can compare options from multiple carriers instead of offering just one.


Frequently Asked Questions

What is social engineering fraud coverage?

  • It's coverage for losses that happen when someone at your business is tricked into sending money or goods to a criminal, for example, by a fake vendor email requesting a banking change. It is usually added to a crime or cyber policy by endorsement.

Isn't this covered by my cyber policy?

  • Not necessarily. Many cyber policies focus on data breaches and ransomware. Social engineering coverage is often optional, sublimited, or not offered at all, depending on the carrier.

Can my bank get the money back?

  • Sometimes, especially if you report it within hours. But once the funds are moved out of the receiving account, recovery becomes much harder. That's why prevention and the right coverage both matter.

We're a small company. Are we really a target?

  • Yes. Smaller businesses are often targeted because they have fewer controls and smaller teams. Criminals don't need to know your company well. They just need access to one vendor's email.

What's the single most important step we can take? 

  • Always verify any change in payment instructions by calling the vendor at a number you already have on file. Never rely on contact information from the email requesting the change.


Let's Make Sure You're Protected

Vendor payment fraud is preventable, and the cost of a coverage review is far less than the cost of a single lost payment. If you're a contractor or manufacturer and aren't sure how your current policies would respond, let's take a look together.


Contact Southern Insurance Associates, at (423) 296-0626 or LBoyd@southins.com.


This article is for general informational purposes only. Coverage depends on the specific terms, conditions, and exclusions of each policy.

 
 
 

Comments


Providing Peace of Mind  

Contact

Southins.com

Tel: (423) 296-0626

4525 Hixson Pike

Hixson, TN 37343

Navigation

Home

Insurance Services 

Careers

About

Contact

Social

Instagram

Facebook

Twitter

LinkedIn

Find Us On

  • Instagram
  • Facebook
  • Twitter
  • LinkedIn

© 2023 by Tripo. Proudly created with Wix.com

bottom of page