In April 2024, a university payables team was tricked into paying an attacker posing as the construction contractor for a campus project. Southern Oregon University wired $1.9 million to a fraudulent account. Three days later the contractor, Andersen Construction, reported they had never received payment. This was a textbook “contractor impersonation” business email compromise (BEC): attackers discovered a real vendor relationship, spoofed or compromised a related email address and sent altered payment instructions and successfully perpetrated payment fraud.
What BEC Is and Why It Is So Dangerous
Business Email Compromise (BEC) — also called Email Account Compromise (EAC) — is a social-engineering and account-intrusion scam where attackers impersonate trusted vendors or executives to request changes to vendor bank account information or to request wire transfers to a fraudulent account.
It’s one of the most financially damaging cybercrimes globally, with reported losses in the billions according to the FBI’s IC3 Division, which collects and analyzes data on cyber-enabled criminal activity. Because BEC exploits legitimate business processes (invoices, purchase orders, vendor updates), it bypasses traditional cybersecurity defenses.
IC3 and FBI data show BEC is widespread, international and high-value — reported losses are measured in billions and attackers commonly use intermediaries or overseas banks to move funds. Rapid reporting and contacting your financial institution immediately are critical steps if you suspect a fraudulent transfer.
How the Scam Typically Works
- Reconnaissance: Attackers research real vendor relationships.
- Impersonation: They spoof or hack legitimate vendor emails.
- Change Request: They send a “new bank account” notice that appears authentic.
- Urgency: The message appears legitimate and pressures staff to act quickly.
- Funds Lost: Payment is sent to the attacker’s account. Recovery is difficult and time sensitive—the longer discovery takes, the less likely your organization will recover the funds.
Recommended Controls & Practices
Top-line: Prevent BEC with process + people + technology. Strong technical controls reduce risk. Your IT department should already be onboard with email authentication standards, multi-factor authentication, secure email gateways and anti-phishing controls to block known malicious senders and flag suspicious messages.
But robust, enforced payment processes and verification channels are crucial for effective mitigation for electronic funds transfer fraud.
1) Payment verification procedures
- Require multi-channel verification for any change to vendor banking details: call a pre-approved phone number you look up yourself (not the one in the email), or use a previously validated contact.
- Enforce two-person (or three-way) approval for all wire transfers above a configurable threshold (e.g., any single wire > $10k or project-related final payments). Approvers must be independent of the requester.
- Never allow email alone to authorize a wire or change vendor banking details. Log and timestamp all verification steps.
2) Supplier onboarding & change controls
- Validate vendor banking information during onboarding: obtain bank letter, perform micro deposits, or use an independent contact at the vendor (contract manager, dedicated AP contact) and verify bank account ownership.
- Maintain a limited-access vendor master file with a formal process to request and approve any changes.
- Segregate duties: the person who enters and updates vendor banking data must not be the final approver of payments. Attackers often exploit weak vendor-change workflows.
3) Transaction monitoring & banking controls
- Configure bank-level controls: whitelists/blacklists of beneficiary accounts, daily wire limits and dual-authorization at the bank for large transfers.
- Maintain relationships with banks and know their procedures for recall/trace requests — act immediately if a fraud is suspected. Time matters for fund recovery.
4) Employee training & awareness
- Run mandatory, role-based training for AP, procurement, finance, and project managers on BEC red flags (unexpected account changes, urgent requests and lookalike domains).
- Teach staff to verify via trusted phone numbers, never via reply-to, and to treat urgent or confidential payment demands as suspicious. Phishing simulation exercises help.
5) Contract & invoice design
- Use purchase orders and contract language that specify fixed payment routing and a formal change-request process.
- Require invoices to include contract numbers and confirmation tokens that are cross-checked before payment.
6) Logging, monitoring & least privilege
- Log changes to vendor records and wire requests and use Security Information and Event Management (SIEM) or transaction analytics to detect anomalous requests (new routing info + invoice mismatch).
- Apply least-privilege access to finance systems and rotate access for temporary roles.
7) Incident response & reporting plan
- Have a documented fraud response playbook: immediate notification to the bank, filing IC3 complaint, contacting law enforcement, preserving email headers and collecting vendor confirmations.
- Report BEC attempts/losses to IC3 and local FBI field office; IC3 data helps trace funds internationally. The FBI/IC3 recommend contacting the bank immediately and filing an IC3 complaint.
8) Vendor & partner collaboration
- Share vendor-validation processes with major contractors and require vendors to follow secure billing channels (e.g., vendor portal, EDI and encrypted invoicing).
- Consider escrow or staged payments for very large construction draws, tied to verified milestones.
The Criticality of Bank Account Verification
Most BEC and payment diversion scams succeed not because of advanced hacking, but because vendor banking data was changed without true verification. A robust vendor bank account verification process ensures that any change to a vendor’s payment details is authenticated against a trusted, external source — before any funds move. This creates a hard barrier between fraudsters and your treasury.
However, even when procedures exist, the process often breaks down because manual verification is slow, inconsistent or perceived as burdensome during tight payment cycles. As a result, staff may skip or abbreviate the process, trusting what appears to be a legitimate vendor email.
Automated vendor bank account verification is a best practice to ensure this vital control is applied consistently and efficiently. Automated BAV uses secure API integrations with financial institutions and verification networks.
These systems validate that:
- The account exists and is active.
- The account holder’s name matches the vendor’s legal entity.
- The routing and account numbers correspond to the expected bank.
This process takes seconds and dramatically reduces the risk of fraud stemming from altered payment instructions. Automated verification isn’t just faster — it also tightens control. Key benefits include:
- Reduced human error: Eliminates manual data entry mistakes or skipped verification calls.
- Fraud prevention: Detects mismatches between vendor name and account owner — a common red flag in BEC schemes.
- Compliance: Produces an audit trail demonstrating due diligence, supporting compliance with internal control standards (e.g., SOX, NIST, ISO 27001).
- Improved vendor trust: Vendors are paid faster and with fewer onboarding delays, improving relationships and reducing disputes.
Automation doesn’t replace oversight — it reinforces it, allowing finance teams to verify every account change consistently and in real time.
Summing Up
The Southern Oregon University case shows how easily BEC can exploit normal payment workflows. The fastest, most sustainable defense now combines:
- Verified process discipline — independent confirmation of all payment changes.
- Trained staff — aware of social-engineering red flags.
- Automated verification technology — that eliminates the friction and inconsistency of manual verifications.
When all three work together, BEC attempts can be detected before any funds leave your organization.
Publicly available project/vendor information makes target selection trivial for attackers; the remaining defense must be internal process rigor and human skepticism. The SOU case shows that even well-intentioned staff can be deceived when a request looks legitimate and payment routines lack independent verification. Build controls that assume email may be forged or compromised.
Manual processes once served as the backbone of AP controls, but in today’s fast-moving payment environment, manual verification is no longer adequate. Automated vendor account verification delivers speed, certainty and auditability — the qualities needed prevent modern payment fraud.
Speed without verification leads to loss. Speed with verification leads to confidence.
To find out how VendorInfo can help you with automated vendor bank account verification, contact us.

