Skip to main content
Omaha office · 9224 S 169th St
Serving local businesses since 2016
Veteran-owned and operated
Onsite support across the metro
Free — print it, post it, use it today

Wire Fraud Prevention Toolkit

Fake invoices and changed bank details are how small businesses lose five and six figures in a single afternoon. Everything below is free: a printable verification checklist, a wall poster for the accounting desk, a payment policy you can hand to staff, a short quiz, and what to do in the first hour if money already went out.

Veteran Owned Business Verified Proud MemberVeteran-OwnedOmaha, NE · Since 2016
Read this before you pay an invoice

What Wire Fraud Actually Looks Like

Wire fraud usually isn't a stranger with a fake email. Someone quietly gets into a real mailbox — often at a vendor, a contractor, or a title company you already work with — reads the conversation until they know what you owe and when, then sends an invoice that looks exactly like every other invoice you've paid. The only thing that changes is where the money goes.

That's why no email checker can catch it. The email really did come from your vendor's real address.

The bank details changed

A vendor you've paid for years suddenly sends "updated" account or routing numbers. This is the single most common sign of wire fraud.

It's urgent, and it's quiet

"Wire it today." "Don't loop anyone in yet." Pressure plus secrecy exists to stop you from picking up the phone.

The invoice is unexpected

You weren't waiting on a bill, or the amount doesn't match anything you ordered. Real vendors expect you to ask questions.

The reply-to isn't the sender

The email looks right, but replies quietly route to a different address so the real vendor never sees the conversation.

The domain is one letter off

dmeomaha.com vs dmeomaha.co, or an "rn" standing in for an "m." Read the address character by character, not at a glance.

The boss is asking, over email

An owner or CFO requesting a transfer by email alone — especially while "traveling" or "in meetings all day" — should never be enough on its own.

The one step that actually stops it

Before any payment where the bank details are new or changed, call the vendor on the phone number you already had for them — from your records, an old invoice, or their website. Never the number in the email asking for money. Thirty seconds on the phone with a real person is the whole defense, and it has never once been the wrong call.

The 30-second call that stops the loss

Exactly What to Say When Bank Details Change

Most staff know they're supposed to "call and verify" — then freeze, because nobody told them what to ask. Print this next to the phone. Dial the number you already had on file, never the one in the email.

Say this, in order

  1. 1"Hi, this is [name] at [company]. I'm calling to verify a payment change before we send anything."
  2. 2"We received an invoice dated [date] for [amount] with new banking details. Can you confirm those changed?"
  3. 3"Can you read me the last four digits of the account number you want us to pay?"
  4. 4"Who at your office authorized the change, and when?"
  5. 5"I'm going to note that I spoke with you today to approve this. Can I get your name and extension?"

Stop and escalate if

  • They can't confirm the change, or have no idea what invoice you mean.
  • The account digits they read don't match the ones in the email.
  • You're pushed to "just email" instead of talking, or told the person who knows is unreachable.
  • The number in the email is the only one that reaches anybody.

Any one of these means do not pay today. Nothing legitimate is lost by waiting a few hours — and a real vendor will never penalize you for confirming.

Stop — verify before paying

Before You Pay: Invoice Verification Checklist

Run through this every time an invoice asks for money — especially if anything about the payment details is new. Print it and keep it wherever payments get approved.

Saved in this browser so it's here next time.

Which version?
  1. 1. Confirm you were expecting this bill

    Match it to a purchase order, a signed contract, or work you know was done. If nobody here ordered it, stop.

  2. 2. Read the sender's address character by character

    Compare it to an older email from the same vendor. Look for a swapped letter, an extra letter, or a different ending (.co instead of .com).

  3. 3. Check who a reply would actually go to

    Hit reply and look at the address that fills in. If it isn't the vendor's normal address, do not send the reply.

  4. 4. Compare the bank details to the last payment

    Pull the previous invoice. If the account number, routing number, or bank name changed at all, treat it as fraud until proven otherwise.

  5. 5. Call the vendor on a number you already had

    Use your own records, an old invoice, or their website — never a number in this email. Ask them to read the bank details back to you.

  6. 6. Get a second person to sign off

    Any new or changed payment details should be approved by someone other than the person who received the email.

  7. 7. Ignore the urgency

    A real vendor will wait a day for verification. Pressure to pay immediately or keep it quiet is the scam, not the deadline.

  8. 8. Write down who you verified with

    Note the name, the phone number you called, and the date on the invoice itself. This protects you and your team later.

Known-good vendor numbers

Fill these in from your own records, not from any email. This is the list you call.

VendorVerified phone numberWho we ask for
   
   
   
   
   
   

Verified by: ______________________________

Date: ______________________________

If anything on this list fails, do not send the payment. Call DME Computer Services at 402-650-8407 — we'll look at it with you, free, client or not.

What one of these actually looks like

This is a realistic example, not a real message. Every red mark is a tell you can check in about ten seconds.

From:

Karen Willis <billing@midlandssupply.co> 1

Reply-To:

k.willis.accounts@outlook.com 2

Subject:

Invoice 40218 — updated remittance details

Hi,

Please find attached invoice 40218 for $18,450. Note that our bank has changed and payments should now go to the account below. 3

Account: 8841002317   Routing: 104000029

We need this settled today to avoid holding your order — please don't loop in anyone else, I'm handling it personally. 4

Any questions call me direct on (402) 555-0148. 5

Thanks,
Karen

  • 1

    The domain is one character off. The real vendor is midlands-supply.com — this is midlandssupply.co.

  • 2

    Reply-to points somewhere else entirely. Your reply never reaches the vendor.

  • 3

    Bank details "just changed." This is the entire scam in one sentence.

  • 4

    Urgency plus a request to keep it between you two. Real vendors don't do this.

  • 5

    The phone number is theirs, not the vendor's. Calling it confirms the fraud to the fraudster.

Your cyber policy may already require this

Most cyber and crime policies include a social engineering clause that requires out-of-band verification — a phone call to a known number — plus a second approver before any change to payment details. If a wire goes out without it, the claim can be denied even though you were clearly defrauded. Pull your policy and search for “social engineering” or “funds transfer fraud,” then keep the completed checklist on file as your proof of process.

Build your payment approval policy

Set your dollar threshold and who signs off. You get a one-page policy you can hand to staff — the document insurers and auditors ask for.

Approval required at or above
  1. 1. Any payment at or above $5,000 requires written approval from a second authorized approver before funds are released.
  2. 2. Any change to a vendor's bank account, routing number, or payee name must be verified by phone using a number already on file — never a number supplied in the request.
  3. 3. Verification calls are made to the vendor's known contact. The vendor reads the details to us; we do not read them out.
  4. 4. New vendors are paid only after their banking details have been verified by phone and approved by a second authorized approver.
  5. 5. The person who receives a payment request may not be the person who approves it.
  6. 6. Urgency is never a reason to skip verification. A 24-hour hold applies to any new or changed payment details.
  7. 7. The name of the person verified with, the number called, and the date are recorded on the invoice.
  8. 8. Suspected fraud is reported immediately to management and to the bank's fraud line.

Five-question staff check

Send this to anyone who can approve a payment. Four out of five is a pass — screenshot the result for your training records.

1. A long-time vendor emails that their bank details changed. What do you do first?

2. The email address looks right at a glance. Is that enough?

3. The invoice says payment is needed today or the order gets held. What does that tell you?

4. Who should approve a change to a vendor's bank account?

5. A wire went out to a fraudulent account an hour ago. First call?

Protect your customers too

Fraudsters also impersonate you to your customers. Paste this into your email signature so every message you send carries the warning.

Payment security notice: We will never change our bank details by email. If you receive a message claiming our payment information has changed, do not pay it — call us on the number you already have on file to verify.

<table role="presentation" width="100%" style="border-collapse:collapse;margin-top:16px">
  <tr>
    <td style="background:#fff8e1;border-left:4px solid #f5a623;padding:12px 16px;font-family:Arial,Helvetica,sans-serif;font-size:12px;color:#5a4300;line-height:1.5">
      <strong>Payment security notice:</strong> We will never change our bank details by email.
      If you receive a message claiming our payment information has changed, do not pay it &mdash;
      call us on the number you already have on file to verify.
    </td>
  </tr>
</table>

In Outlook: File → Options → Mail → Signatures. In Gmail: Settings → General → Signature (paste the rendered version above rather than the code).

If the money already went out

Do these in this order. Recoveries happen in the first few hours and almost never after the first few days.

  1. 1 · Immediately

    Call your bank's fraud line and say the words "wire recall"

    Ask them to initiate a SWIFT recall or a Hold Harmless letter on the receiving bank. Speed is everything — funds are often moved on within hours.

  2. 2 · Within the hour

    File a report at ic3.gov

    The FBI's Recovery Asset Team can freeze domestic transfers, but they need the report. Include the amount, both account numbers, and the timestamp.

  3. 3 · Same day

    Notify your cyber insurance carrier

    Most policies have a short reporting window. Late notice is one of the most common reasons a wire fraud claim gets denied.

  4. 4 · Same day

    Lock down the mailbox and get someone technical involved

    Change the password, force sign-out everywhere, turn on MFA, and check for forwarding rules the attacker left behind. Then look for other pending payments.

In the Omaha metro and don't know who to call first? 402-650-8407 — we'll walk you through it whether you're a client or not.

Can someone already fake an email from your domain?

Most invoice fraud starts with a message that looks like it came from you or your vendor. A free 30-second scan checks whether your domain is protected against spoofing — the single setting that stops it.

Scan My Domain
Straight answers

Wire Fraud Questions Business Owners Ask

Can the bank get our money back?+

Sometimes — but only if you move immediately. Banks can attempt a wire recall, and the FBI's Financial Fraud Kill Chain can freeze domestic transfers over $50,000 if reported fast, usually within 24–72 hours. After that the money has typically been broken up and moved offshore. Call your bank's fraud line before you do anything else, then file at ic3.gov.

Does our cyber insurance cover this?+

Often not by default. Many policies treat wire fraud as "social engineering" or "funds transfer fraud," which is a separate rider with its own — usually much lower — limit. Some insurers also deny claims if the payment bypassed your own written verification procedure. Ask your broker for those specific limits in writing.

Our vendor was hacked, not us. Are we still liable?+

In most cases the loss stays with whoever sent the money. Courts have generally placed responsibility on the party in the best position to catch the change — which is the payer verifying new bank details. Being the victim of someone else's breach rarely gets the funds back.

How much do businesses actually lose to this?+

Business email compromise is consistently one of the costliest categories of cybercrime reported to the FBI's Internet Crime Complaint Center, with billions in reported losses annually and average incidents well into six figures. Small businesses are targeted heavily because they rarely have a formal payment-verification step.

What's the cheapest way to prevent it?+

A written rule that no bank-detail change is ever accepted by email alone — always a callback to a number already on file, plus a second person approving anything over a set dollar amount. That costs nothing. Everything else on this page exists to make that rule stick.

Should we tell our customers about this?+

Yes. If someone impersonates you to your clients, they'll pay a criminal and blame you. Add a short banner to outgoing invoices stating that your banking details never change by email and giving a number to call. There's a copy-paste version in the toolkit above.

Who's behind this toolkit?

This toolkit is published by DME Computer Services, a local Omaha IT and cybersecurity company — not an anonymous website.

A real Omaha company

We're local — same city, same time zone. Call 402-650-8407 and a person here answers.

Veteran-owned since 2016

DME has supported small businesses across the Omaha metro for nearly a decade, including recovering from real fraud incidents.

No strings attached

Everything on this page is free to print and use. No signup, no credit card, no sales call required.

Not Sure If an Invoice Is Real?

Send it over and a local DME tech will look at it with you before you pay a cent. Free, client or not.

Call 402-650-8407

Get a Free Second Opinion

Tell us what's broken — a local tech gets back to you, usually same business day.

No contracts. No obligation. If we're not the right fit, we'll tell you straight.

Money Already Sent? Call Now.

The first hour matters more than anything else — banks can sometimes recall a wire if you move fast. Call us and we'll walk you through it.