How-to guideAug 08, 2026by Docurensic Team7 min read

Wire Fraud: What to Do in the First 72 Hours

Almost everything that works on a fraudulent transfer works in the first day. Almost nothing works after the third. Here is the order to work in when it has already happened.

Wire Fraud: What to Do in the First 72 Hours
In this guide
  1. Key takeaways
  2. Hour zero to four: the recall window
  3. Hour four to twenty-four: report and preserve
  4. Day one to three: contain the blast radius
  5. After 72 hours: it becomes an investigation
  6. The prevention that would have worked
  7. Frequently asked questions

Most of what we publish is about catching a fraud before the money moves. This one is for the other case: it has already gone, somebody has just realised, and the next few hours matter more than anything that happens afterwards.

The single most common reason a recall fails is not that the bank was unhelpful. It is that the victim spent the first afternoon emailing the supplier to work out what had happened.

Key takeaways

Hour zero to four: the recall window

Phone the bank's fraud line. Not the branch, not the relationship manager's inbox, not the app's message centre. The fraud team is the only function that can act at the speed this needs. Ask explicitly for a recall on a domestic payment or a SWIFT indemnity request on an international one, and get a reference number.

What you are asking the bank to do is contact the receiving institution and request the funds be returned or frozen. Whether that works depends almost entirely on whether the money is still sitting in the receiving account. Mule accounts are drained fast — often within the hour, frequently split across several onward transfers — which is why the first phone call outranks everything else, including working out how it happened.

Have these ready before you dial: the date and time of the payment, the amount and currency, your account details, the beneficiary name, account number and sort code / IBAN / SWIFT, and the payment reference. Reading them off a screen while the fraud analyst waits costs minutes you do not have.

Do not contact the fraudster. Not to ask, not to accuse, not to warn. The moment they know, the money moves. Any communication also risks contaminating the record.

Do not touch the mailbox yet. Nobody deletes anything, forwards anything, or moves anything into folders. If a compromise is involved, the mailbox is a crime scene and it is one of the most fragile kinds — audit logs on many platforms roll off in weeks.

Diagram: the first 72 hours after a fraudulent payment
The recovery curve falls steeply from the first hour

Hour four to twenty-four: report and preserve

Report to the police or national fraud body. Every jurisdiction has one, and the report matters for three reasons beyond the vanishing hope of recovery: it is usually required by insurers, it is often required by the bank to progress a claim, and it is what allows law enforcement to connect your incident to the others they are already looking at. In the United States that is the FBI's Internet Crime Complaint Center, which operates a recovery-asset process specifically for fraudulent wires and is explicit that speed determines whether it can act (ic3.gov).

Preserve the evidence properly. This is where most organisations quietly destroy their own case.

Establish whether a mailbox was compromised. Check for forwarding rules nobody created, sign-ins from unexpected locations, and OAuth grants to applications nobody recognises. A malicious forwarding rule quietly copying invoice threads is the most common finding, and it means the exposure is broader than one payment.

Force credential resets on any account that may be involved, and enforce multi-factor authentication if it was not already on.

Day one to three: contain the blast radius

Check every other payment in the same conversation. These operations rarely target one invoice. Review payments to the same supplier over the preceding months, and — critically — any other supplier whose correspondence lives in the same compromised mailbox.

Call your suppliers, on numbers you already had. They may be compromised rather than you. They may have been sent redirected details for your payments. This conversation is unpleasant and it is the one that prevents the second loss.

Notify your insurer. Crime and cyber policies commonly carry notification deadlines measured in days, and late notice is a routine reason for a declined claim. Notify early even if the facts are incomplete.

Involve counsel if the amount is material, and to manage the supplier relationship — the question of who bears the loss when a payment goes to a fraudster's account is contractual and jurisdictional, and it is better addressed early.

Consider your regulatory obligations. If personal data was accessed as part of a mailbox compromise, breach-notification clocks may already be running, and they are often 72 hours from awareness.

After 72 hours: it becomes an investigation

Recall almost never succeeds beyond this point. The money has been layered through onward accounts and, frequently, out of the banking system entirely.

That does not make the work pointless, it changes what the work is for:

Establish how the instruction was accepted. Almost always there is a control that existed and was bypassed under pressure, or a control that never existed. Neither is a personal failing; both are fixable.

Fix the specific gap. In practice this is nearly always the same one: a change of payment details was accepted without independent verification. The fix is the 60-second bank detail check — a call to a number you already held, before any change is actioned, with no exceptions for urgency.

Feed what you learned back in. The lookalike domain, the sending pattern, the document that came attached. Block the domain, add the pattern to your mail rules, and tell the supplier whose identity was borrowed.

Handle the human part deliberately. The person who processed the payment is usually devastated and usually blameless — they were targeted by an operation designed by people who study exactly this. Organisations that punish get slower reporting next time, and slow reporting is what turns a recoverable loss into a permanent one.

The prevention that would have worked

Almost every case in this family comes down to one of three gaps, and all three are cheap to close:

Payment-detail changes verified out-of-band. One phone call, to a number from your own records. This defeats the attack even when every technical control was fooled.

Dual authorisation on new or changed beneficiaries. Two people, and the second one's job is specifically to check the account, not the invoice.

A first-time-sender banner on inbound mail. Most mail platforms can flag a domain nobody at the organisation has corresponded with before. The entire attack depends on the domain feeling familiar.

None of these require a project. All of them are policy changes you can make this week — and the reason to make them this week is that the window in which any of this is recoverable is measured in hours.

Frequently asked questions

Can a bank reverse a fraudulent wire transfer?

Sometimes, if it is caught quickly. The bank contacts the receiving institution to request a recall or freeze, which only works while the funds are still in the receiving account. Mule accounts are typically emptied within hours, so the first call is the one that matters.

Who do I call first after a fraudulent payment?

Your bank's fraud line, by phone. Before IT, before the supplier, before internal escalation. Everything else can happen in parallel; the recall cannot.

Should I tell the fraudster we know?

No. Any contact accelerates the onward movement of funds and can compromise evidence. Do not reply, do not warn, and do not attempt to negotiate.

How long do we have to notify our insurer?

Crime and cyber policies commonly require notification within days of discovery, and late notice is a frequent reason for declined claims. Notify as soon as you are aware, even before the facts are settled.

Put it to the test

Scan a document and get a plain-English verdict in seconds. Free to start.

Start scanning free

Keep reading

How-to guideAug 02, 20267 min

Reading Email Headers: The Trail a Message Can't Fake

Everything a sender types can be forged. Everything the relay servers stamped on the way through cannot be rewritten after the fact — which is why the headers are where the answer lives.

ArticleJul 31, 20267 min

One Character Off: How Lookalike Domains Get Paid

The most effective domain in payment fraud is not a hacked one. It is a real domain, correctly configured, that differs from your supplier's by a single character nobody reads.