Wire Fraud: What to Do in the First 72 Hours
Almost everything that works on a fraudulent transfer works in the first day. Almost nothing works after the third. Here is the order to work in when it has already happened.

Most of what we publish is about catching a fraud before the money moves. This one is for the other case: it has already gone, somebody has just realised, and the next few hours matter more than anything that happens afterwards.
The single most common reason a recall fails is not that the bank was unhelpful. It is that the victim spent the first afternoon emailing the supplier to work out what had happened.
Key takeaways
- Call the bank's fraud line before doing anything else, and phone rather than email. Recall requests are a race against the fraudster's onward transfers.
- Do not contact the fraudulent counterparty. Warning them accelerates the money out of reach and can destroy evidence.
- Preserve the original email with full headers and the attachment as received, before anyone forwards, deletes or "tidies" the mailbox.
- Assume the mailbox is compromised until proven otherwise, and check whether other payments in the same thread were also redirected.
Hour zero to four: the recall window
Phone the bank's fraud line. Not the branch, not the relationship manager's inbox, not the app's message centre. The fraud team is the only function that can act at the speed this needs. Ask explicitly for a recall on a domestic payment or a SWIFT indemnity request on an international one, and get a reference number.
What you are asking the bank to do is contact the receiving institution and request the funds be returned or frozen. Whether that works depends almost entirely on whether the money is still sitting in the receiving account. Mule accounts are drained fast — often within the hour, frequently split across several onward transfers — which is why the first phone call outranks everything else, including working out how it happened.
Have these ready before you dial: the date and time of the payment, the amount and currency, your account details, the beneficiary name, account number and sort code / IBAN / SWIFT, and the payment reference. Reading them off a screen while the fraud analyst waits costs minutes you do not have.
Do not contact the fraudster. Not to ask, not to accuse, not to warn. The moment they know, the money moves. Any communication also risks contaminating the record.
Do not touch the mailbox yet. Nobody deletes anything, forwards anything, or moves anything into folders. If a compromise is involved, the mailbox is a crime scene and it is one of the most fragile kinds — audit logs on many platforms roll off in weeks.
Hour four to twenty-four: report and preserve
Report to the police or national fraud body. Every jurisdiction has one, and the report matters for three reasons beyond the vanishing hope of recovery: it is usually required by insurers, it is often required by the bank to progress a claim, and it is what allows law enforcement to connect your incident to the others they are already looking at. In the United States that is the FBI's Internet Crime Complaint Center, which operates a recovery-asset process specifically for fraudulent wires and is explicit that speed determines whether it can act (ic3.gov).
Preserve the evidence properly. This is where most organisations quietly destroy their own case.
- Export the original email with full headers, not a forward. A forwarded message loses the delivery trail, which is the part that cannot be faked — see reading email headers.
- Save the attachment as received. Do not open-and-resave it. Re-saving a PDF can rewrite its structure and destroy the revision history, which is often the strongest evidence you have.
- Capture the payment instruction as it was actioned, including who approved it.
- Ask IT to preserve mailbox audit logs, sign-in records and mail-forwarding rules before retention windows expire.
- Write a timeline while people still remember. Who received what, when, who approved, what was said on the phone.
Establish whether a mailbox was compromised. Check for forwarding rules nobody created, sign-ins from unexpected locations, and OAuth grants to applications nobody recognises. A malicious forwarding rule quietly copying invoice threads is the most common finding, and it means the exposure is broader than one payment.
Force credential resets on any account that may be involved, and enforce multi-factor authentication if it was not already on.
Day one to three: contain the blast radius
Check every other payment in the same conversation. These operations rarely target one invoice. Review payments to the same supplier over the preceding months, and — critically — any other supplier whose correspondence lives in the same compromised mailbox.
Call your suppliers, on numbers you already had. They may be compromised rather than you. They may have been sent redirected details for your payments. This conversation is unpleasant and it is the one that prevents the second loss.
Notify your insurer. Crime and cyber policies commonly carry notification deadlines measured in days, and late notice is a routine reason for a declined claim. Notify early even if the facts are incomplete.
Involve counsel if the amount is material, and to manage the supplier relationship — the question of who bears the loss when a payment goes to a fraudster's account is contractual and jurisdictional, and it is better addressed early.
Consider your regulatory obligations. If personal data was accessed as part of a mailbox compromise, breach-notification clocks may already be running, and they are often 72 hours from awareness.
After 72 hours: it becomes an investigation
Recall almost never succeeds beyond this point. The money has been layered through onward accounts and, frequently, out of the banking system entirely.
That does not make the work pointless, it changes what the work is for:
Establish how the instruction was accepted. Almost always there is a control that existed and was bypassed under pressure, or a control that never existed. Neither is a personal failing; both are fixable.
Fix the specific gap. In practice this is nearly always the same one: a change of payment details was accepted without independent verification. The fix is the 60-second bank detail check — a call to a number you already held, before any change is actioned, with no exceptions for urgency.
Feed what you learned back in. The lookalike domain, the sending pattern, the document that came attached. Block the domain, add the pattern to your mail rules, and tell the supplier whose identity was borrowed.
Handle the human part deliberately. The person who processed the payment is usually devastated and usually blameless — they were targeted by an operation designed by people who study exactly this. Organisations that punish get slower reporting next time, and slow reporting is what turns a recoverable loss into a permanent one.
The prevention that would have worked
Almost every case in this family comes down to one of three gaps, and all three are cheap to close:
Payment-detail changes verified out-of-band. One phone call, to a number from your own records. This defeats the attack even when every technical control was fooled.
Dual authorisation on new or changed beneficiaries. Two people, and the second one's job is specifically to check the account, not the invoice.
A first-time-sender banner on inbound mail. Most mail platforms can flag a domain nobody at the organisation has corresponded with before. The entire attack depends on the domain feeling familiar.
None of these require a project. All of them are policy changes you can make this week — and the reason to make them this week is that the window in which any of this is recoverable is measured in hours.
Frequently asked questions
Can a bank reverse a fraudulent wire transfer?
Sometimes, if it is caught quickly. The bank contacts the receiving institution to request a recall or freeze, which only works while the funds are still in the receiving account. Mule accounts are typically emptied within hours, so the first call is the one that matters.
Who do I call first after a fraudulent payment?
Your bank's fraud line, by phone. Before IT, before the supplier, before internal escalation. Everything else can happen in parallel; the recall cannot.
Should I tell the fraudster we know?
No. Any contact accelerates the onward movement of funds and can compromise evidence. Do not reply, do not warn, and do not attempt to negotiate.
How long do we have to notify our insurer?
Crime and cyber policies commonly require notification within days of discovery, and late notice is a frequent reason for declined claims. Notify as soon as you are aware, even before the facts are settled.
Put it to the test
Scan a document and get a plain-English verdict in seconds. Free to start.
Keep reading
Fake Proof of Payment: The Screenshot That Buys Three Days
Nobody fakes a payment to steal money. They fake it to buy time — long enough to collect the goods and be somewhere else when the bank tells you nothing arrived.
Reading Email Headers: The Trail a Message Can't Fake
Everything a sender types can be forged. Everything the relay servers stamped on the way through cannot be rewritten after the fact — which is why the headers are where the answer lives.
One Character Off: How Lookalike Domains Get Paid
The most effective domain in payment fraud is not a hacked one. It is a real domain, correctly configured, that differs from your supplier's by a single character nobody reads.