# Payment Fraud Prevention for Construction | RankShield Financial

> Payee verification for construction payments: draw-schedule BEC, subcontractor impersonation, deepfake executive fraud, shell vendors — every payment verdict sealed and verifiable.
>
> Source: https://rankshieldfinancial.com/industries/construction/ · RankShield Financial (verifiable pre-settlement payment security)

Industries · Construction
# The draw is scheduled. So is the fraud. RankShield Financial gives contractors, developers, and owners independent payee verification for the industry fraud targets by the calendar: every banking-detail change verified out-of-band before a draw relies on it, every payment checked against the verified payee record, and every verdict sealed to the RankShield Network as a receipt that survives disputes, audits, and lien fights.
  Request a pilot  See the integrations    payee-verified  approval-bound  verified before the draw      The ground truth    $3.05B  reported U.S. business email compromise losses in 2025 — 86% of BEC loss transactions moved by wire or ACH (FBI IC3 2025)  1      $250K  median occupational-fraud loss in construction — fourth-highest of any industry (ACFE Report to the Nations 2024)  3             01  // the attacks   The attacks, on the draw calendar
## The fraud built for how construction pays

Illustrative scenarios drawn from documented fraud families — FBI IC3 typologies, FinCEN advisories, DOJ prosecutions, and ACFE industry data — not from any named operator. Phase 1 establishes what is live in your AP.
    THREE DAYS BEFORE THE DRAW
### The subcontractor whose bank “changed”

Project rosters are public — bid tabs, permits, site signage. An attacker registers a lookalike domain of a sub on a live project and emails AP new banking details ahead of the scheduled progress payment. In the DOJ-prosecuted Adeagbo case, exactly this diverted a payment of more than $1.9 million on a university construction project. 5
  RankShield:  The signature is precise: a banking-detail change days before a large scheduled payment, from a recently registered domain, followed by a first-ever payment to the new account. That change holds until verified out-of-band with the sub through details on file — before the record, not after the wire.    A VIDEO CALL FROM THE “CFO”
### The executive who ordered the urgent wire

Executive impersonation drives roughly half of BEC attempts on businesses (AFP 2025: 49%), and it no longer requires email alone — engineering firm Arup confirmed losing $25.6 million to a deepfake video call impersonating its CFO and colleagues in 2024. 46
  RankShield:  An off-cycle payment outside the draw calendar is scored as what it is, and clearance requires out-of-band confirmation plus dual control that no urgency can waive — with a sealed receipt binding the verification to the humans who performed it.    FUNDING DAY · THE TITLE EMAIL
### Wire instructions that changed at closing

Construction-loan funding and closings run through title and escrow email threads — and a compromised thread swaps the wire instructions late, when everyone is watching the deadline instead of the account number. IC3 reported $275 million in real-estate fraud losses in 2025.
  RankShield:  Instruction changes late in an escrow window are the highest-risk class in the rules: verified against the established record and confirmed out-of-band before funds release, with the verification sealed for the closing file.    MONTH-END · THE VENDOR FILE
### The supplier that only exists on invoices

The inside version: ACFE’s industry data puts corruption in 52% of construction fraud cases and billing schemes in 38% — shell vendors and fictitious suppliers slipped into a vendor file that grows project by project.
  RankShield:  A vendor with no lien-waiver or insurance-certificate history, or a vendor account that matches an employee’s, is flagged from the vendor file itself — and every clearance in the file carries a receipt an auditor can verify.    DEADLINE DAY
### The urgency window itself

Pay applications, conditional waivers, retainage, and prompt-payment statutes make construction money large, scheduled, and deadline-bound — FinCEN has flagged large construction projects as repeat high-dollar BEC targets. Attackers time the swap so the callback is the step nobody has time for.
  RankShield:  Verification is front-loaded: banking changes are confirmed when they arrive, not when the draw is due — so deadline day releases on schedule against payees that are already verified, and the one payment that cannot be confirmed is the one that waits.         02  // the agent era   Emerging · the agent era
## Impersonation just got a face and a voice

The deepfake era is documented, not hypothetical — and the automation era is forming behind it. None of this means your firm is under attack today; it means the verification step is about to matter more, not less.
     $25.6M  lost by engineering firm Arup to a deepfake video call impersonating its CFO — confirmed by the company, 2024
Email verification habits do not survive a video call with familiar faces. The defense that does survive is procedural and recorded: out-of-band confirmation through known channels and dual control on clearance, made unskippable — with a sealed receipt proving the verification happened, whatever the caller looked like.
    $893M  in reported losses on complaints referencing AI in 2025 — the first year the FBI’s IC3 tracked it
FinCEN has warned of GenAI-falsified documents, and fully automated BEC is the projected next step — we label it that honestly: projected, not yet documented in a construction prosecution. The preparation is the same either way: payee verification that does not depend on a human judging authenticity under deadline.
        03  // the mechanics   The mechanics
## Why construction payments are schedulable targets

The fraud on this page is not opportunistic — it is planned against a calendar the attacker can read. Here is the machinery.

### The draw calendar is public enough to attack

FinCEN’s BEC advisory flagged large construction and renovation projects as repeated high-dollar targets, and its 2018 case data put the combined manufacturing-and-construction sector at the top of reported BEC — a combined category we cite precisely. The structural reason: progress payments are large, scheduled, and discoverable. Bid tabulations, permits, and site signage tell an attacker who is on the job and roughly when money moves; pay-application cycles, conditional lien-waiver exchanges, and prompt-payment statutes tell them the deadline pressure the fraud will ride. A payee-swap timed three days before a known draw is not luck — it is logistics. 2

### What one prosecution teaches about the whole family

The Adeagbo case is worth studying because it contains no sophistication anywhere except the timing. A lookalike domain of a legitimate construction company, an email in a real employee’s name, and a request that AP update banking details before the next progress payment — that was the entire attack, and it moved more than $1.9 million from a university project. Every element was checkable: the domain’s registration age, the mismatch with the contractor’s known contact record, the first-ever payment to a new account. The lesson is not that attackers are brilliant; it is that unverified trust in a busy AP inbox is the whole vulnerability. 5

### The recovery math, read honestly

When a diverted wire is reported fast, the FBI’s Recovery Asset Team can attempt a freeze through the Financial Fraud Kill Chain — and in 2025 it froze $679 million, succeeding on 58% of the cases it could act on. The denominator is the honest part: that covers only victims who reported in time and were still inside the freeze window, a fraction of the $3.05 billion in reported BEC losses, 86% of which moved on wire and ACH rails built for settlement finality. One documented municipal case recovered a $6 million construction-related wire because it was reported almost immediately. Recovery rewards speed; prevention removes the race entirely. 1

### What the survey data adds

The AFP’s practitioner survey — the treasury profession’s own measurement — found 79% of organizations experienced attempted or actual payments fraud in 2024, with BEC the most-cited method at 63%, vendor impersonation reported by 60%, and executive impersonation by 49%. Wires, construction’s default rail for draws, were the payment type most targeted by BEC. None of this is construction-specific, and we do not pretend otherwise — but an industry whose payment profile is large, scheduled, wire-borne, and vendor-dense sits squarely in the pattern the whole dataset describes. 4
        04  // check your exposure   An honest two-minute read
## Five questions that predict your exposure

Each question maps to a control an authority actually recommends for this industry. The tally runs in your browser — nothing is transmitted.

- 01 Would your AP desk update a subcontractor’s banking details on the strength of a well-written email?
- 02 Is an out-of-band callback — to a number on file, not from the email — required before the first payment to changed details?
- 03 Can one person both edit vendor banking details and release a draw payment?
- 04 Do off-cycle or “urgent” wire requests require dual sign-off regardless of who asks?
- 05 Do vendors in your file all have lien-waiver and insurance-certificate history behind them?

Answer all 5 to see where you stand · 0/5
        05  // the stack   No rip-and-replace
## It plugs into construction AP as it runs today

Construction finance runs on ERPs and AP automation the industry already trusts. RankShield adds the independent verification layer beside them — see the integration paths already published.
   AvidXchange  Sage Intacct  NetSuite  QuickBooks  Bill.com  All integrations        06  // rollout   Observe first, enforce when earned
## Deployment that cannot break a store

Every phase defaults to no-change. Nothing is blocked until observe mode has proven its accuracy on your own traffic.
    PHASE 1
### Historical baseline on your own AP

Sixty to ninety days of vendor-file history and payment records through the rule set, offline: every banking change, every first payment to new details, every vendor without a document trail — what would have held, and why.
   PHASE 2
### Observe mode across live projects

Live vendor and payment data scored advisory-only. Finance sees the holds that would have happened; draws release exactly as before. Accuracy is earned on your projects before anything gates.
   PHASE 3
### Verification before the money moves

High-risk changes hold for automated out-of-band verification; dual control becomes unskippable on clearance; every verdict seals to the RankShield Network — evidence for the audit, the insurer, and the lien fight.
        What we claim, and what we do not
## Landscape is not evidence — your data is

The scenarios on this page are illustrative and the statistics are industry-level measurements from primary sources — none of it claims that any specific operator is under attack, and none of it comes from customer data. We also do not claim in-flight authorization declines, which require a position in the payment path we do not hold. What we offer is precise: per-terminal detection on feeds you already own, near-real-time operational response, and a sealed, independently verifiable receipt behind [every verdict](https://rankshieldfinancial.com/verifiable-attestation/). Phase 1 replaces this landscape with findings from your own stores.
       Across the verticals
## Fraud defense, industry by industry
   Fuel & convenience stores  Restaurants & QSR  Wholesale distribution  Auto dealers  Trucking & logistics  Manufacturing  All industries    How payee verification works  What a sealed receipt proves  How the rail works end to end        Primary sources
## References

The load-bearing statistics on this page trace to the sources below — government, regulator, and association primaries first. Measurements from industry vendors are labeled as such.

- [FBI IC3 — 2025 Internet Crime Report](https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf)
- [FinCEN — Updated Advisory on Email Compromise Fraud (FIN-2019-A005)](https://www.fincen.gov/sites/default/files/2019-07/Updated%20BEC%20Advisory%20FINAL%20508.pdf)
- [ACFE — Occupational Fraud 2024: A Report to the Nations](https://www.acfe.com/-/media/files/acfe/pdfs/rttn/2024/2024-report-to-the-nations.pdf)
- [AFP — 2025 Payments Fraud and Control Survey (press release)](https://www.financialprofessionals.org/about/learn-more/press-releases/Details/over-75-percent-of-us-firms-experienced-payments-fraud-in-2025-while-ai-adoption-for-fraud-mitigation-lags)
- [U.S. DOJ — Previously Extradited Nigerian National Sentenced (construction progress-payment BEC)](https://www.justice.gov/usao-wdnc/pr/previously-extradited-nigerian-national-sentenced-role-multimillion-dollar-business)
- [CNN — Arup confirms $25.6M deepfake video-call fraud (company-confirmed report)](https://www.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk)
- [FinCEN — Alert on Fraud Schemes Involving Deepfake Media (FIN-2024-Alert004)](https://www.fincen.gov/system/files/shared/FinCEN-Alert-DeepFakes-Alert508FINAL.pdf)
- [FBI IC3 — 2024 Internet Crime Report](https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf)

     FAQ
## Construction, answered

Every question buyers ask before they trust a payment-security platform, answered directly.
           JAMIE KLONCZ · RANKSHIELD FINANCIAL           ONLINE
Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.
      REQUEST ACCESS →             Verify, then settle
## Start with a findings report on your own stores.

Sixty to ninety days of your existing journal and authorization history, through the full rule set, offline. What would have been caught, where — before anything touches production.
  Request a pilot  See the integrations

## Frequently asked questions

### Why is construction such a strong target for payment fraud?

Because the industry pays in a way attackers can schedule against. Progress payments and draws are large, calendared, and deadline-bound — pay applications, conditional lien waivers, retainage releases, prompt-payment statutes — and the project roster is effectively public through bid tabulations, permits, and site signage. An attacker knows who is on the job, who owes whom, and roughly when the money moves; FinCEN has flagged large construction and renovation projects as repeated high-dollar targets for exactly this reason. The fraud then rides the deadline: a banking-detail change timed days before a draw, with urgency doing the work of suppressing the one phone call that would catch it.

### What does a real case actually look like?

The DOJ-prosecuted Adeagbo case is the template. The attacker registered a lookalike domain of a construction company working on a university project, emailed as one of its employees, and redirected a progress payment of more than $1.9 million. Nothing was hacked in the Hollywood sense — no malware, no breached bank. A convincing domain, a plausible email, and a payment calendar the attacker could read from public records were the whole attack. The defense that stops it is equally unglamorous: independent verification of the banking-detail change through contacts on file before the payment relies on it, made unskippable. That is the product.

### If a wire goes out, can the money be recovered?

Sometimes — and the honest framing matters. When fraud is reported fast, the FBI’s Recovery Asset Team can attempt to freeze funds: in 2025 it succeeded on 58% of the cases it could act on, freezing $679 million of $1.16 billion attempted. Read the denominator carefully: that covers only victims who reported in time and were still inside the freeze window, a fraction of total losses — and 86% of BEC losses move by wire or ACH, rails built to settle with finality. Recovery is a backstop that works sometimes. Verification before release is the control. We build for the second and prepare the evidence pack for the first.

### Will verification slow down our draws?

No — and the design reason is worth understanding, because deadline pressure is precisely the mechanism this fraud exploits. Verification is front-loaded: a banking-detail change is confirmed out-of-band when it arrives, in the quiet days before it matters, not on funding day. By the time a draw executes, every payee on it is already verified and releases on schedule, each with a sealed receipt. The only payment that waits is the one whose details changed inside the deadline window and could not be confirmed — which is exactly the payment that should wait a day rather than fund a fraudster on time.

### What about deepfakes — can technology even tell anymore?

Wrong question, honestly answered: the defense is not detecting the fake, it is making authenticity irrelevant to the payment decision. Arup — a world-class engineering firm — confirmed losing $25.6 million to a deepfake video call of its own CFO; the FBI’s IC3 logged $893 million in reported losses on AI-referenced complaints in its first year tracking them. A control that depends on a human judging whether a face or voice is real will lose that race. A control that requires out-of-band confirmation through known channels and dual sign-off before money moves — regardless of how convincing the request was — does not care how good the fake is. That procedural control, automated, recorded, and sealed, is what RankShield deploys.
