Finance Index
We sent money to a fraudster's account - what do we do right now, in order?
Reference guide to payment fraud first 24 hours, including payment timing, method choices, control points, reconciliation, and vendor communication.
Act in the first hours, in this order: (1) call your bank's fraud line and request a recall/reversal immediately; (2) have your bank contact the receiving bank to freeze the funds; (3) file with the FBI's IC3 (ic3.gov) and ask for the Recovery Asset Team; (4) file a local police report; (5) notify your insurer. Speed is everything - recovery odds fall sharply after the first 24 - 72 hours.
At a Glance
| Aspect | Short Answer | Why It Matters |
|---|---|---|
| We sent money | Act in the first hours, in this order: (1) call your bank's fraud line and request a recall/reversal immediately. | Keeps vendor records and payment decisions reliable. |
| Risk check | When you file a qualifying fraudulent-wire complaint at ic3.gov fast enough, IC3's Recovery Asset Team can initiate the Financial Fraud Kill Chain - coordinating with the receiving bank to freeze funds before they're withdrawn or moved offshore. | Reduces payment errors, timing issues, and reconciliation cleanup. |
| Realistic recovery odds | Reported within 24 hours to cooperative domestic banks, recovery is genuinely possible - funds may still be sitting in the receiving account. | Keeps vendor records and payment decisions reliable. |
| Who do we call first | Your bank first (they initiate the recall and contact the receiving bank), then IC3 (ic3.gov, request the Recovery Asset Team), then local police, then your insurer - but if you have multiple people, run these in parallel; minutes matter. | Keeps vendor records and payment decisions reliable. |
| Request a wire recall | Call the fraud line, state it's fraud, and provide the date, amount, sending and receiving account/routing, trace or IMAD/OMAD reference, and a brief incident description; the bank sends a recall request. | Reduces payment errors, timing issues, and reconciliation cleanup. |
How does the fbi ic3 recovery asset team / financial fraud kill chain work?
When you file a qualifying fraudulent-wire complaint at ic3.gov fast enough, IC3's Recovery Asset Team can initiate the Financial Fraud Kill Chain - coordinating with the receiving bank to freeze funds before they're withdrawn or moved offshore. It works only within a tight window (generally measured in hours to a couple of days) and above certain thresholds, which is exactly why you file immediately rather than waiting to investigate internally.
What are realistic recovery odds, and what changes after 72 hours?
Reported within 24 hours to cooperative domestic banks, recovery is genuinely possible - funds may still be sitting in the receiving account. After 72 hours, fraudsters have typically layered the money through mule accounts or moved it abroad, and recovery odds drop steeply. The clock, not the amount, is the primary determinant of getting money back.
Who do we call first - our bank, the receiving bank, ic3, law enforcement, or our insurer?
Your bank first (they initiate the recall and contact the receiving bank), then IC3 (ic3.gov, request the Recovery Asset Team), then local police, then your insurer - but if you have multiple people, run these in parallel; minutes matter.
How do I request a wire recall or ACH reversal on fraud grounds, and what does the bank need?
Call the fraud line, state it's fraud, and provide the date, amount, sending and receiving account/routing, trace or IMAD/OMAD reference, and a brief incident description; the bank sends a recall request - for ACH, fraud isn't a standard return reason, so it becomes a recall/dispute, which is why prevention beats remedy.
What should a written payment-fraud incident response plan contain?
Named roles and a call tree, the bank fraud-line and IC3 details, step-by-step scripts for the first hour, evidence-preservation instructions (don't delete the email, capture headers), insurer notice requirements, and a post-incident control-review checklist.
Does cyber or crime insurance cover BEC losses?
It depends on the policy: computer-fraud coverage often excludes losses where an employee voluntarily transferred funds (as in BEC), while social-engineering fraud coverage is specifically designed for it - many BEC claims fail because the company carried only the former. Confirm you have social-engineering coverage and know its sublimit.
We discovered the fraud three weeks later during bank rec - is recovery hopeless?
Recovery odds are low but not zero; still file with IC3 and police, notify your insurer within policy deadlines, request a recall, and - most importantly - complete a control remediation, because late discovery is itself a finding about your reconciliation cadence.
How do we preserve email evidence and headers after a BEC incident?
Do not delete or forward-and-delete the messages; export the full original emails including headers (which show true routing), preserve them in a separate location, document who had access, and hand them to investigators and your insurer intact.
After a fraud event, what should the post-incident control review cover before payments resume?
Re-verify every recently changed vendor bank detail, confirm segregation of duties and dual control are intact, check for compromised credentials and reset them, validate callback procedures are being followed, and document the gaps the incident exposed and how they're closed.
Do we have to disclose a payment fraud loss to auditors, the board, or anyone else?
Material losses generally require disclosure to auditors and, depending on size and circumstances, the board; insurers and possibly regulators have notice requirements too - set the materiality threshold with finance leadership and counsel rather than deciding ad hoc.
Stampli perspective
Incident recovery is a bank, law-enforcement, and insurer process - not a software function. Stampli's role is upstream: payment-integrity controls and validation guardrails that flag suspicious changes and block payments on unverified details aim to prevent the diversion, and the immutable audit trail provides the who-approved-what-and-when record investigators and insurers request after the fact.