The email looked completely normal. Same vendor, same logo, same guy who'd been sending invoices for three years. Same casual tone, same "Hope your week's going well" opener.

The only thing different was one line near the bottom. "Quick heads up, we switched banks this quarter. Updated ACH details attached. Please use these going forward."

The bookkeeper at a client's company updated the vendor record that afternoon. Two weeks later, they paid a 46,000 dollar invoice to the new account. The real vendor called a month after that asking where their money was.

The money was gone. The vendor's email had been compromised for weeks. The scammer had been reading the thread, learning the rhythm, waiting for a big invoice. When it came, they swapped one line.

That's business email compromise, and it is not a story about a dumb employee. That bookkeeper did exactly what the process allowed. The process was the problem.

This week's Deep Dive is the payment gate I'd build for any business that moves money, from a two-person shop to a 50-person operation. Monday we locked down your personal perimeter. Today we lock down the business.

How big this actually is

The FBI's internet crime report for 2025 logged about 3.05 billion dollars in business email compromise losses across 24,768 complaints. That works out to roughly 123,000 dollars per incident. BEC has been the most expensive fraud aimed at businesses for years running, and it dwarfs ransomware, which gets all the headlines. Reported ransomware losses for the same year were around 32 million dollars. BEC was nearly a hundred times larger.

The treasury side tells the same story. The 2026 payments fraud survey from the Association for Financial Professionals found that 76 percent of organizations faced attempted or actual payments fraud in 2025, and 74 percent dealt with BEC specifically. Checks were still the payment type most often hit, with 58 percent of organizations reporting check fraud.

And here's why I'm writing this in October instead of March. Q4 is when payment volume spikes. Year-end vendor payments. Holiday staffing. Bonuses. And right around the corner, W-9 and 1099 season, which gives scammers a perfect excuse to email your finance person asking to "confirm banking and tax details." For payments made in 2026, the 1099-NEC reporting threshold rose from 600 to 2,000 dollars, so expect a wave of genuinely confused vendors this January, and scammers happy to use the confusion as cover.

The principle: never trust the channel the request came in on

Every control below comes back to one idea. A request to move money or change payment details can never be verified through the same channel it arrived on.

If the request came by email, you don't verify by replying to the email. The scammer is in the email. If it came by phone, you don't verify by calling back the number that called you. The scammer controls that number. You verify through a channel you already had before the request showed up.

Simple to say. Hard to enforce when someone's busy, the request looks normal, and the person asking sounds like your boss. That's why it has to be built into the process, not left to judgment.

Gate 1: Lock the vendor master file

The most dangerous button in your entire business isn't "send payment." It's "edit vendor bank details." Every change after that point sends money somewhere new, quietly, on autopilot.

So that button gets its own rules:

Callback to the number on file. Any request to change bank details gets verified with a phone call to the number already in your system, or the one on the vendor's original contract. Never a number in the email, the PDF, or the signature block of the message asking for the change.

Cooling-off period. New bank details don't go live for five business days. Legit vendors don't care. Scammers hate it, because their window is usually measured in days before the real vendor notices.

Second approver. The person who enters the change can't be the person who approves it.

Notify the old contact. After any change, send a confirmation to the vendor's original contact email and phone. If they didn't request it, you'll find out before you pay, not after.

Test payment. For large or new payees, send a 1 dollar test and have the vendor confirm the amount they received through your callback number.

Gate 2: Two keys on every payment that matters

Pick a threshold. For a small business it might be 2,500 dollars. For a larger one, 10,000. Anything above it needs two people: one to set it up, one to release it. Your bank almost certainly supports this inside its business portal. It's usually called dual control or dual approval, and most owners never turn it on because it's buried in an admin menu.

Owners, this includes you. The "CEO" emailing the bookkeeper for an urgent wire before a closing is one of the oldest plays in the book, and it now comes with a cloned voice on the follow-up call. Back in 2024, a finance employee at the engineering firm Arup in Hong Kong sent roughly 25 million dollars after a video call where the CFO and several colleagues were all deepfakes. Everyone on that call was fake except him.

If your team knows that even you can't skip the second key, there's nothing for a scammer to exploit by pretending to be you.

Gate 3: Make your bank do some of the work

Banks offer a bunch of fraud tools for business accounts that sit unused because nobody asked for them. Call your business banker this week and ask about these by name.

Positive Pay for checks. You upload a file of the checks you actually issued. Anything presented that doesn't match the amount, number, or payee gets flagged for you to approve or reject. Given that check fraud is still the most common type, this is the highest-value tool on the list for anyone who still writes checks.

ACH debit block or filter. Blocks anyone from pulling money out of your account by ACH unless you've pre-approved them. Your payroll provider and tax payments go on the allow list. Everyone else gets stopped.

Separate the accounts. Keep a disbursement account that only gets funded with what's needed to cover approved payments. Your operating reserves sit in a different account that never pays anyone directly. If the disbursement account gets hit, the blast radius is small.

Lock down wires. Turn off international wires if you don't send them. Lower daily limits. Require out-of-band confirmation for any wire.

Gate 4: Harden the email itself

BEC works because email is easy to fake and easy to break into. Three fixes close most of the gap.

Set up your domain's email authentication. SPF, DKIM, and DMARC are three DNS records that tell the world which servers are allowed to send email as your company. With DMARC set to reject, someone spoofing your domain gets their email bounced instead of delivered to your customers and vendors. Your IT person or email provider can set this up in under an hour. If you don't know whether you have it, you probably don't.

Tag external email. Most email platforms can add a banner to any message from outside your company. It sounds small. It catches a lot of "CEO" emails that come from lookalike addresses with one letter swapped.

Phishing-resistant logins for anyone who touches money. Your bookkeeper, controller, and anyone with bank access should log into email and banking with a passkey or a hardware key, not a password and a text code. Most compromised vendor inboxes start with one stolen password.

Gate 5: Get out of the check business

Checks are slow, they travel through the mail, and they can be stolen out of a blue mailbox, washed with chemicals, and rewritten for a bigger amount to a different payee. It's a 1950s payment method trying to survive in a world of organized fraud rings.

The federal government saw this coming. A 2025 executive order directed agencies to phase out paper checks for most federal payments starting September 30, 2025. If Washington is getting out of checks, you can too.

Move as many vendors as you can to ACH or a payables platform. For the checks you still send, mail them from inside the post office, not a collection box, and use Positive Pay. For checks you receive, push customers toward electronic payment with a small incentive or a slightly faster payment term.

Gate 6: The first-hour plan

Even with every gate built, someday something might slip through. In BEC, the difference between getting money back and losing it is often measured in hours.

So write this down now, while nobody's panicking:

Minute one: Call your bank's fraud line and ask them to recall the payment. Use the phone number on your card or your banker's direct line, not anything in the suspicious email.

Same hour: File a complaint at ic3.gov. For qualifying international wires, the FBI's Recovery Asset Team works with banks to freeze funds, and it works best inside the first 72 hours.

Same day: Lock down the compromised mailbox. Reset passwords, kill active sessions, and check for forwarding rules. Attackers love to quietly forward copies of every email to an outside address. Then notify your cyber insurance carrier if you have a policy, because many policies have notification deadlines.

Print this on one page. Tape it next to whoever runs payables. Nobody thinks clearly at 4:45 on a Friday when they realize the money's gone.

Automate the gate so it doesn't depend on memory

Policies written in a Google Doc don't stop fraud. Policies baked into the workflow do.

Here's the setup I helped that client build after the 46,000 dollar hit. Vendor bank change requests no longer go through email at all. Vendors fill out a short form. A Make.com scenario takes the submission, compares it against the vendor's existing record, and creates a task for the callback with the number pulled from the original contract, not from the form. It starts the five-day clock, emails the vendor's original contact to confirm, and only after a second person marks the callback complete does it flag the change as approved for the bookkeeper to enter. Any email that comes in with words like "updated banking," "new account," or "change of remittance" gets auto-labeled and replied to with a link to the form, so it never gets handled informally again.

For writing the policy itself, I'd use Galaxy.ai. Give it your team size, your payment types, your bank, and the thresholds you picked, and have it draft a one-page payment controls policy plus a short training script for your team. Then edit it to sound like you, and have everyone who touches money sign it.

And when you run the 20-minute walkthrough with your team, record it with Fathom. New hires watch it in their first week. You'll have proof that everyone was trained, which some insurers and auditors will ask about. Cheap insurance on the insurance.

What this costs you vs. what it saves

Let's be honest about the friction. Dual approval adds a few minutes to some payments. The cooling-off period occasionally means a vendor waits an extra week the first time they change banks. Your bookkeeper will grumble for about a month.

Now compare that to a single average BEC loss of roughly 123,000 dollars. For most small businesses, that's not a bad quarter. That's a layoff, a missed payroll, or a personal guarantee getting called.

The math isn't close. The friction is the product.

What this is really about

Most owners file fraud prevention under tech problems they'll get to later. Really, it's an operations problem, and you already know how to solve operations problems. You decide what the process is, you write it down, you build it into the tools, and you make it impossible to skip.

The bookkeeper at my client's company still works there. She's the one who runs the callback process now, and she's ruthless about it. Last month she caught a fake bank change request from what looked like their biggest supplier. Same logo. Same guy. Same "Hope your week's going well."

The gate held.

Want the whole system ready to deploy?

I built The Payment Gate Kit so you can stand this up in a week. It includes the six-gate controls checklist, a vendor bank change verification form and callback script, the Make.com workflow blueprint from above, a one-page payment controls policy template you can customize, the bank call script listing every fraud tool to ask about by name, a DMARC setup checklist to hand your IT person, and the first-hour response card to print and tape next to your payables desk.

Reply to this email with the word GATE and I'll send it over.

About the room.

Inside The Grid Inner Circle, we don't just talk about systems like this. We build them, live, with your actual setup on the screen. This month's sessions cover both of this week's builds: the personal perimeter and the payment gate, with members walking through their bank settings and workflows in real time.

Monthly membership is 29 dollars. But the one I'd point you to is the lifetime seat at 499 dollars. One payment, no renewals, every future system and live call included for as long as the Circle runs. It's the founding price, and it's gone once the room fills.

Reply with the word LIFETIME and I'll send you the details and the link.

See you Sunday.

Alex Rivera, Wealth Architect at Wealth Grid

Recommended for you

View all
caret-right