Request access
Industries · Construction

The draw is scheduled.So is the fraud.RankShield Financial gives contractors, developers, and owners independent payee verification for the industry fraud targets by the calendar: every banking-detail change verified out-of-band before a draw relies on it, every payment checked against the verified payee record, and every verdict sealed to the RankShield Network as a receipt that survives disputes, audits, and lien fights.

payee-verifiedapproval-boundverified before the draw
The ground truth
$3.05B
reported U.S. business email compromise losses in 2025 — 86% of BEC loss transactions moved by wire or ACH (FBI IC3 2025)1
$250K
median occupational-fraud loss in construction — fourth-highest of any industry (ACFE Report to the Nations 2024)3
01 // the attacks
The attacks, on the draw calendar

The fraud built for how construction pays

Illustrative scenarios drawn from documented fraud families — FBI IC3 typologies, FinCEN advisories, DOJ prosecutions, and ACFE industry data — not from any named operator. Phase 1 establishes what is live in your AP.

THREE DAYS BEFORE THE DRAW

The subcontractor whose bank “changed”

Project rosters are public — bid tabs, permits, site signage. An attacker registers a lookalike domain of a sub on a live project and emails AP new banking details ahead of the scheduled progress payment. In the DOJ-prosecuted Adeagbo case, exactly this diverted a payment of more than $1.9 million on a university construction project.5

RankShield: The signature is precise: a banking-detail change days before a large scheduled payment, from a recently registered domain, followed by a first-ever payment to the new account. That change holds until verified out-of-band with the sub through details on file — before the record, not after the wire.
A VIDEO CALL FROM THE “CFO”

The executive who ordered the urgent wire

Executive impersonation drives roughly half of BEC attempts on businesses (AFP 2025: 49%), and it no longer requires email alone — engineering firm Arup confirmed losing $25.6 million to a deepfake video call impersonating its CFO and colleagues in 2024.46

RankShield: An off-cycle payment outside the draw calendar is scored as what it is, and clearance requires out-of-band confirmation plus dual control that no urgency can waive — with a sealed receipt binding the verification to the humans who performed it.
FUNDING DAY · THE TITLE EMAIL

Wire instructions that changed at closing

Construction-loan funding and closings run through title and escrow email threads — and a compromised thread swaps the wire instructions late, when everyone is watching the deadline instead of the account number. IC3 reported $275 million in real-estate fraud losses in 2025.

RankShield: Instruction changes late in an escrow window are the highest-risk class in the rules: verified against the established record and confirmed out-of-band before funds release, with the verification sealed for the closing file.
MONTH-END · THE VENDOR FILE

The supplier that only exists on invoices

The inside version: ACFE’s industry data puts corruption in 52% of construction fraud cases and billing schemes in 38% — shell vendors and fictitious suppliers slipped into a vendor file that grows project by project.

RankShield: A vendor with no lien-waiver or insurance-certificate history, or a vendor account that matches an employee’s, is flagged from the vendor file itself — and every clearance in the file carries a receipt an auditor can verify.
DEADLINE DAY

The urgency window itself

Pay applications, conditional waivers, retainage, and prompt-payment statutes make construction money large, scheduled, and deadline-bound — FinCEN has flagged large construction projects as repeat high-dollar BEC targets. Attackers time the swap so the callback is the step nobody has time for.

RankShield: Verification is front-loaded: banking changes are confirmed when they arrive, not when the draw is due — so deadline day releases on schedule against payees that are already verified, and the one payment that cannot be confirmed is the one that waits.
02 // the agent era
Emerging · the agent era

Impersonation just got a face and a voice

The deepfake era is documented, not hypothetical — and the automation era is forming behind it. None of this means your firm is under attack today; it means the verification step is about to matter more, not less.

$25.6M
lost by engineering firm Arup to a deepfake video call impersonating its CFO — confirmed by the company, 2024

Email verification habits do not survive a video call with familiar faces. The defense that does survive is procedural and recorded: out-of-band confirmation through known channels and dual control on clearance, made unskippable — with a sealed receipt proving the verification happened, whatever the caller looked like.

$893M
in reported losses on complaints referencing AI in 2025 — the first year the FBI’s IC3 tracked it

FinCEN has warned of GenAI-falsified documents, and fully automated BEC is the projected next step — we label it that honestly: projected, not yet documented in a construction prosecution. The preparation is the same either way: payee verification that does not depend on a human judging authenticity under deadline.

03 // the mechanics
The mechanics

Why construction payments are schedulable targets

The fraud on this page is not opportunistic — it is planned against a calendar the attacker can read. Here is the machinery.

The draw calendar is public enough to attack

FinCEN’s BEC advisory flagged large construction and renovation projects as repeated high-dollar targets, and its 2018 case data put the combined manufacturing-and-construction sector at the top of reported BEC — a combined category we cite precisely. The structural reason: progress payments are large, scheduled, and discoverable. Bid tabulations, permits, and site signage tell an attacker who is on the job and roughly when money moves; pay-application cycles, conditional lien-waiver exchanges, and prompt-payment statutes tell them the deadline pressure the fraud will ride. A payee-swap timed three days before a known draw is not luck — it is logistics.2

What one prosecution teaches about the whole family

The Adeagbo case is worth studying because it contains no sophistication anywhere except the timing. A lookalike domain of a legitimate construction company, an email in a real employee’s name, and a request that AP update banking details before the next progress payment — that was the entire attack, and it moved more than $1.9 million from a university project. Every element was checkable: the domain’s registration age, the mismatch with the contractor’s known contact record, the first-ever payment to a new account. The lesson is not that attackers are brilliant; it is that unverified trust in a busy AP inbox is the whole vulnerability.5

The recovery math, read honestly

When a diverted wire is reported fast, the FBI’s Recovery Asset Team can attempt a freeze through the Financial Fraud Kill Chain — and in 2025 it froze $679 million, succeeding on 58% of the cases it could act on. The denominator is the honest part: that covers only victims who reported in time and were still inside the freeze window, a fraction of the $3.05 billion in reported BEC losses, 86% of which moved on wire and ACH rails built for settlement finality. One documented municipal case recovered a $6 million construction-related wire because it was reported almost immediately. Recovery rewards speed; prevention removes the race entirely.1

What the survey data adds

The AFP’s practitioner survey — the treasury profession’s own measurement — found 79% of organizations experienced attempted or actual payments fraud in 2024, with BEC the most-cited method at 63%, vendor impersonation reported by 60%, and executive impersonation by 49%. Wires, construction’s default rail for draws, were the payment type most targeted by BEC. None of this is construction-specific, and we do not pretend otherwise — but an industry whose payment profile is large, scheduled, wire-borne, and vendor-dense sits squarely in the pattern the whole dataset describes.4

04 // check your exposure
An honest two-minute read

Five questions that predict your exposure

Each question maps to a control an authority actually recommends for this industry. The tally runs in your browser — nothing is transmitted.

  1. 01Would your AP desk update a subcontractor’s banking details on the strength of a well-written email?
  2. 02Is an out-of-band callback — to a number on file, not from the email — required before the first payment to changed details?
  3. 03Can one person both edit vendor banking details and release a draw payment?
  4. 04Do off-cycle or “urgent” wire requests require dual sign-off regardless of who asks?
  5. 05Do vendors in your file all have lien-waiver and insurance-certificate history behind them?

Answer all 5 to see where you stand · 0/5

05 // the stack
No rip-and-replace

It plugs into construction AP as it runs today

Construction finance runs on ERPs and AP automation the industry already trusts. RankShield adds the independent verification layer beside them — see the integration paths already published.

AvidXchangeSage IntacctNetSuiteQuickBooksBill.comAll integrations
06 // rollout
Observe first, enforce when earned

Deployment that cannot break a store

Every phase defaults to no-change. Nothing is blocked until observe mode has proven its accuracy on your own traffic.

PHASE 1

Historical baseline on your own AP

Sixty to ninety days of vendor-file history and payment records through the rule set, offline: every banking change, every first payment to new details, every vendor without a document trail — what would have held, and why.

PHASE 2

Observe mode across live projects

Live vendor and payment data scored advisory-only. Finance sees the holds that would have happened; draws release exactly as before. Accuracy is earned on your projects before anything gates.

PHASE 3

Verification before the money moves

High-risk changes hold for automated out-of-band verification; dual control becomes unskippable on clearance; every verdict seals to the RankShield Network — evidence for the audit, the insurer, and the lien fight.

What we claim, and what we do not

Landscape is not evidence — your data is

The scenarios on this page are illustrative and the statistics are industry-level measurements from primary sources — none of it claims that any specific operator is under attack, and none of it comes from customer data. We also do not claim in-flight authorization declines, which require a position in the payment path we do not hold. What we offer is precise: per-terminal detection on feeds you already own, near-real-time operational response, and a sealed, independently verifiable receipt behind every verdict. Phase 1 replaces this landscape with findings from your own stores.

FAQ

Construction, answered

Every question buyers ask before they trust a payment-security platform, answered directly.

JAMIE KLONCZ · RANKSHIELD FINANCIAL ONLINE

Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.

REQUEST ACCESS →
Verify, then settle

Start with a findings report on your own stores.

Sixty to ninety days of your existing journal and authorization history, through the full rule set, offline. What would have been caught, where — before anything touches production.

Request a pilotSee the integrations