The draw is scheduled.So is the fraud.RankShield Financial gives contractors, developers, and owners independent payee verification for the industry fraud targets by the calendar: every banking-detail change verified out-of-band before a draw relies on it, every payment checked against the verified payee record, and every verdict sealed to the RankShield Network as a receipt that survives disputes, audits, and lien fights.
The fraud built for how construction pays
Illustrative scenarios drawn from documented fraud families — FBI IC3 typologies, FinCEN advisories, DOJ prosecutions, and ACFE industry data — not from any named operator. Phase 1 establishes what is live in your AP.
The subcontractor whose bank “changed”
Project rosters are public — bid tabs, permits, site signage. An attacker registers a lookalike domain of a sub on a live project and emails AP new banking details ahead of the scheduled progress payment. In the DOJ-prosecuted Adeagbo case, exactly this diverted a payment of more than $1.9 million on a university construction project.5
The executive who ordered the urgent wire
Executive impersonation drives roughly half of BEC attempts on businesses (AFP 2025: 49%), and it no longer requires email alone — engineering firm Arup confirmed losing $25.6 million to a deepfake video call impersonating its CFO and colleagues in 2024.46
Wire instructions that changed at closing
Construction-loan funding and closings run through title and escrow email threads — and a compromised thread swaps the wire instructions late, when everyone is watching the deadline instead of the account number. IC3 reported $275 million in real-estate fraud losses in 2025.
The supplier that only exists on invoices
The inside version: ACFE’s industry data puts corruption in 52% of construction fraud cases and billing schemes in 38% — shell vendors and fictitious suppliers slipped into a vendor file that grows project by project.
The urgency window itself
Pay applications, conditional waivers, retainage, and prompt-payment statutes make construction money large, scheduled, and deadline-bound — FinCEN has flagged large construction projects as repeat high-dollar BEC targets. Attackers time the swap so the callback is the step nobody has time for.
Impersonation just got a face and a voice
The deepfake era is documented, not hypothetical — and the automation era is forming behind it. None of this means your firm is under attack today; it means the verification step is about to matter more, not less.
Email verification habits do not survive a video call with familiar faces. The defense that does survive is procedural and recorded: out-of-band confirmation through known channels and dual control on clearance, made unskippable — with a sealed receipt proving the verification happened, whatever the caller looked like.
FinCEN has warned of GenAI-falsified documents, and fully automated BEC is the projected next step — we label it that honestly: projected, not yet documented in a construction prosecution. The preparation is the same either way: payee verification that does not depend on a human judging authenticity under deadline.
Why construction payments are schedulable targets
The fraud on this page is not opportunistic — it is planned against a calendar the attacker can read. Here is the machinery.
The draw calendar is public enough to attack
FinCEN’s BEC advisory flagged large construction and renovation projects as repeated high-dollar targets, and its 2018 case data put the combined manufacturing-and-construction sector at the top of reported BEC — a combined category we cite precisely. The structural reason: progress payments are large, scheduled, and discoverable. Bid tabulations, permits, and site signage tell an attacker who is on the job and roughly when money moves; pay-application cycles, conditional lien-waiver exchanges, and prompt-payment statutes tell them the deadline pressure the fraud will ride. A payee-swap timed three days before a known draw is not luck — it is logistics.2
What one prosecution teaches about the whole family
The Adeagbo case is worth studying because it contains no sophistication anywhere except the timing. A lookalike domain of a legitimate construction company, an email in a real employee’s name, and a request that AP update banking details before the next progress payment — that was the entire attack, and it moved more than $1.9 million from a university project. Every element was checkable: the domain’s registration age, the mismatch with the contractor’s known contact record, the first-ever payment to a new account. The lesson is not that attackers are brilliant; it is that unverified trust in a busy AP inbox is the whole vulnerability.5
The recovery math, read honestly
When a diverted wire is reported fast, the FBI’s Recovery Asset Team can attempt a freeze through the Financial Fraud Kill Chain — and in 2025 it froze $679 million, succeeding on 58% of the cases it could act on. The denominator is the honest part: that covers only victims who reported in time and were still inside the freeze window, a fraction of the $3.05 billion in reported BEC losses, 86% of which moved on wire and ACH rails built for settlement finality. One documented municipal case recovered a $6 million construction-related wire because it was reported almost immediately. Recovery rewards speed; prevention removes the race entirely.1
What the survey data adds
The AFP’s practitioner survey — the treasury profession’s own measurement — found 79% of organizations experienced attempted or actual payments fraud in 2024, with BEC the most-cited method at 63%, vendor impersonation reported by 60%, and executive impersonation by 49%. Wires, construction’s default rail for draws, were the payment type most targeted by BEC. None of this is construction-specific, and we do not pretend otherwise — but an industry whose payment profile is large, scheduled, wire-borne, and vendor-dense sits squarely in the pattern the whole dataset describes.4
Five questions that predict your exposure
Each question maps to a control an authority actually recommends for this industry. The tally runs in your browser — nothing is transmitted.
- 01Would your AP desk update a subcontractor’s banking details on the strength of a well-written email?
- 02Is an out-of-band callback — to a number on file, not from the email — required before the first payment to changed details?
- 03Can one person both edit vendor banking details and release a draw payment?
- 04Do off-cycle or “urgent” wire requests require dual sign-off regardless of who asks?
- 05Do vendors in your file all have lien-waiver and insurance-certificate history behind them?
Answer all 5 to see where you stand · 0/5
It plugs into construction AP as it runs today
Construction finance runs on ERPs and AP automation the industry already trusts. RankShield adds the independent verification layer beside them — see the integration paths already published.
Deployment that cannot break a store
Every phase defaults to no-change. Nothing is blocked until observe mode has proven its accuracy on your own traffic.
Historical baseline on your own AP
Sixty to ninety days of vendor-file history and payment records through the rule set, offline: every banking change, every first payment to new details, every vendor without a document trail — what would have held, and why.
Observe mode across live projects
Live vendor and payment data scored advisory-only. Finance sees the holds that would have happened; draws release exactly as before. Accuracy is earned on your projects before anything gates.
Verification before the money moves
High-risk changes hold for automated out-of-band verification; dual control becomes unskippable on clearance; every verdict seals to the RankShield Network — evidence for the audit, the insurer, and the lien fight.
Landscape is not evidence — your data is
The scenarios on this page are illustrative and the statistics are industry-level measurements from primary sources — none of it claims that any specific operator is under attack, and none of it comes from customer data. We also do not claim in-flight authorization declines, which require a position in the payment path we do not hold. What we offer is precise: per-terminal detection on feeds you already own, near-real-time operational response, and a sealed, independently verifiable receipt behind every verdict. Phase 1 replaces this landscape with findings from your own stores.
Fraud defense, industry by industry
References
The load-bearing statistics on this page trace to the sources below — government, regulator, and association primaries first. Measurements from industry vendors are labeled as such.
- FBI IC3 — 2025 Internet Crime Report
- FinCEN — Updated Advisory on Email Compromise Fraud (FIN-2019-A005)
- ACFE — Occupational Fraud 2024: A Report to the Nations
- AFP — 2025 Payments Fraud and Control Survey (press release)
- U.S. DOJ — Previously Extradited Nigerian National Sentenced (construction progress-payment BEC)
- CNN — Arup confirms $25.6M deepfake video-call fraud (company-confirmed report)
- FinCEN — Alert on Fraud Schemes Involving Deepfake Media (FIN-2024-Alert004)
- FBI IC3 — 2024 Internet Crime Report
Construction, answered
Every question buyers ask before they trust a payment-security platform, answered directly.
Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.
Start with a findings report on your own stores.
Sixty to ninety days of your existing journal and authorization history, through the full rule set, offline. What would have been caught, where — before anything touches production.