Request access
RankShield Network · Financial · Payment Fraud

Construction Payment Fraud: Why Contractors Top the Federal BEC Data and Where the Payment Chain Breaks

Federal analysis ranks construction and manufacturing as the number one target sector for business email compromise, and the reason is structural: every project runs a chain of owner, general contractor, subcontractor, and supplier payments where an impostor can pose as the next party up or down the line. Here is where the chain breaks and how to verify before a draw funds.

Key takeaways
  • Federal analysis ranks manufacturing and construction as the top BEC target sector at 25 percent of analyzed transactions, and the same analysis found vendor and client invoice impersonation overtook CEO impersonation as the dominant method.
  • The payment chain is the vulnerability: owner to general contractor to subcontractor to supplier means every party routinely receives payment instructions from someone they do not transact with daily, which is exactly the gap an impostor occupies.
  • There are four hops where an impostor enters, and each one is a bank-detail or payment-instruction change that arrives by email at a predictable, publicly documented moment in the project schedule.
  • ACFE’s 2026 study puts the construction median fraud loss at $120,000 per case with billing schemes in 35 percent of them, which on thin project margins is the profit on an entire job.
  • The control that fits is verification before the draw funds: the payee matches the party entitled to payment, the account belongs to that payee, and a named person approved the release. That is what RankShield Financial is built to do.

Construction payment fraud is the diversion of a legitimate project payment to an impostor, and contractors absorb it more than almost any other industry because of how the money moves. The Financial Crimes Enforcement Network’s sector analysis, still the most recent federal ranking of its kind, found that manufacturing and construction together drew 25 percent of analyzed business email compromise transactions, the largest share of any sector1, with attempted BEC running about $301 million per month in the period studied. That analysis also recorded the shift that defines the threat today: vendor and client invoice impersonation overtook CEO impersonation, which fell from 33 percent of cases to 12 percent. The current scale is larger still. The FBI logged $3.046 billion in BEC losses in 2025, with 86 percent of that money moving by wire or ACH3, the same rails that fund a draw. This guide maps the four hops where an impostor enters a construction payment chain, explains why the chain itself invites impersonation, sets out the verification that belongs before a draw funds, and covers who actually eats the loss when a payment is diverted. The honest framing on the federal sector data: it is the best sector ranking published, and it is several years old, so treat it as the shape of the risk rather than this year’s scoreboard.

Why the construction payment chain invites impersonation

Construction is targeted because its payment structure hands an impostor a ready-made disguise. A single project moves money through a chain of owner, lender, general contractor, subcontractor, and supplier, and the parties at either end of that chain often have no direct relationship. A GC pays subs it may have onboarded weeks earlier; a sub pays suppliers it uses on one job. That means payment instructions routinely arrive from a party the payer does not transact with daily and has no long baseline for, which is precisely the condition an impersonation needs. FinCEN’s analysis found that construction and renovation projects at institutions were specifically attractive to BEC actors1.

The second structural gift is publicity. Bid results, permit filings, lien notices, and bond documents put the parties, the scope, and often the schedule into the public record. An attacker does not have to guess who is owed money on a project or roughly when; the paperwork says so. The same public-record problem drives losses in institutional and public-fund construction projects, where board minutes name the contractor and the draw schedule is published.

The third is timing pressure. Draws fund on a schedule, retainage releases at milestones, and crews and suppliers expect payment on terms that keep the job moving. Margins are thin enough that a delayed payment has real consequences, so a request to update banking details before the next draw gets processed rather than questioned. ACFE’s 2026 study puts the construction median loss at $120,000 per case, with billing schemes appearing in 35 percent of them2. On a job running single-digit margins, that is the entire profit.

The four hops where an impostor enters

Every construction payment diversion happens at one of four hops in the chain, and each one is the same mechanic wearing different clothes: a payment instruction or banking detail changes, and the change arrives by email at a moment when it looks routine. Naming the hops matters because each is verifiable before money moves, and because the party that gets impersonated is rarely the party that absorbs the loss.

What unites all four is that none of them requires hacking a payment system. The attacker only needs a plausible identity and correct timing, both of which the project record supplies. That is why perimeter security does not touch this category and why the check has to sit on the payment itself.

  • Hop one, owner or lender to general contractor: an impostor posing as the GC sends updated remittance details before a scheduled draw, so the draw funds an account the GC never sees.
  • Hop two, general contractor to subcontractor: an impostor posing as a sub submits a pay application or a bank-detail change on a real, open contract the GC is already expecting to pay.
  • Hop three, subcontractor to supplier: an impostor posing as a material supplier redirects payment on a real delivery, often timed to a large material buy at the start of a phase.
  • Hop four, anyone to the accounting desk: an impostor posing as an executive or PM authorizes an urgent, one-time payment outside the normal draw cycle, the classic executive-wire variant that FinCEN found declining but never disappearing.

Verification before the draw funds

The control that fits this loss pattern is verification at the moment of funding, not detection afterward. Before a draw or a sub payment is released, three things need to be true: the payee is the party actually entitled to payment on this contract, the receiving account belongs to that payee, and a named person approved this payee and amount. The rule that makes it work is out-of-band confirmation. Any new payee or changed banking detail is confirmed through a phone number or contact your company already had on file from the contract or onboarding, never the number or reply address in the message carrying the change.

This is no longer just good practice. Nacha’s fraud-monitoring rules, whose second phase took effect on June 19, 2026 for all non-consumer ACH originators4, now expect any business originating ACH credits, general contractors included, to screen for payments induced under false pretenses. A draw funded to an impostor on a forged bank-change request is exactly that. The practical version for a construction office is to treat a banking change as a contract event rather than an administrative one, with the same seriousness as a change order, because the dollar exposure is comparable and the invoice that carries it is the attack surface.

  • Match the payee to the contract: the party being paid is the party named on the subcontract or purchase order for this scope.
  • Match the account: the receiving account belongs to that payee, confirmed out of band using contract or onboarding contact details.
  • Hold the change: the first payment to a new payee or to changed banking details waits until that confirmation is complete, with no exception for draw-day urgency.
  • Prove the approver: a named person is on record approving this payee and amount, so the decision survives an audit or a dispute.

Loss allocation when a construction payment is diverted

The party that authorized the payment generally absorbs the loss, which in this chain is usually the payer rather than the impersonated party. If a GC funds a sub payment to an impostor’s account, the sub still has not been paid for work it performed, and it retains its contractual claim and, depending on the jurisdiction, its lien rights. The GC has paid once and still owes. Banks that execute an authorized payment order are generally protected, so recovery depends on freezing funds fast, which the FBI’s data shows is the exception rather than the rule once a transfer settles.

You might also be wondering whether insurance absorbs it. Do not assume so. Losses from a payment the company itself authorized are commonly handled under social-engineering or fraudulent-instruction provisions rather than general cyber coverage, those provisions are frequently sub-limited well below a draw, and carriers examine whether the company followed its own verification procedure before paying. That last point deserves weight: the existence and documented use of a verification step can decide whether a claim is covered. Confirm the specifics with your carrier and counsel, and treat the verification record itself as part of what you are buying. The same pattern holds across every sector in the payment fraud league table: the loss lands where the authorization happened.

Putting the gate in front of the draw

Every control above works, and every one fails the same way: on draw day, under schedule pressure, when checking is optional and the crew is waiting. The durable version is structural. Before a payment is released, the payee is verified against the party entitled to payment on that contract, a changed account is held until confirmed through an independent channel, and a named approver is on record.

This is where RankShield Financial fits for construction and contracting payments. It is a verification and attestation layer in the authorization path, not a bank, a lender, or a payment processor, and it never takes custody of funds; your existing bank and rails still move the money. It holds a draw or sub payment when the payee does not match a verified record, requires proof that an authorized person approved the release, and seals a signed, tamper-evident record of that decision that an owner, a lender, an auditor, or a surety can independently verify rather than take on faith. That shared signal compounds as members join, rather than claiming a scale we have not yet reached. The honest boundary: verification does not qualify your subs, resolve a lien dispute, or replace the bank-detail discipline your office already needs; it makes the unsafe release impossible to do casually and produces evidence of who approved what. If you fund draws and want that gate in front of them, you can see how it works or request access.

The change that protects a job’s margin

If a construction finance office changes one thing after reading this, make every banking-detail change a verified event with a named second approver, and hold the first payment to new details until the verification is done. That single procedure interrupts all four hops, because all four depend on a payment instruction that nobody confirmed through a channel the sender did not control. The projects that make a contractor a target are public, the draw schedules are predictable, and the rules now expect screening before release. The only question a controller should need answered is whether a payment can leave this company to a payee nobody independently verified. If the answer is provably no, the impersonation has nowhere to land, and the margin on the job stays where it was earned.

Operate it

Verify a payment before it settles

Compose a payment and the conditions around it, then run the same check the product runs on a live rail. The verdict comes back before the money would move.

Conditions around this payment
PRE-SETTLEMENT VERDICTRANKSHIELD NETWORK

Compose a payment on the left and run the check. The verdict is returned before the money moves, the way the product returns it on a live rail.

Sandbox demo · reproduces the product’s verdict logic and signing metadata · not a live network call

Downloadable · SVG
RANKSHIELD FINANCIAL // CONSTRUCTION PAYMENT FRAUD The four hops where an impostor enters OWNER / LENDER Funds the draw GENERAL CONTRACTOR Pays the subs SUBCONTRACTOR Pays suppliers SUPPLIER Delivers material HOP 1 Impostor poses as the GC Updated remittance detailsland before a scheduled draw. HOP 2 Impostor poses as a sub A pay app or bank changeon a real open contract. HOP 3 Impostor poses as a supplier Payment redirected on a realdelivery, timed to a material buy. HOP 4 Impostor poses as an exec An urgent one-time paymentoutside the draw cycle. Every hop is the same mechanic: a payment instruction changes by email at a moment the project record makes predictable. rankshieldfinancial.com VERIFY BEFORE THE DRAW FUNDS

A construction project pays down a chain of owner, general contractor, subcontractor, and supplier, and an impostor can insert itself at any of the four hops by posing as the next party up or down the line. Every hop is the same mechanic: a payment instruction or banking detail changes by email at a moment the public project record makes predictable. The check that closes all four is verifying the payee and the approver before the draw funds.

FAQ

Frequently asked questions

Every question buyers ask before they trust a payment-security platform, answered directly.

JAMIE KLONCZ · RANKSHIELD FINANCIAL ONLINE

Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.

REQUEST ACCESS →
Self-check

How exposed are your payments?

Five controls decide whether an authorized-payment scam gets through on a fast rail. Answer them honestly to see where you stand.

  1. 01Do you send payments on instant or same-day rails (RTP, FedNow, same-day ACH)?
  2. 02Can one person both change a vendor’s bank details and approve the payment?
  3. 03Do you always confirm a bank-detail change on a number from your own files, not the request?
  4. 04Is the first payment to a new or changed payee held for verification before it goes out?
  5. 05Do you keep a signed record of exactly who approved each payment?

Answer all five to see where you stand · 0/5

Jamie Kloncz
About the author

Jamie KlonczFounder, RankShield Financial

Jamie founded RankShield Financial to verify a payment’s intent and authority before it settles on instant and tokenized rails. These guides are written from building that product and reading the primary sources directly: every statistic here links to its original filing or report, never a secondhand summary.

  • Primary sources only: each figure links to the original filing
  • Honest boundaries: what verification can and cannot do is stated plainly
  • Last verified July 28, 2026
Verify, then settle

See your payments verified before they settle.

RankShield Financial is rolling out with design partners on instant and tokenized rails. Request access and we’ll map it to your settlement flow.

Request accessHow it works