Recovery odds fall by the hour. This is the order to work in.
Call your own bank immediately and ask it to initiate a recall or an indemnity request on the wire, then contact the receiving bank’s fraud department. Report it to the FBI Internet Crime Complaint Center at ic3.gov straight away, because there is a federal process for attempting to freeze qualifying transfers that depends on speed. Then secure the compromised mailbox and preserve the evidence.
Not the branch, and not email. Ask them to initiate a recall or an indemnity request, and for international transfers to send a recall notice. Get the reference number for the request.
The goal is a freeze on the receiving account while the facts are established. Banks talk to banks faster than customers reach either.
Include the exact amounts, dates, both banks, both account numbers, and the fraudulent emails with their full headers. Speed matters more than completeness here, and the report can be supplemented.
Your local police for a report number, and the nearest FBI field office for a large loss. Insurers and banks will both ask whether a report exists.
Reset credentials on the affected account and on anything sharing the password, turn on multi-factor authentication, and check for forwarding rules, inbox rules, and connected applications the attacker left behind. This is the step people skip, and it is how the second loss happens.
The payment obligation between the parties is a legal question and not a settled one. It needs counsel early, and the other side needs to know their own systems may be involved.
Crime, cyber, and professional liability policies each have notice requirements measured in days.
The original emails with full headers, the wire request as submitted, the confirmation, the call log, and every reference number. Do not delete the fraudulent messages, and do not let a retention policy do it for you.
There is no dispute button on a wire and no guaranteed recovery. The actions above improve the odds and preserve the options, and they are worth taking within the hour precisely because none of them guarantees anything.
Once the immediate calls are made, the work turns to understanding what happened and closing the same door on every other transaction in flight.
Knowing the usual route matters, because the same route is probably still open. Almost none of these involve breaking software.
An attacker who has been in a mailbox usually leaves a way back: a forwarding rule, an inbox rule that files replies somewhere the owner never looks, or an application authorized to read mail. Resetting the password alone closes none of them.
This is an explanation of how a transaction works, not legal or tax advice. Termn is not a law firm, a bank, an escrow agent, or a money transmitter, and it never holds your money. What is right for your situation is a question for your own counsel, who decides it and drafts the documents that carry it.
Termn is built so this call is less likely: instructions are sealed until signing, revealed on an authenticated page, and every payment is confirmed against the receiving side’s own evidence.
How Termn runs sign and fund Your first workspace is free, and nothing goes out until you send it.
The fraud does not break anything. It waits for the right moment and sends a correction.
Money showing in the account is not the same as money you get to keep.
Three separate facts that most systems collapse into one green tick.
Everything else is in the learning center.
Your first workspace is free: one live workspace, unlimited agreements inside it, no card.
Close your first deal freeRather talk it through first? Contact us at sales@termn.ai.