A payment went to the wrong account: the first hours

Recovery odds fall by the hour. This is the order to work in.

3 minute read · Last reviewed August 10, 2026 · How Termn runs sign and fund

In short

Call your own bank immediately and ask it to initiate a recall or an indemnity request on the wire, then contact the receiving bank’s fraud department. Report it to the FBI Internet Crime Complaint Center at ic3.gov straight away, because there is a federal process for attempting to freeze qualifying transfers that depends on speed. Then secure the compromised mailbox and preserve the evidence.

Do these in order, now

  1. 01

    Call your bank’s wire department

    Not the branch, and not email. Ask them to initiate a recall or an indemnity request, and for international transfers to send a recall notice. Get the reference number for the request.

  2. 02

    Ask your bank to contact the receiving bank

    The goal is a freeze on the receiving account while the facts are established. Banks talk to banks faster than customers reach either.

  3. 03

    File at ic3.gov immediately

    Include the exact amounts, dates, both banks, both account numbers, and the fraudulent emails with their full headers. Speed matters more than completeness here, and the report can be supplemented.

  4. 04

    Report locally as well

    Your local police for a report number, and the nearest FBI field office for a large loss. Insurers and banks will both ask whether a report exists.

  5. 05

    Assume the mailbox is compromised

    Reset credentials on the affected account and on anything sharing the password, turn on multi-factor authentication, and check for forwarding rules, inbox rules, and connected applications the attacker left behind. This is the step people skip, and it is how the second loss happens.

  6. 06

    Tell counsel and the other party

    The payment obligation between the parties is a legal question and not a settled one. It needs counsel early, and the other side needs to know their own systems may be involved.

  7. 07

    Notify your insurance broker

    Crime, cyber, and professional liability policies each have notice requirements measured in days.

  8. 08

    Preserve everything

    The original emails with full headers, the wire request as submitted, the confirmation, the call log, and every reference number. Do not delete the fraudulent messages, and do not let a retention policy do it for you.

What determines whether the money comes back

  • Whether it is still in the receiving account. Nothing else matters nearly as much.
  • How quickly the recall request reached the receiving bank.
  • Whether the transfer was domestic or international, and which jurisdictions are involved.
  • Whether the receiving account was opened for the fraud or belongs to someone who was themselves deceived.
What nobody can promise

There is no dispute button on a wire and no guaranteed recovery. The actions above improve the odds and preserve the options, and they are worth taking within the hour precisely because none of them guarantees anything.

The week after

Once the immediate calls are made, the work turns to understanding what happened and closing the same door on every other transaction in flight.

  • Establish which mailbox was accessed, when, and what was readable.
  • Review every other pending payment and re-verify instructions by phone.
  • Check whether any other party in the thread was also compromised.
  • Consider whether the exposure of personal data triggers notification obligations, with counsel.
  • Change how instructions are delivered, so the next one cannot be substituted in a message.
  • Write down what happened while it is fresh. Insurers, banks, and counsel will each ask for the same timeline.

How the access was probably obtained

Knowing the usual route matters, because the same route is probably still open. Almost none of these involve breaking software.

  • A password reused from a service that was breached elsewhere, tried against a mail provider.
  • A convincing sign-in page reached from a message about a shared document, an invoice, or a voicemail.
  • Multi-factor prompts approved out of habit, or a session token stolen so the prompt never appeared.
  • A third party in the transaction who was compromised instead of you: the other side’s office, an agent, a broker.
  • A lookalike domain differing by one character, where nobody was compromised at all and the reply address was misread.
The rules left behind

An attacker who has been in a mailbox usually leaves a way back: a forwarding rule, an inbox rule that files replies somewhere the owner never looks, or an application authorized to read mail. Resetting the password alone closes none of them.

Sources

This is an explanation of how a transaction works, not legal or tax advice. Termn is not a law firm, a bank, an escrow agent, or a money transmitter, and it never holds your money. What is right for your situation is a question for your own counsel, who decides it and drafts the documents that carry it.

Common questions

Can my bank pull the money back?
Not on its own authority. It can send a recall or indemnity request to the receiving bank, which then has to act, and generally needs the account holder’s agreement to return funds. Whether that succeeds depends almost entirely on whether the money is still sitting there.
How long do I have?
Hours, realistically. Fraudulent receiving accounts are drained quickly and often moved onward or abroad the same day. There is a federal process for attempting to freeze qualifying transfers, and it has a short reporting window and thresholds, which is why the report goes in immediately rather than after an internal review.
Should I contact the person whose account received it?
Contact the receiving bank, not the account holder. If the account is fraudulent, warning the holder tells them to move the money. If it was an honest mistake, the banks are still the right channel, and your counsel should guide anything beyond that.
Will insurance cover it?
It depends on the policy, and this is where the wording matters. Crime policies often need a specific social engineering or funds transfer fraud endorsement, and cyber policies have short notice deadlines. Notify the broker early even if coverage looks unlikely: a late notice can end the question before it is asked.

Running one of these now?

Termn is built so this call is less likely: instructions are sealed until signing, revealed on an authenticated page, and every payment is confirmed against the receiving side’s own evidence.

How Termn runs sign and fund Your first workspace is free, and nothing goes out until you send it.

Read next

  1. Why wire instructions should not travel by email

    The fraud does not break anything. It waits for the right moment and sends a correction.

  2. Which payments can be reversed, and for how long

    Money showing in the account is not the same as money you get to keep.

  3. What “reconciled” actually means

    Three separate facts that most systems collapse into one green tick.

Everything else is in the learning center.

Finish what the agreement started

Your first workspace is free: one live workspace, unlimited agreements inside it, no card.

Close your first deal free

Rather talk it through first? Contact us at sales@termn.ai.