Why wire instructions should not travel by email

The fraud does not break anything. It waits for the right moment and sends a correction.

3 minute read · Last reviewed August 10, 2026 · How Termn runs sign and fund

In short

Emailed wire instructions can be intercepted or spoofed, and the usual attack is a plausible correction sent at the moment a payment is expected. Instructions should be delivered in a place that requires authentication rather than in a message, revealed only when the payment is actually due, and verified by calling a number obtained independently of the email.

The attack is patience, not technique

Business email compromise rarely involves breaking anything. Someone gets access to a mailbox, usually with a stolen password, and then does nothing except read. They learn the deal, the names, the tone, the timing, and the amount.

When the payment is close, the correction arrives. It comes from the right address or one that differs by a character, it references the real matter, it apologizes for the change, and it carries new account details. Nothing about it is alarming, because everything about it is correct except the account number.

Why the timing works

A payment instruction is only suspicious when it is unexpected. The whole method is to make sure it is expected, which is why the message arrives exactly when the recipient is waiting to be told where to send the money.

Why the wire is the target

The rail is chosen deliberately. A wire is effectively final once the receiving bank accepts it, so the recovery window is measured in hours and depends on the money still being there. Funds are usually moved onward the same day, often abroad.

Which is why the control has to sit before the payment. There is no dispute process to fall back on, and the bank that followed your instruction did what it was told.

Controls that actually hold

  1. 01

    Never put account details in a message

    Not in the body, not in an attachment, not in a chat. A message is a copy that travels and can be replaced in transit or at rest.

  2. 02

    Deliver them where a person has to authenticate

    A page the counterparty reaches through their own secure link, or a portal they sign into. The email carries the pointer, not the payload.

  3. 03

    Reveal them only when the payment is due

    Instructions that appear after the agreement is executed have a much shorter window in which to be stolen, and their arrival is tied to an event both sides witnessed.

  4. 04

    Call to verify, on a number you already had

    Before the first payment to any account, and again on any change. The number comes from your own records, never from the message asking for the payment.

  5. 05

    Treat any change of details as a fresh verification

    A changed account number is the single highest-risk event in a transaction. Both sides should expect a call, and neither should be embarrassed to make one.

  6. 06

    Tell the other side what you will never do

    Say once, at the start, that your instructions never change by email. That sentence is what makes a fraudulent correction look wrong to someone who is not thinking about fraud.

The uncomfortable part

Most people who lose money this way did nothing careless by the standards they were working to. They received a normal-looking message on a deal that was really happening and followed it. The defense that works is structural rather than personal: put the details somewhere a message cannot reach, and make verification a step in the process rather than an act of suspicion.

Where the money actually goes

In a well-run transaction the money moves from one party’s bank to the other’s, and no software should ever sit between them. What software can do is control where the instructions appear and record who confirmed the payment arrived.

What a safe handoff looks like, start to finish

  1. 01

    Say at the outset how instructions will arrive

    One sentence in the first substantive message: the details will appear on the secure page and never change by email. Now a fraudulent correction has to contradict something the recipient already read.

  2. 02

    Collect your own details once, carefully

    Entered by someone who can read them off a bank-issued document, and stored where they redisplay masked rather than in full.

  3. 03

    Keep them sealed until the agreement is executed

    There is no reason for payment details to exist anywhere before the thing that triggers the payment has happened.

  4. 04

    Reveal them on the payer’s own authenticated page

    Reached from their own link, after their own signature. The message that brought them there carries no account numbers at all.

  5. 05

    Ask for a verification call on the first payment

    Numbers from your own records, both directions. Say plainly that this is routine, so nobody feels accused.

  6. 06

    Confirm receipt from your own account

    The payment is reconciled against the receiving bank’s record, not against the payer’s confirmation. That closes the loop the fraud was aimed at.

Nothing in that sequence is technically demanding. What it does is remove the moment the attack depends on, which is the one where a person is waiting to be told where to send money and will believe the first plausible answer.

Sources

This is an explanation of how a transaction works, not legal or tax advice. Termn is not a law firm, a bank, an escrow agent, or a money transmitter, and it never holds your money. What is right for your situation is a question for your own counsel, who decides it and drafts the documents that carry it.

Common questions

Is encrypting the email enough?
It helps against interception and does nothing against the more common case, which is an attacker with legitimate access to somebody’s mailbox. An encrypted message from a compromised account arrives encrypted, trusted, and wrong.
What does a callback actually verify?
That the person who controls the account is the person you already know, reached at a number you already had. The rule that makes it work is that the number never comes from the email, the attached letterhead, or the signature block. Those are all things an attacker supplies.
We have always sent instructions as a PDF attachment. Is that safer?
No. The attachment is as easy to replace as the message body, and a letterhead makes a substitution more convincing rather than less. What matters is where the details are read, not what they are wrapped in.
What if the other side asks us to send them by email anyway?
Many will, because it is what they are used to. The workable answer is to send a link to the place the instructions live, keep the details out of the message, and confirm the first payment by phone. It takes one extra minute per deal.

Running one of these now?

Termn keeps your receiving instructions sealed until the signatures are in, then reveals them on the participant’s own authenticated page rather than in a message.

How Termn runs sign and fund Your first workspace is free, and nothing goes out until you send it.

Read next

  1. A payment went to the wrong account: the first hours

    Recovery odds fall by the hour. This is the order to work in.

  2. Which payments can be reversed, and for how long

    Money showing in the account is not the same as money you get to keep.

  3. Are electronic signatures binding, and where do they stop

    Almost everywhere, yes. The exceptions are the documents you care most about.

Everything else is in the learning center.

Finish what the agreement started

Your first workspace is free: one live workspace, unlimited agreements inside it, no card.

Close your first deal free

Rather talk it through first? Contact us at sales@termn.ai.