The fraud does not break anything. It waits for the right moment and sends a correction.
Emailed wire instructions can be intercepted or spoofed, and the usual attack is a plausible correction sent at the moment a payment is expected. Instructions should be delivered in a place that requires authentication rather than in a message, revealed only when the payment is actually due, and verified by calling a number obtained independently of the email.
Business email compromise rarely involves breaking anything. Someone gets access to a mailbox, usually with a stolen password, and then does nothing except read. They learn the deal, the names, the tone, the timing, and the amount.
When the payment is close, the correction arrives. It comes from the right address or one that differs by a character, it references the real matter, it apologizes for the change, and it carries new account details. Nothing about it is alarming, because everything about it is correct except the account number.
A payment instruction is only suspicious when it is unexpected. The whole method is to make sure it is expected, which is why the message arrives exactly when the recipient is waiting to be told where to send the money.
The rail is chosen deliberately. A wire is effectively final once the receiving bank accepts it, so the recovery window is measured in hours and depends on the money still being there. Funds are usually moved onward the same day, often abroad.
Which is why the control has to sit before the payment. There is no dispute process to fall back on, and the bank that followed your instruction did what it was told.
Not in the body, not in an attachment, not in a chat. A message is a copy that travels and can be replaced in transit or at rest.
A page the counterparty reaches through their own secure link, or a portal they sign into. The email carries the pointer, not the payload.
Instructions that appear after the agreement is executed have a much shorter window in which to be stolen, and their arrival is tied to an event both sides witnessed.
Before the first payment to any account, and again on any change. The number comes from your own records, never from the message asking for the payment.
A changed account number is the single highest-risk event in a transaction. Both sides should expect a call, and neither should be embarrassed to make one.
Say once, at the start, that your instructions never change by email. That sentence is what makes a fraudulent correction look wrong to someone who is not thinking about fraud.
Most people who lose money this way did nothing careless by the standards they were working to. They received a normal-looking message on a deal that was really happening and followed it. The defense that works is structural rather than personal: put the details somewhere a message cannot reach, and make verification a step in the process rather than an act of suspicion.
In a well-run transaction the money moves from one party’s bank to the other’s, and no software should ever sit between them. What software can do is control where the instructions appear and record who confirmed the payment arrived.
One sentence in the first substantive message: the details will appear on the secure page and never change by email. Now a fraudulent correction has to contradict something the recipient already read.
Entered by someone who can read them off a bank-issued document, and stored where they redisplay masked rather than in full.
There is no reason for payment details to exist anywhere before the thing that triggers the payment has happened.
Reached from their own link, after their own signature. The message that brought them there carries no account numbers at all.
Numbers from your own records, both directions. Say plainly that this is routine, so nobody feels accused.
The payment is reconciled against the receiving bank’s record, not against the payer’s confirmation. That closes the loop the fraud was aimed at.
Nothing in that sequence is technically demanding. What it does is remove the moment the attack depends on, which is the one where a person is waiting to be told where to send money and will believe the first plausible answer.
This is an explanation of how a transaction works, not legal or tax advice. Termn is not a law firm, a bank, an escrow agent, or a money transmitter, and it never holds your money. What is right for your situation is a question for your own counsel, who decides it and drafts the documents that carry it.
Termn keeps your receiving instructions sealed until the signatures are in, then reveals them on the participant’s own authenticated page rather than in a message.
How Termn runs sign and fund Your first workspace is free, and nothing goes out until you send it.
Recovery odds fall by the hour. This is the order to work in.
Money showing in the account is not the same as money you get to keep.
Almost everywhere, yes. The exceptions are the documents you care most about.
Everything else is in the learning center.
Your first workspace is free: one live workspace, unlimited agreements inside it, no card.
Close your first deal freeRather talk it through first? Contact us at sales@termn.ai.