Your client calls you in a panic. Someone impersonating a vendor, or worse, impersonating their own CFO, sent an email asking for a wire to a “new” bank account. Someone on their team almost sent it. Maybe they caught it before the money left. Maybe they didn’t.
Either way, your client’s next question is usually: “We caught it in time, so we’re fine, right?”
Not necessarily. And the next 48 hours matter more than most people realize.
What This Actually Costs
This isn’t a rare, exotic attack. It’s one of the most expensive kinds of theft businesses face today. The FBI’s Internet Crime Complaint Center reported business email compromise losses of roughly $3 billion in 2025, one of its top five costliest crime categories, in a year where total reported cybercrime losses topped $20.8 billion for the first time.
Two things make this attack effective. First, it doesn’t require any malware or technical exploit. It just requires one convincing email and one person moving fast under pressure. Second, banks can sometimes claw back a wire if it’s caught within hours, not days. That window closes fast, and it’s smaller than most business owners assume.
The financial loss is the visible cost. The quieter cost is what happens next: if the email account was actually compromised (not just spoofed), the attacker may still have access. If it was spoofed, the same client is now a known target and will likely see a second attempt within weeks.
What to Preserve Before Anyone Touches Anything
If your client calls you about this, the instinct is to clean it up and move on. That instinct is the problem. Tell them to do three things before anyone deletes an email or resets a password:
Do not delete the fraudulent email or forward it in a way that alters the headers. Save it as-is, ideally by exporting the original message file, not a screenshot.
Do not reset passwords or “fix” the account yet if there’s any chance the email account itself was compromised, not just spoofed. Changing things before anyone’s looked can erase the evidence of how the attacker got in, which matters for both the bank recovery process and the cyber insurance claim.
Get a timeline down while it’s fresh. Who received the email, when, who responded, when the wire was initiated or nearly initiated, when it was caught, and by whom.
What to Do This Week
Call the bank immediately if any funds moved. Ask specifically about a wire recall or SWIFT recall request. Every hour matters here.
File a report with IC3 (ic3.gov). This isn’t paperwork theater. It feeds the same database law enforcement uses to trace and sometimes freeze funds tied to a specific account.
Check whether the email account was actually accessed, not just impersonated. This is not a DIY step. It requires someone who can look at login history, mail forwarding rules, and authentication logs, because attackers who get real access often set up quiet forwarding rules to keep watching the mailbox after the incident looks “resolved.”
Notify their cyber insurance carrier if they have a policy, even if the loss was avoided. Carriers want to know about near-misses, and notifying late can complicate a future claim if a related incident shows up down the road.
When to Call Someone
This is the moment to bring in outside help, not after your client has already reset everything and called it handled. The two situations that call for it right away: money actually left the account, or there’s any chance the email account itself was compromised rather than just spoofed.
“We caught it” answers whether the money is gone. It doesn’t answer whether the door is still open.
Line for the Email
“If a wire request ever looks even slightly off, don’t fix it yourself first. Preserve what you have, even if you’ve already called the bank. I’d want to know before anyone resets a password or calls it resolved.”
References
FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report (released April 2026) — https://www.fbi.gov/file-repository/2025_ic3report.pdf/view

