Skip to main content

Financial Scams Targeting Small Businesses: The Warning Signs Before the Wire Goes Out

9 min readMike ThriftMike Thrift
Financial Scams Targeting Small Businesses: The Warning Signs Before the Wire Goes Out

It's a Friday afternoon. The owner is out of the office. An email lands in the bookkeeper's inbox from "the CEO," asking for an urgent wire transfer to a new vendor account before the bank closes. The tone is polite but pressing. The signature block looks right. The transfer goes out. By Monday, the money — and the "vendor" — are gone.

This scenario plays out at small businesses every day, and it's rarely the dramatic Hollywood heist you'd imagine. Most fraud against small businesses is quiet, patient, and disguised as routine paperwork. According to the Association of Certified Fraud Examiners (ACFE), organizations lose roughly 5% of their annual revenue to fraud, and nearly half of victimized businesses never fully recover. For a business running on thin margins, that's not a rounding error — it's existential.

Here's what the fraud actually looks like, the numbers behind why it keeps working, and the warning signs that give you a chance to stop it before the wire goes out.

Why Small Businesses Are the Preferred Target

Fraudsters don't chase the biggest targets — they chase the softest ones. Small businesses are attractive marks for a specific reason: they run lean. There's often no separate accounts payable department, no dedicated fraud analyst, and no second set of eyes on every transaction. One person may open the mail, approve invoices, and reconcile the bank account. That concentration of duties, which is completely normal for a five-person company, is exactly the gap fraud schemes are built to exploit.

The scale of the problem has grown sharply in the last two years:

  • The FBI's Internet Crime Complaint Center (IC3) logged 24,768 Business Email Compromise (BEC) complaints in 2025, totaling $3.05 billion in reported losses — up from 21,442 complaints and $2.77 billion in 2024, a roughly 16% jump in complaints and 10% jump in losses year over year.
  • The Association for Financial Professionals found that 76% of U.S. organizations experienced attempted or actual payment fraud in 2025, and about 74% were hit by a BEC attempt specifically. Vendor impersonation was the single most common attack type.
  • ACFE's most recent global fraud study, drawn from over 2,400 real cases, found a median loss of $104,000 per case and an average exceeding $1.4 million. Only 25% of small businesses have a whistleblower reporting mechanism, compared to 85% of large organizations — meaning small businesses lose one of the most effective detection tools (employee tips catch 43% of all fraud cases) almost by default.
  • Generative AI is making the lures harder to spot. By some estimates, roughly 40% of BEC phishing emails are now AI-generated, which means the broken grammar and awkward phrasing that used to be a giveaway is disappearing fast.

The pattern is consistent: fraud isn't rare, it isn't slowing down, and small businesses are structurally more exposed to it than their larger competitors.

The Five Scams That Show Up Most Often

Business Email Compromise (BEC). An attacker either spoofs or quietly compromises an email account belonging to an executive, vendor, or trusted partner, then requests a wire transfer, gift cards, or a change to payroll direct-deposit details. The emails are timed deliberately — right before a long weekend, while the owner is traveling, during a busy vendor payment cycle — so the request feels urgent and hard to double-check.

Invoice and vendor impersonation. A fraudster poses as an existing supplier and sends a "updated banking details" notice, or invoices your business for goods and services that were never ordered. This is now the most frequently reported form of payment fraud, according to the AFP survey above, and it thrives on messy vendor records: duplicate entries, dormant suppliers nobody's cleaned out, and bank-detail changes nobody verified by phone.

Payroll diversion. An email that looks like it's from an employee asks HR or payroll to redirect their direct deposit to a "new" bank account. The real employee never sees a paycheck, doesn't notice for a pay cycle or two, and by the time it's flagged, the money is gone.

Business identity theft. Someone files fraudulent paperwork using your company's name and EIN — opening credit lines, filing for unemployment benefits on behalf of "employees," or registering a shell business that trades on your reputation with vendors and customers.

Check fraud and mail theft. It's the oldest scam on this list, and it's making a comeback. A stolen or intercepted check gets "washed" — the payee name and amount chemically removed and rewritten — or simply photographed and used to create a counterfeit check drawn on your account. Because checks still travel through mailboxes and drop boxes, a single stolen envelope can hand a fraudster your routing number, account number, and a real signature to copy.

Warning Signs to Train Your Team On

Fraud attempts rarely look sophisticated up close — they look like slightly-off versions of normal business communication. The tells to watch for:

  • Urgency and secrecy. "This needs to happen today," "please don't loop in anyone else," "I'm in a meeting and can't take calls" — legitimate urgent requests exist, but pressure combined with a request to bypass your normal process is the single biggest red flag.
  • A channel switch. A contact who has only ever emailed from a company address suddenly writes from a personal Gmail account, or a vendor who's always invoiced by mail suddenly wants payment details confirmed over email.
  • New banking details on an old relationship. Any request to change where money is sent — vendor payment info, payroll direct deposit, wire instructions — deserves a phone call to a number you already have on file, never a number provided in the request itself.
  • Invoices for work you don't recognize, or from a vendor whose name is almost-but-not-quite right (a swapped word order, an extra "LLC," a slightly different domain in the email address).
  • Unexplained financial gaps in reconciliations, repeated payments to the same vendor for round or suspiciously similar amounts, or an employee who never takes time off and resists anyone else touching their accounts (a classic sign of someone concealing an ongoing scheme rather than risking discovery while they're away).

None of these signs is proof of fraud on its own. Together, or in combination with a payment request, they're reason enough to stop and verify before money moves.

Building Defenses That Fit a Small Team

You don't need an internal audit department to close most of these gaps. A handful of habits does most of the work:

  1. Verify by phone, on a number you already have. This is the single highest-leverage control against BEC and vendor impersonation. Never confirm a banking change by replying to the same email or calling a number included in the message — look up the vendor's or executive's known number independently.
  2. Separate who requests a payment from who approves it. Even in a two- or three-person finance function, having one person initiate a payment and a different person (even the owner) review and approve it before it's sent closes off the most common single-point-of-failure fraud creates.
  3. Clean up your vendor file regularly. Duplicate vendor records and suppliers who haven't sent an invoice in 12–18 months are exactly where fraudulent entries hide in plain sight. A quarterly pass through your chart of accounts and vendor list catches this cheaply.
  4. Reconcile on a fixed schedule — weekly or monthly, without skipping. Fraud that gets caught within six months has a median loss of $40,000; fraud that runs more than five years undetected has a median loss north of $1.1 million. Reconciliation cadence is the difference between those two numbers.
  5. Turn on multi-factor authentication everywhere it's offered, on banking portals, accounting software, and email, and never disable it for convenience.
  6. Train continuously, not once. A single onboarding-day fraud slide doesn't stick. A short quarterly refresher — including a real, current example of a scam email — keeps the pattern recognition sharp.
  7. Move away from paper checks where you can. ACH transfers and card payments can't be washed out of a mailbox. If checks are unavoidable, use a locked drop box or hand delivery instead of an unsecured mail slot, and consider positive pay through your bank, which flags any check that doesn't match the amount and payee you originally issued.
  8. Put the verification rule in writing. A one-page policy — "no payment or banking-detail change is processed without a callback to a known number" — turns a good habit into an expectation everyone on the team, including new hires, is held to from day one.

If You Think You've Already Been Hit

Speed matters more than almost anything else in fraud recovery. If a fraudulent wire has already gone out:

  1. Call your bank immediately and ask about a recall or hold — banks can sometimes intercept a wire in the first 24 hours, rarely after.
  2. File a complaint with the FBI's IC3 (ic3.gov) and the FTC (reportfraud.ftc.gov), and file a police report — these reports matter for insurance claims and can help law enforcement connect your case to a broader pattern.
  3. Document everything: the original email, headers, timestamps, and every communication in the chain.
  4. Notify anyone else affected — an employee whose payroll was diverted, or a real vendor being impersonated who deserves a heads-up.
  5. Review and tighten the control that failed so the same door doesn't stay open.

Keep Your Finances Organized and Auditable

The businesses that catch fraud fastest are the ones whose books are clean, current, and easy to scan for something that doesn't belong. Beancount.io provides plain-text accounting that gives you complete transparency and a full audit trail over your financial data — no black boxes, no vendor lock-in, and every transaction is version-controlled and reviewable. Get started for free and see why developers and finance professionals are switching to plain-text accounting.

Share this article