🤖 AI SCAM DEFENSE · GUIDE 3 OF 10

How to Verify a Payment Request Is Legitimate

This is the scam category that costs businesses the most money, and it rarely involves a single line of malware.

By TechODash.com  ·  9–11 minute read  ·  Published 2026

Our first two guides in this category covered writing and voice. This one is about the moment those tricks are actually built toward: a message asking you, or someone in your business, to send money or change where it goes. Business email compromise, as this category of fraud is officially known, isn't flashy or technically complicated. It's a message that looks routine enough that nobody stops to question it — and it's responsible for more reported losses than almost any other type of online fraud.

The defense here is genuinely simple once you understand what it's actually protecting against.

Who This Guide Is For

Small business owners, freelancers, and anyone who handles payments, invoices, or account changes on behalf of themselves or a business.

The Scam That Doesn't Need Any Malware At All

The FBI's Internet Crime Complaint Center received nearly 25,000 reports of this kind of fraud in a single recent year, with losses totaling roughly three billion dollars — and that's just what got reported. It shows up in a handful of recognizable shapes: a vendor you already work with sends an invoice with "updated" banking details, a message that looks like it's from your boss asks you to quickly purchase gift cards for a work event, or a title company sends wiring instructions for a home purchase that turn out to be fraudulent. In every version, nothing was hacked open with force. Someone was simply convinced.

Why "It Came From the Right Email" Isn't Proof

This is the detail that trips people up most. It's tempting to assume that if an email came from a real, familiar address, the request must be legitimate — but attackers frequently aren't spoofing an address at all. They're inside the real one. Once a mailbox is compromised, criminals will often sit quietly and read existing conversations for days or weeks, learning the tone, timing, and billing history well enough to send a request that fits seamlessly into an ongoing thread. A message can be completely genuine in origin and still be fraudulent in content, which is exactly why checking who sent something is not the same as verifying what it's asking you to do.

The One Verification Step That Actually Works

Every serious source covering this fraud — the FBI, banks, fraud investigators — converges on the exact same answer: verify by phone, using a number you already had on file or looked up independently, never a number provided in the email or on the invoice itself. This one step defeats the scam regardless of how convincing the message is, because it doesn't ask you to evaluate the message at all — it simply routes around it entirely. Make this an unbreakable rule for two specific triggers: any request to change where a payment goes, and any request framed as urgent or requiring unusual discretion. If a business you work with doesn't yet have a written policy requiring this kind of callback before processing an account change, that policy is worth writing today, not after the first incident.

If Money Has Already Gone Out

Speed matters enormously here. Contact your bank immediately, ideally within 72 hours of the transfer — that window is specifically what triggers a coordination process between financial institutions and the FBI designed to freeze and potentially recover funds still in transit internationally. Beyond that window, recovery odds drop sharply. File a report with the FBI's Internet Crime Complaint Center at ic3.gov regardless of the amount, and preserve every related email and document rather than deleting anything out of frustration or embarrassment — that evidence matters for both recovery and any investigation that follows.

A Realistic Standard to Aim For

Any request to change payment details or account information should require a phone call to a number you already had on file, every single time, with no exceptions made for how routine or urgent the request seems. That one habit stops the majority of this fraud outright.

Where to Go From Here

Payment requests are one specific target. The next guide widens out to the broader pattern of AI being used to impersonate people you trust in general.

→ Deepfake Voice Calls Explained → AI Impersonation Scams Explained Download Free Checklist →

Sources

  • FBI — official business email compromise guidance and reporting through IC3
  • CYBERRISKED — 2025 BEC complaint and loss statistics, common scenarios targeting small businesses
  • Gennai — the 72-hour recovery window and the Financial Fraud Kill Chain process
GOING DEEPER

Scam defense is one layer. A well-built network is the rest.

The SOHO 2026 Guide covers the network foundation that keeps a home office or small business secure — the same structure and habits that back up everything in this category. Written in plain English. Built on 25+ years of real-world IT experience.

Explore SOHO 2026 →
TechODash.com

Calm, practical guides for remote workers, content creators, and small business owners who want networks that work reliably and safely — without the enterprise complexity. Built on 25+ years of hands-on IT experience.