SKIP TO CONTENT
FL1GHT5 Network

Jan 01, 2026 · Construction Tech / Security · ~4 MIN READ

Wire Fraud in the Draw Cycle: How Builders Get Hit and How to Harden Against It

Why the draw cycle is a favourite target for business email compromise and fake-invoice fraud, and the specific controls that stop it.

Who This Is For

Anyone who approves or processes payments on a construction project — GCs, developers, lenders’ representatives, and the accounts payable staff who action wire instructions. If your draw cycle still runs on email, this is worth ten minutes.

The draw cycle is attractive to fraud for the same reason it’s attractive to everyone else on the project: the money is real, the schedule is predictable, and everyone involved is used to acting fast on an email.

Why the Draw Cycle Specifically

A construction draw is a near-ideal fraud target, for reasons that have nothing to do with how careful anyone involved is:

  • The payment is large and expected. Nobody double-checks a wire that was already on the schedule.
  • Multiple parties email about the same invoice. GC, sub, lender, and owner are all in the same thread at different points, so an extra “reply-all” from a slightly-wrong address doesn’t stand out.
  • Timing pressure is built in. Draws are processed close to a deadline, which is exactly when people skip the step they’d normally take.

None of this requires the attacker to be sophisticated. It requires patience and one convincing email.

How the Attack Usually Works

Business email compromise (BEC). An attacker gets into a real mailbox — a sub’s, a lender’s, an owner’s — usually through a phished credential, and simply watches. When a draw is close, they send (or intercept and alter) an email with “updated banking details,” from the real, compromised account. There’s no lookalike domain to catch, because the email is genuinely coming from where it claims to.

Lookalike domains. The cheaper version of the same idea: a domain one character off from a real vendor or lender (superior-electric.ca vs superlor-electric.ca), used to send a banking-change notice that looks identical to the real thing at a glance.

Timing. Both versions are sent right before a draw is due — enough urgency that “call and confirm” feels like it’ll cost a day nobody has.

What Actually Stops It

None of these are exotic. They’re the specific controls that address the specific mechanics above:

  1. Email authentication — SPF, DKIM, DMARC, actually enforced. Not “configured and left on p=none.” A DMARC policy set to quarantine or reject means a spoofed sending domain gets rejected before it lands, closing off the cheaper lookalike-domain version of the attack entirely. This does nothing against a genuinely compromised mailbox — that’s what the next control is for.
  2. A verbal-confirmation rule for any banking-detail change, no exceptions. Call the vendor or lender back on a number you already had on file — never one from the email that just changed the details — before a payment goes out to new banking information. This is the single control that catches BEC, because it doesn’t depend on detecting anything was wrong with the email.
  3. MFA on every account that can send or approve a payment instruction. A compromised password alone shouldn’t be enough to take over the mailbox in the first place.
  4. Conditional Access policies that flag logins from unexpected locations or devices. Catches the account takeover closer to the start of the chain, before it gets anywhere near a draw request.

What to Do This Week

  • Confirm SPF, DKIM, and DMARC are enforced on your domain — not just present in DNS. A configured but unenforced DMARC record (p=none) provides visibility, not protection.
  • Write down the verbal-confirmation rule in one sentence and send it to your accounts payable team today. A rule that exists only as tribal knowledge doesn’t survive someone being on vacation.
  • Check who in your organization can approve a wire, and confirm every one of those accounts has MFA enabled — not “should have,” confirm it.
  • Ask your lender and largest subs whether they have the same rule. Fraud in the draw cycle doesn’t require your systems to be the weak link — it just needs one party in the chain to skip the call.

The Bottom Line

The draw cycle isn’t vulnerable because construction companies are careless. It’s vulnerable because the workflow — large, scheduled, multi-party, time-pressured, email-driven — is exactly the shape fraud is built to exploit. The fix isn’t more caution under pressure; it’s a rule that doesn’t depend on anyone noticing anything under pressure.

This is a service we deliver. If this article describes your operation, skip the DIY weekend — see how we build it → or send the brief →.

NEXT STEP

Want this running in your business?

Everything in the Lab is a service we deliver. If this guide describes your problem, skip the DIY weekend — send the brief.

FIVE MINUTES TO WRITE · A WRITTEN PLAN BACK · NO SALES CALL UNLESS YOU WANT ONE