The Callback Rule: A Payment Verification Procedure That Stops Wire Fraud

The email that does not look like an attack

It is 4:10 on a Thursday. Your bookkeeper opens an email from the controller at a supplier you have paid monthly for six years. Same signature block, same logo. Subject line: Updated remittance details. Their bank completed a merger, the old account closes Friday, please route this month’s invoice to the new one. Attached is a PDF on letterhead with the new routing and account number, and a phone number for questions.

The invoice is real. The amount matches what you owe. The purchase order number is correct. The sender’s address is correct except for one character you would have to read letter by letter to catch. The number on the attachment rings, and a polite voice confirms the change. Your bookkeeper pays it. Eleven days later the real supplier calls about a past-due balance, and $47,000 is gone.

Nothing in that sequence required malware or an unpatched server. It required one thing: a payment instruction that changed, and nobody calling a number the attacker did not control. That is the whole attack and the whole defense. What follows is not an explainer — it is a procedure you can hand to whoever cuts your checks on Monday.

What business email compromise costs, and why urgency works

Two levers do all the work. Authority: the request appears to come from someone your employee is not in the habit of questioning — a supplier’s accounts department, the CEO, an attorney handling a closing. Pushing back feels like insubordination or bad service. Urgency: a deadline that makes verifying look like the expensive choice. Urgency is in these messages for one reason — it is the only tool the attacker has that shortens the gap between “request received” and “money sent.” Remove the time pressure and the attack collapses.

The scale is not theoretical. In the FBI’s 2025 IC3 Annual Report, the Internet Crime Complaint Center logged 24,768 business email compromise complaints accounting for $3,046,598,558 in reported losses — the second-costliest crime type by dollar loss that year, behind investment fraud, out of $20.877 billion in total losses across 1,008,597 complaints. BEC is not the most common complaint type. It is one of the most expensive per incident, because one message moves an invoice-sized amount of money.

For the anatomy of the attack itself — how the mailbox gets compromised, how lookalike domains are registered, how the attacker reads invoices in a thread for weeks before saying a word — see our guide to what business email compromise is. That article explains the attack; this one is the single operational control that stops it, whichever variant hits you.

The callback rule, written down

Paste this into your accounting policy, your handbook, or a card taped above the bookkeeper’s monitor. Change the dollar threshold and the names; change nothing else.

PAYMENT VERIFICATION POLICY — THE CALLBACK RULE

  1. Trigger. Mandatory for: (a) any payment to a payee we have never paid before; (b) any change to the bank details, routing number, account number, or payment method of an existing payee; (c) any payment request arriving outside our normal invoice process, including by text, chat, or phone; (d) any request described as urgent or confidential.
  2. Callback to a known number. Before release, a named employee calls the payee and verbally confirms the request. The number must come from our vendor master record, a prior paid invoice, or the signed contract. The number in the requesting email, its signature block, or any attachment may never be used. If no known number exists, we obtain one through an independent channel and document how.
  3. Two-person approval. Any payment at or above $[THRESHOLD], and any payment involving changed bank details at any amount, requires two named approvers. Whoever performs the callback may not be the person who releases the payment.
  4. Verbal safe word. Any approval given by voice — phone, voicemail, or video call — requires the current safe word, distributed in person or on paper, never by email or chat, and changed on a set schedule.
  5. Mandatory delay. No payment triggered by this procedure is released the same business day it is requested. Urgency is not an exception to this rule; it is a reason to apply it.
  6. Written record. Every verification logs who called, the number dialed, who answered and their title, date and time, the outcome, and who approved release. Retained with the payment record.
  7. No exceptions. No officer, owner, client, or attorney may waive this procedure. A request to bypass it is itself a red flag and is escalated.

Item 2 does all the work. An attacker can forge letterhead, spoof a display name, register a domain one character off yours, and staff a phone line — all of it cheap. What they cannot do is answer the phone at the number your clerk already had from a paid invoice three months ago. That single habit — call the number you already had, never the number they gave you — is the whole payment verification callback procedure in one sentence.

Payment verification by trigger: who signs off on what

Print this next to the rule. Note that the bank-details row has no dollar threshold, and that the delay column is not padding — the same-day exception is where these procedures die.

TriggerRequired verificationWho signs offDelay
New payee, any amountCallback to a number obtained independently of the request; document its sourceAP clerk verifies; owner or finance lead approves1 business day
Change to existing payee’s bank detailsCallback to the number already in the vendor master — never one supplied with the requestTwo named approvers, regardless of amount1 business day minimum
Routine invoice, existing payee, unchanged details, under thresholdNormal invoice matching; no callbackAP clerkNone
Any payment at or above your dollar thresholdCallback plus written approvalTwo named approvers1 business day
Request from an executive by email, text, or chatCallback to that executive’s number from your own directory, not the messageOwner or finance lead plus one other1 business day
Approval given by voice or video callCurrent safe word plus callback to a known numberTwo named approvers1 business day
Payroll direct-deposit changeCallback to the number in HR records; confirm in person if possibleHR plus payroll approver1 pay cycle

Why “I called him and it sounded like him” is no longer verification

This procedure has one failure mode: the employee calls, hears a familiar voice, and releases the money. That voice is now the cheapest part of the attack to fake. The FBI’s public service announcement of December 3, 2024, on criminals using generative AI to commit fraud, states that criminals “generate short audio clips containing a loved one’s voice to impersonate a close relative in a crisis situation.” Its countermeasure is equally plain: “Create a secret word or phrase with your family to verify their identity.” The Bureau framed that for families, but the mechanics are identical in a business: a passphrase works because a cloned voice reproduces sound, not shared knowledge. FinCEN alert FIN-2024-Alert004 (November 13, 2024) warned financial institutions of rising reports of deepfake media used to circumvent identity verification controls, and the FBI’s PSA of May 15, 2025 on AI-generated voice messages impersonating senior US officials told recipients to “independently identify a phone number for the person and call to verify their authenticity.”

The safe word is the one factor a voice clone cannot supply. Pick something arbitrary rather than the dog’s name. Distribute it in person or on paper, never by email, chat, or text — an attacker in a compromised mailbox reads everything. Give it only to people who can approve payments, and change it when someone leaves. If a caller demanding payment does not have it, the answer is no. Not “let me check.” No.

The mechanics — how the audio is sourced, what the call sounds like, why caller ID is worthless — are covered in our article on vishing and deepfake voice fraud. That one is about recognizing the call; this one is about the control that means you do not have to.

Making the callback rule survive contact with reality

A rule nobody can follow gets abandoned in about three weeks. Three things make it stick.

Clean the vendor master first. The callback depends on having a known-good number on file. Spend an afternoon on your top twenty vendors by spend, confirm a direct number for each one’s accounts receivable contact, and record where you got it.

Make lookalike email visible. In Microsoft 365, turn on external sender identification in the Exchange admin center and review impersonation protection under anti-phishing policies in the Microsoft Defender portal. In Google Workspace, go to Apps > Google Workspace > Gmail > Safety and enable protection against spoofing of employee names and lookalike domains. Neither replaces the callback.

Test it, and give the bookkeeper cover. Once a quarter, send your own fake change-of-bank-details request and see what happens. This pairs with general phishing defenses and an understanding of how social engineering pressures employees; security awareness training platforms automate the simulations, though a manual test costs nothing. Say out loud in a meeting that nobody will ever be criticized for slowing a payment down — most procedural failures are social, not technical.

Wire fraud recovery: the first hours after the money leaves

Most people read an article like this after the money is gone. Recovery is possible, and it is purely a function of speed. The FBI’s Internet Crime Complaint Center runs a Recovery Asset Team, established in 2018, which uses the Financial Fraud Kill Chain to contact the receiving bank and freeze funds before they are withdrawn or moved onward. Per the 2025 IC3 Annual Report, the RAT initiated 3,900 kill chain incidents in 2025 against $1,163,919,846 in attempted theft and froze $679,013,183 — a 58% success rate. That is not a long shot, but it only works if you move immediately. The report’s instruction: “If you discover a fraudulent transfer, time is of the essence. Immediately, contact your financial institution and request a recall of the funds along with any necessary indemnification documents.” It adds, “Regardless of the amount lost, file a complaint at www.ic3.gov.” IC3 publishes no minimum figure and no cutoff hour — treat the window as the next few hours, because once funds are withdrawn or forwarded onward there is nothing left to freeze.

In order, and in parallel where you have the people:

  1. Call your bank’s fraud department by phone, not email. Request a wire recall and a hold on the receiving account, and get a case number.
  2. File at ic3.gov immediately with full transaction detail: date, amount, sending and receiving bank names, account and routing numbers, reference numbers. Incomplete reports cannot be actioned fast.
  3. Contact the receiving bank yourself, in writing, stating the transfer was fraudulently induced and requesting a freeze — do this even if your bank is also doing it. Then call your local FBI field office and reference your IC3 complaint number.
  4. Notify your insurer or broker the same day. Policies carry notice deadlines, and late notice is a coverage defense.
  5. Preserve evidence. Do not delete the emails or forward them as normal messages — save the originals with full internet headers intact, plus attachments. Suspend auto-delete on the mailbox and check for inbox rules the attacker created to hide replies.
  6. Assume a mailbox is compromised. Reset passwords, revoke sessions, enable MFA, and audit forwarding rules before resuming normal payments.

On who absorbs the loss, be pessimistic until your broker says otherwise. A payment you authorized — even one induced by fraud — is frequently excluded from a standard commercial crime policy’s computer fraud and funds transfer coverage, precisely because you initiated the transfer. What responds is usually a specific social engineering fraud or fraudulent instruction endorsement, often at a sublimit far below your policy limit and sometimes conditioned on having a documented callback procedure — some carriers require the exact control described here. Do not take a coverage opinion from an article: pull your policy and ask your broker whether fraudulent instruction is covered, at what sublimit, and on what conditions. Our overview of small business cyber insurance explains how these policies fit together.

What to do this week

  1. Monday: Copy the callback rule into a document, set your two-person threshold to a real number, and put your name on it as approver.
  2. Tuesday: Verify direct phone numbers for your top twenty vendors by spend, write them into the vendor master, and note where each came from.
  3. Wednesday: Choose a safe word. Write it on paper, hand it to the people who approve payments, and set a calendar reminder to change it quarterly.
  4. Thursday: Turn on external sender tagging and anti-impersonation settings in Microsoft 365 or Google Workspace, and confirm MFA on every mailbox that touches money.
  5. Friday: Walk the rule line by line with whoever pays your bills, and tell them plainly that delaying a payment to verify it will never be held against them — including when the request appears to come from you.
  6. Next week: Send your own test change-of-bank-details email and see whether the callback happens. Save your bank’s fraud line in your phone now, before you need it.

Total cost: one afternoon and a piece of paper — the highest-return security work available to a small business, and the one almost nobody does until after the wire has cleared.

Get the Cybersecurity Policy (Premium)

The master policy document, ready to adapt — including the payment approval and verification controls this article walks through.

Get it on Gumroad →

Similar Posts