Fraud losses are rarely caused by one spectacular failure. More often, a small anomaly is noticed, explained away, then followed by another. The company keeps moving because the shipment is ready, the sales target matters, or the counterparty sounds offended by the questions.
Here are eight avoidable mistakes that commonly make a weak situation worse.
1. Using the counterparty’s own evidence to verify the counterparty
Bad practice: the contact sends a certificate, a phone number and a website; staff check those three items against each other and call the verification complete.
Better practice: use at least one source the contact did not provide — an official registry, an independently found switchboard, a trusted existing relationship, a professional due-diligence provider or another authoritative source.
The U.S. Commercial Service’s background-check guidance specifically recommends looking beyond superficial website information and treating domain and contact mismatches as red flags.
2. Treating a bank-change document as authentication
Bad practice: “They sent the instruction on letterhead, so finance updated the bank.”
Better practice: treat the letter as data to be authenticated, not as authentication itself. Call a previously verified number and confirm the change with a known contact. Require a second approver for material transfers.
FBI BEC guidance recommends secondary channels to verify account-information changes because compromised email can make a fraudulent instruction look like it came from a real business relationship.
3. Letting urgency lower the verification standard
Bad practice: an urgent discount, production slot, customs deadline or “CEO instruction” becomes a reason to skip a control.
Better practice: decide in advance which controls are non-waivable and which can be compressed. A five-minute independent callback is often compatible with urgency; removing the callback entirely is not.
4. Assuming a repeat transaction is low risk
Bad practice: the first two payments worked, so the third bank change is accepted without question.
Better practice: verify changes, not just relationships. A genuine supplier’s account can be compromised after years of clean trading. The trust built with the real company is precisely what an attacker tries to borrow.
5. Ignoring the delivery side of fraud
Bad practice: fraud review is owned only by accounts payable.
Better practice: connect finance and logistics. The FBI’s 2023 vendor warning described schemes where criminals impersonated legitimate companies to acquire commodities. If a buyer’s delivery address changes, the warehouse should know whether that change was independently approved.
6. Collecting information without deciding what would stop the deal
Bad practice: the due-diligence file lists six red flags, but nobody owns the decision.
Better practice: define escalation thresholds. For example, one explainable anomaly may require documentation; two independent identity mismatches may require a hold; a last-minute bank change plus refusal to verify through the published switchboard may require cancellation or senior review.
Thresholds should be tailored to risk and local law. The point is not the exact formula. The point is that “we found something strange” must lead to an action.
7. Calling a suspected fraudster before preserving options
Bad practice: an employee angrily emails “We know you are a scammer” before the bank, carrier or counsel is contacted.
Better practice: preserve evidence, contact the financial institution or carrier where time-sensitive action is possible, and decide reporting and communication strategy with the appropriate professionals. Premature confrontation can cause evidence to disappear or goods/funds to move faster.
8. Cleaning up the file after the loss
Bad practice: staff delete informal chat messages, rewrite call notes, or replace the original invoice with the “corrected” version.
Better practice: keep originals and add explanatory notes separately. A messy authentic record is more useful than a neat reconstructed one.
Quick comparison: what changes the answer?
| Signal | Could be legitimate | Why it still needs checking |
|---|---|---|
| New bank account | Treasury restructure | Also common in payment diversion |
| Third-country payee | Group treasury / agent | May create contract, compliance or recovery issues |
| Rush order | Genuine demand spike | Can be used to suppress verification |
| New employee contact | Staff change | Identity and authority may be unverified |
| Different delivery address | Customer site / 3PL | May be diversion of goods |
| Free email account | Small business practice | Harder to tie to claimed company identity |
The right mindset is not “every anomaly is fraud.” That creates false alarms and frustrates legitimate trade. The right mindset is “every material anomaly needs an explanation that can be independently checked.”
A short recovery sequence if one of these mistakes already happened
If funds were sent to a suspicious account, contact the financial institution immediately and ask what recall or fraud procedures exist. If goods are moving, contact the verified carrier or warehouse and ask about a hold or return. Preserve records before editing anything. Then evaluate contractual remedies, fraud reporting, cyber incident response and insurance notifications with the relevant local professionals.
FinCEN’s email-compromise advisory is directed to financial institutions, but it underscores how fraud exploits vulnerable payment processes. For trading companies, that means the control cannot end with “we know the supplier.” It must include how payment changes are authenticated.
This article is general cross-border commercial-risk information, not legal advice. Fraud law, contract remedies, banking procedures, reporting duties and evidence rules differ by jurisdiction. Get local counsel for material disputes or transactions.
The most expensive mistake is usually not that a red flag appeared. It is that the organization saw the red flag and had no practiced way to stop, verify and resume safely.
Additional operating note: measuring fraud control by how many checks were performed
A team can complete ten low-value checks and still miss the one fact that controls the risk. Counting registry searches, screenshots and forms does not answer the more important question: Did anyone independently authenticate the instruction that moved money or goods? Good controls are risk-linked, not paperwork-linked.
Additional operating note: failing to update the counterparty file after a legitimate change
There is another side to the problem. If a bank change is properly verified but the approved vendor record is never updated, future employees may treat the correct account as suspicious or, worse, rely on an old unverified spreadsheet. After a legitimate change passes review, update the controlled master record, note the verification date and retire obsolete details without deleting the audit history.
A better operating rhythm
For recurring counterparties, use a short periodic review instead of waiting for a crisis. Confirm that the legal entity still exists, key contacts still work there, the verified domains remain the same, material ownership or address changes are understood, and payment controls still match the contract. The frequency should reflect exposure: a strategic supplier receiving large wires may justify more frequent checks than an occasional low-value vendor.
A useful post-incident review also asks which control failed at which layer. If an impostor fooled the company despite a correct registry check, adding more registry checks will not solve the problem. If the failure was a missing callback on bank changes, fix that specific process.
Exception-discipline note: treating an exception as a permanent shortcut
A control often erodes after a legitimate emergency. A senior manager approves one unusual transfer because a vessel is closing, the transaction turns out to be genuine, and the team quietly treats that exception as a new precedent. That is dangerous. An exception should record who approved it, what evidence justified it, which normal control was bypassed, and when the exception expires. The next transaction should return to the normal process unless a formal policy change is made. This matters because fraudsters watch for habits: once staff become accustomed to "special" payment routes or rushed approvals, a later impostor needs less persuasion. A useful review question is not merely “Was the last exception legitimate?” but “Did we accidentally teach the organization to accept weaker proof?”
Sources
- U.S. International Trade Administration — Commercial Service Tips on Background Checks. accessed 2026-10-03. https://www.trade.gov/feature-article/commercial-service-tips-background-checks
- U.S. International Trade Administration — Perform Due Diligence. accessed 2026-10-03. https://www.trade.gov/perform-due-diligence
- FBI Internet Crime Complaint Center — Business Email Compromise. accessed 2026-10-03. https://www.ic3.gov/CrimeInfo/BEC
- FBI IC3 — BEC Tactics Used to Facilitate the Acquisition of Commodities and Defrauding Vendors. published 2023-03-24. https://www.ic3.gov/PSA/2023/PSA230324
- FinCEN — Updated Advisory on Email Compromise Fraud Schemes Targeting Vulnerable Business Processes. issued 2019-07-16. https://www.fincen.gov/resources/advisories/fincen-advisory-fin-2019-a005
Related Reading
- A 12-Step Counterparty Fraud Check Before You Send Money or Goods
- Negotiate, Freeze Funds, Report, Sue—or Walk Away? Choosing a Response to Counterparty Fraud
- Red Flags That Mean a Counterparty Problem Is Escalating