Business Email Compromise at Credit Unions: How Attackers Redirect Wire Payments and What Stops Them
What is Business Email Compromise at a Credit Union?
Business email compromise (BEC) is a financial-fraud attack in which a criminal impersonates a trusted party: a vendor, an executive, or a member; to trick credit union staff into redirecting a legitimate payment to an account the attacker controls. Unlike ransomware, BEC rarely involves malware; it exploits the wire and ACH approval process itself.
How does a BEC attack unfold, step by Step
A typical BEC attack at a credit union follows a predictable chain. The attacker first researches the target by examining the credit union’s website for vendor names, staff roles, or member lists. They may monitor outbound email to identify common payment patterns or vendor relationships. Then they craft an email address that mimics a legitimate sender: a vendor name with a slightly altered domain, an executive’s name on a lookalike account, or a member’s email with a typo that’s easy to miss under time pressure.
The email arrives in an employee’s inbox with an urgent request: a vendor needs their banking details updated before tomorrow’s payment runs; an executive needs funds transferred immediately for a client emergency; or a member is requesting a wire on a business account to close a time-sensitive deal. The attacker counts on momentum and authority. They may reference a real project, a real member, or a real vendor to build credibility. A wire technician or accounting staff member, processing dozens of legitimate requests daily, may not pause to verify the sender’s address character by character or call the vendor back using a number from the company’s own records.
Once the employee clicks “approve,” the payment flows to the attacker’s account, which is often overseas, structured to look legitimate but designed to clear and move quickly. By the time the credit union or the member notices the transaction is missing or misrouted, days have passed. Wire reversals are difficult. ACH reversals have narrow windows. The money is often unrecoverable.
What are the most common BEC scenarios at credit unions?
Vendor Impersonation. A credit union receives an email from what appears to be the IT vendor, the branch supply company, or the loan-servicing platform. The sender claims they’re updating their banking information for future invoices. A staff member enters the new account details into the accounts-payable system. When the next invoice arrives from the real vendor, the payment goes to the attacker instead. Months can pass before the discrepancy surfaces, especially if the real vendor doesn’t follow up on unpaid invoices immediately.
Executive Impersonation. An email arrives that appears to be from the CEO or CFO requesting an urgent wire transfer for a business opportunity, regulatory fee, or acquisition deposit. The sender’s urgency, “this needs to clear before 4 p.m. today”, bypasses normal scrutiny. A mid-level staff member, accustomed to following executive directives, processes the request without the verification step that would normally apply.
Member Impersonation. The attacker poses as a credit union member, requesting a wire or ACH transfer from their business account. The request may reference a real business deal or lease the attacker learned about through public records or social media. Because the attacker is requesting their own account to send funds, not the credit union’s, the wire goes through. The attack targets the member, but it damages the credit union’s reputation and compliance posture when the member disputes the transaction.
Payroll Diversion. The attacker sends an email to the payroll processor or HR department claiming to be an employee requesting direct-deposit changes. The request redirects future paychecks to an account controlled by the attacker. Because payroll is processed in batches on a fixed schedule, the fraud may go undetected for one or more pay cycles. Affected employees discover it only when their deposit fails to arrive.
Why is email authentication (SPF, DKIM, DMARC) the first line of defense?
Email authentication standards do not block BEC attacks outright, but they make spoofing significantly harder and give credit unions a concrete technical control that regulators recognize.
SPF (Sender Policy Framework) tells the internet which mail servers are authorized to send email on behalf of a domain. When a credit union’s email system receives a message claiming to be from “vendor.com,” it checks vendor.com’s SPF record. If the sending server is not on the authorized list, the message is flagged or rejected. An attacker using a lookalike domain like “vendor-services.com” instead of “vendor.com”, bypasses SPF because the lookalike domain has no SPF record to check. But a credit union that monitors which vendors it actually receives email from can enforce stricter rules: flag unauthenticated mail from critical vendors and require additional verification before payment.
DKIM (DomainKeys Identified Mail) cryptographically signs outgoing mail so the receiving system can verify it genuinely came from the claimed sender. If an attacker spoofs an email using a real vendor’s domain name but doesn’t have the vendor’s DKIM private key, the receiving email system detects the forgery. DKIM is not foolproof, it doesn’t prevent lookalike domains, but it raises the attacker’s burden: they must either compromise the real domain or register a fake one and hope staff doesn’t notice.
DMARC (Domain-based Message Authentication, Reporting, and Conformance) ties SPF and DKIM together and tells email systems what to do when authentication fails: reject the message, quarantine it, or allow it through while flagging it as suspicious. More importantly, DMARC sends reports back to the domain owner: the vendor, the credit union, etc.; showing exactly where mail claiming to use their domain is coming from. A credit union can review these reports to spot lookalike-domain attacks targeting its vendors before employees see the fraudulent email. A vendor can use DMARC reports to alert their customers that spoofing is occurring and to verify requests through a phone call.
For credit unions, the practical step is to deploy DMARC monitoring for vendors and partners that the institution sends wire and ACH payments to regularly. If a payment-change request arrives, and DMARC shows that mail claiming to be from that vendor is coming from an unauthenticated source or a misaligned domain, that’s a hard stop: call the vendor back using the number on the credit union’s own records before processing the change.
What is out-of-band verification and how does it stop wire redirects?
The single most effective control against BEC is out-of-band verification: any request that changes a payment destination, such as a vendor’s banking details, a wire instruction, an ACH routing number, or a member’s direct-deposit setup must be verified through a separate communication channel before processing.
Out-of-band means: if the request arrives by email, verify by phone. If it arrives by phone, verify in person or through a documented callback to a known number. A staff member receives a vendor email requesting a banking update. Before entering it into the accounts-payable system, the staff member hangs up any call, opens the vendor’s phone number from the credit union’s contact list (not from the email), and calls the vendor directly: “I received an email asking to update your banking information. Can you confirm the new account number and routing number?” The vendor either confirms or alerts the credit union to a spoofing attempt in real time.
This control is simple but requires discipline. Urgency is the attacker’s weapon. The email says “this needs to be processed before end of day.” The staff member’s instinct is to move fast. The defense is to flip that instinct: urgency itself becomes a reason to slow down and verify. A real vendor will wait for a phone callback. A real executive will understand that wire transfers require verification. A real member expects the credit union to call back before moving large sums.
Credit unions under $500M often struggle to implement this control because small-business banking creates high volume and the staff that processes wires or ACH transfers is lean. But the control doesn’t require new technology. It requires a documented policy, staff training, and a clear signal from leadership that verification is non-negotiable. Examiners expect this control to be documented and followed consistently.
What does FBI IC3 data say about BEC losses?
The FBI’s Internet Crime Complaint Center reports that business email compromise is the single most damaging cyber-crime category for businesses and financial institutions by dollar loss. Across all sectors, reported BEC losses exceed $2.7 billion annually in the United States. Financial services like banks, credit unions, and payment processors account for a large share of this because wire and ACH systems move money at scale and with limited reversal options.
Credit unions are particularly targeted because they hold business accounts, process payroll, and manage vendor relationships. A single successful BEC attack can siphon off $50,000 to $500,000 in a matter of hours. Small and mid-size credit unions often lack the redundant approval processes and electronic controls that larger institutions have built in. An attacker researching a $100 million credit union knows that wire requests may require only one or two approvals from staff who process dozens daily.
Real cases show the pattern. In the vendor-impersonation scheme litigated as Studco Building Systems v. 1st Advantage Federal Credit Union, attackers spoofed a vendor’s email, supplied new banking details, and diverted four ACH payments totaling $558,868.71 into an account held at the credit union before anyone caught it (the Fourth Circuit ultimately ruled, in March 2025, that the receiving credit union was not liable). And in January 2025, a federal grand jury in South Carolina indicted twelve people for a nationwide BEC operation that used spoofed vendor and executive emails to redirect wire and ACH payments from businesses across multiple states. Both cases highlight the same lesson: attackers impersonate the vendors and partners an institution already trusts, and the fraudulent payment request looks routine until the money is gone.
The pattern suggests that a credit union’s first line of defense: it’s monitoring and alerting when attackers attempt to spoof the credit union’s vendors and partners; is not internal. If a vendor’s domain is being spoofed or compromised, the credit union should know immediately, in time to brief staff on the threat before a fraudulent payment request arrives.
How do NCUA examiners evaluate wire and ACH controls?
The National Credit Union Administration (NCUA) expects credit unions to maintain controls over wire and ACH transactions that address fraud risk at multiple levels. Examiners specifically look for:
Segregation of duties. The person who initiates a wire or ACH request should not be the same person who approves it. For very small credit unions, this is a hardship, but NCUA permits risk-based adjustments: if segregation is not possible, then compensating controls such as post-transaction verification or mandatory review by the board, must be documented.
Authorization limits. Staff members have explicit transaction limits based on their role. A teller cannot initiate a wire over $10,000; only the branch manager or operations director can. These limits are enforced by the core system and reviewed during exams.
Verification of payment-destination changes. Any change to a vendor’s banking information, a member’s direct-deposit setup, or a wire routing number must be verified before processing. The verification must be documented with a note in the transaction record showing the date, time, and method of verification.
System logs and audit trails. The credit union must retain logs showing who accessed what transaction, when, and what action they took. If a fraudulent wire is processed, investigators need a clear record of who approved it and whether they followed the verification procedures.
Monitoring for unusual activity. Credit unions are expected to review high-value wires, out-of-pattern vendor payments, and member transactions that deviate from normal behavior. Many credit unions now use transaction-monitoring software to flag these patterns automatically.
During an exam, if an NCUA examiner discovers that a credit union processed a wire without documented verification of the destination, or if they find that the same person initiated and approved a transaction, these are noted as control deficiencies. Repeated or severe deficiencies can result in enforcement action. Conversely, credit unions that maintain strong, documented controls over wire and ACH, particularly out-of-band verification and email authentication for critical vendors, often receive favorable exam ratings and lower regulatory compliance scores.
BEC defense checklist for credit unions under $500M
Email Authentication and Monitoring
- Deploy DMARC monitoring for all vendors and partners the credit union sends payments to. Generate and review DMARC reports weekly.
- Configure SPF and DKIM enforcement for the credit union’s own domain. Set DMARC policy to “reject” for unauthenticated mail.
- Brief wire and ACH staff on which vendors should have authenticated email. Provide a reference list updated quarterly.
- Flag any payment-change request from a vendor whose DMARC report shows authentication issues. Do not process without a phone callback.
Out-of-Band Verification Protocol
- Document a formal policy: every wire destination change, vendor banking update, or high-value ACH requires verification by phone or in-person callback before processing.
- Maintain a current contact list for critical vendors, separate from email. Post this list where wire and ACH staff can access it immediately.
- Train wire and ACH staff to always initiate the callback. Do not use phone numbers embedded in emails.
- For requests from members, call the member back at the number on file in the core system. If the member did not initiate the request, treat it as potential fraud and escalate.
Staff Training
- Train wire and ACH staff quarterly on BEC tactics and red flags: urgency, unusual requests, slightly altered email addresses, requests that bypass normal approval channels.
- Teach staff that slowing down is the correct response to urgency, not a hindrance. A real transaction can wait for a callback.
- Conduct simulated phishing exercises targeting staff with access to wire and ACH. Use results to identify high-risk individuals and focus training.
- Include executives and board members in awareness training. They are often impersonated in BEC attacks; they need to understand that staff will verify their requests.
System and Process Controls
- Segregate duties: ensure the person who initiates a wire or ACH is not the person who approves it. If the credit union is too small, compensate with mandatory secondary review or board approval for high-value transactions.
- Set transaction limits by role and enforce them in the core system.
- Enable audit logging for all wire and ACH transactions. Retain logs for at least three years.
- For any wire or ACH initiated through online banking or third-party platforms, require manual secondary approval from staff before the transaction actually moves.
Vendor and Member Communication
- Send quarterly reminders to critical vendors explaining that you will always call back to verify banking changes, and ask them to do the same with your institution.
- Include a statement in business account agreements informing members that the credit union will verify wire requests and payment changes through a separate phone callback.
- Provide a fraud hotline that members and vendors can use to report suspicious requests claiming to come from the credit union.
Monitoring and Response
- Review wire and ACH transactions weekly for unusual patterns: payments to new vendors, out-of-market wires, high-value transactions outside business hours.
- Set up alerts in the core system or transaction-monitoring software for wires over a certain threshold, to new destinations, or from unusual initiators.
- If a fraudulent wire or ACH is discovered, freeze the account immediately, notify law enforcement, preserve logs, and conduct an investigation with documented findings.
Taking Action
BEC targets credit unions because the defense: good email authentication, disciplined verification, and staff training; requires ongoing attention rather than sophisticated technology. But that same simplicity is your advantage: a credit union that implements these controls reduces BEC risk significantly.
TorchLight has helped credit unions manage email security and fraud risk for nearly two decades. We monitor DMARC authentication for your vendors and critical partners, detect email threats in real time with 24/7/365 coverage, and provide your staff with the tools and training to verify payment requests before they move. Our managed security services combine these capabilities into one solution, one invoice, and one partnership: removing the complexity of coordinating email monitoring, threat detection, and incident response separately.
To discuss how your credit union can strengthen its defenses against BEC, contact TorchLight’s managed security team.
FAQs
A: BEC is a financial-fraud attack where a criminal impersonates a trusted vendor, executive, or member to trick credit union staff into redirecting a legitimate wire or ACH payment to an account the attacker controls. It rarely uses malware; it exploits the payment approval process itself.
A: Out-of-band verification. Any request that changes a payment destination is confirmed through a separate channel (for example, calling the vendor back at a number from your own records) before processing.
A: DMARC does not block BEC outright, but it makes domain spoofing far harder and gives credit unions a technical control regulators recognize. DMARC reports also reveal when attackers spoof your vendors, so staff can be warned before a fraudulent request arrives.
A: The FBI’s Internet Crime Complaint Center reports U.S. BEC losses exceeding $2.7 billion annually. A single successful attack on a credit union can divert $50,000 to $500,000 within hours.
A: Examiners look for segregation of duties, role-based authorization limits, documented verification of payment-destination changes, audit logs, and monitoring for unusual activity. Undocumented verification or one person initiating and approving a transaction is flagged as a control deficiency.
TorchLight specializes in managed security services for organizations where security and compliance are non-negotiable. With 18+ years serving regulated industries, 24/7 SOC operations, and deep regulatory fluency across GLBA, HIPAA, and SEC requirements, TorchLight delivers security operations leadership can defend.
Ready to explore what partnership looks like? Schedule a consultation to discuss your organization’s specific security needs and regulatory requirements.

