WHEN WIRE INSTRUCTIONS GO WRONG: LESSONS FROM A $50,000 CYBER FRAUD

Cyber fraud targeting condos and property management companies is no longer theoretical, it’s the stark reality of today’s world of electronic communications. A recent incident involving a management company illustrates how quickly a seemingly ordinary transaction can become a financial nightmare, and how easily liability disputes can follow.

The Incident

A property management company received what appeared to be legitimate wire instructions for payment of a vendor invoice on behalf of a condominium. The instructions were transmitted by email and reflected a change from prior payment methods. The email appeared credible, matched a known contact, and did not raise any immediate red flags.

Relying on those instructions, the manager wired approximately $50,000 to an account controlled by the Threat Actor.

The vendor never received payment, and the condominium was out the money.

This fact pattern is becoming increasingly common but now the bad guys are coming after condominiums and management companies too.

The Core Problem: Email Is Not a Secure Payment Channel

The underlying issue in cases like this is simple: email is inherently insecure, particularly when used to transmit payment instructions.

In many cases:

  • Email accounts have been compromised without detection.

  • The fraudulent instructions are sent from a real (hijacked) email account or a nearly identical spoofed address.

  • The request involves urgency or last-minute changes, discouraging scrutiny.

By the time the fraud is discovered, the funds are often irrecoverable.

Who Bears the Loss?

From a legal standpoint, these situations create immediate tension among the three parties involved: 1) the payor (e.g., the management company or association); 2) the intended payee/vendor; 3) the bad actor, who has disappeared with the funds. Additionally, there could be a bitter dispute between the condominium and their management company over disbursement of the funds.

Generally speaking, a payment obligation is only discharged when payment is received by the intended party. Therefore, wiring funds to a fraudster—however reasonable it may have seemed at the time—does not typically satisfy the underlying obligation.

Practical Takeaways for Our Clients

This type of fraud is highly preventable. The following best practices should be communicated clearly to all boards, managers, and staff:

Never Rely Solely on Emailed Wire Instructions

— Especially when:

  • Instructions differ from prior payments;

  • There is a last-minute change; or

  • The request involves urgency;

Email must be treated as an unverified communication channel.

Implement Mandatory Callback Verification

This is the most important step. Any time wire instructions are received or modified, they must be verified through a known, independent phone number (not email!). Each time, every time:

  • Use a phone number already on file—not one provided in the most recent email.

  • Speak directly with a known contact at the vendor.

  • Document the verification (date, time, person spoken to).

No verification = no wire.

Treat Changes in Payment Instructions as High-Risk Events

Policies should explicitly flag the following as requiring heightened scrutiny:

  • Requests to change bank accounts,

  • Requests to switch from checks to wire transfers,

  • Requests made close to payment deadlines.

These are the most common entry points for fraud.

Train Staff and Board Members

Cyber fraud prevention is not solely an IT issue—it is an operational and governance issue. Awareness of the issue alone can be enough to prevent catastrophe from striking. Staff training should cover:

  • Common fraud schemes (business email compromise, spoofing, phishing),

  • How to recognize suspicious communications,

  • Internal approval and verification procedures.

Even experienced professionals are routinely deceived without structured safeguards.

A Critical Protection: Cyber Insurance Coverage

Even with strong internal controls, no system is perfect. For that reason, management companies—and, where appropriate, associations—should maintain insurance coverage specifically designed to address this risk.

Align Internal Controls with Policy Requirements

Insurance carriers frequently require specific procedures (such as callback verification) as a condition of coverage. If the procedures are not followed, there could be no coverage for the claim.

Conclusion

The $50,000 loss described above could have been prevented with a simple phone call and that is often the case. In today’s environment, the assumption must be that email communications involving money are vulnerable to compromise. The only reliable defense is to treat all payment instructions—particularly new or revised ones—as untrusted until independently verified.

Please contact Dean Lennon with any questions regarding this issue or any of our MEEB attorneys.

Next
Next

FRAUD RISKS MAY BE SMALL FOR CONDOS BUT FIDELITY INSURANCE IS ESSENTIAL