PayBeacon

How exposed is your firm to payment fraud?

Ten questions, sixty seconds — in the same language E&O and cyber-insurance applications use. Answer honestly; the point is finding gaps before a fraudster or an insurer does.

Your answers and score never leave your browser — scored on your screen only, never stored or sent. No email required.

1 / 10
When a vendor emails new bank details, does someone call a number already on file — never one from the email?
The number in the email belongs to whoever wrote the email.
2 / 10
Is that callback required by a written procedure — not just habit?
"We're careful" is not a control. Insurers ask for the procedure.
3 / 10
Does a brand-new vendor require the client's confirmation — "did you hire these people?" — before the first payment?
Phantom vendors pass existence checks. They fail this one.
4 / 10
Do bank-detail changes and new payees require two people to approve?
One rushed person is the attack surface.
5 / 10
Is there a dollar threshold above which extra verification is mandatory?
Written down, with what "extra" means.
6 / 10
When a client sends an "urgent" payment request, is it confirmed on a known-good channel before money moves — even when they say not to?
Urgency and secrecy are the fraud's engine, not a reason to skip the check.
7 / 10
Are payroll direct-deposit changes verified with the employee on a contact that existed before the request?
"Update my deposit before Friday" is a template attack.
8 / 10
Is every verification recorded — who called, which number, when, what was confirmed?
If it isn't written down, it didn't happen.
9 / 10
Could you produce that evidence for a specific payment if a client's insurer — or their lawyer — asked?
This is the question that gets asked after the loss.
10 / 10
Are the payment details on each incoming invoice compared against what's on file for that vendor?
The patient fraud never announces the change — it just appears on invoice #47.

Three things that actually happened

Never hacked, sued anyway. A major professional firm wired client money after fake instructions arrived from the client's real, compromised email account. The firm's own systems were never breached. It's being sued regardless.
$25 million, one video call. A finance employee wired the money after a meeting where the CFO — and every colleague on screen — was an AI deepfake.
$123,000 — the average. That's the FBI's average loss per business-email-compromise incident in 2025: $3 billion across ~25,000 reported cases, the worst year on record.
Sources: federal court filings; Hong Kong police reports; FBI IC3 2025 Annual Report.