7 Steps to Prevent Successful Phishing Attacks and Payment Fraud

A recent phishing attack against the City of Pittsburg, California, demonstrates why email security cannot be separated from financial controls.

According to the city, an attacker compromised its email system and impersonated a known vendor, causing a single unauthorized ACH payment of $913,839.81 to be sent to a fraudulent account. The payment was made on February 12, 2026, and identified five days later. Authorities froze the receiving account and recovered $696,241, while the city pursued insurance coverage for the remaining funds.

The investigation remains active, and the publicly available reports do not explain every technical or procedural failure that allowed the payment to be approved. But the incident illustrates an important point for every organization that pays vendors electronically:

Preventing successful phishing attacks requires more than teaching employees to identify suspicious emails.

Businesses need overlapping controls across email, identity, finance, training, monitoring, and incident response. If one control fails, another should stop the attacker before money or sensitive information leaves the organization.

1. Independently verify every vendor payment change

Requests to change a vendor’s bank account, routing number, payment method, or remittance address should automatically trigger an independent verification process.

Call a trusted vendor contact using the phone number already stored in your vendor management system—not the number supplied in the email requesting the change. Employees should also start a new email thread using a known address rather than replying directly to the original message.

The FBI specifically recommends verifying changes to vendor payment information through a previously established contact method. This protects against attackers who have spoofed an address or taken control of a legitimate email account.

Organizations should document this requirement so employees do not have to decide whether a request “looks suspicious.” Every change receives the same verification.

2. Require two people to approve sensitive payments

No individual should be able to receive a payment-change request, update the vendor record, and release the resulting payment without additional review.

Dual control requires one authorized employee to initiate or prepare an ACH transaction and another to review and approve it. The second reviewer should confirm the vendor, amount, bank account, supporting documentation, and completion of the independent verification process.

Nacha, which governs the ACH Network, recommends dual controls because an attacker who deceives one employee may have greater difficulty deceiving two. It also recommends account-validation tools for new or changed payment accounts.

For particularly large or unusual transactions, consider requiring an additional executive approval, a short waiting period after an account change, or confirmation from the organization’s bank.

3. Strengthen email accounts with phishing-resistant MFA

A stolen password should not be enough to access an employee’s email account.

Organizations should require multifactor authentication for email, finance, administrative, remote-access, and other sensitive systems. Where possible, use phishing-resistant authentication methods, such as security keys or passkeys, instead of relying exclusively on text-message codes or approval prompts.

CISA recommends phishing-resistant MFA for email services and other critical accounts because it adds protection even when an attacker obtains a user’s password.

Access policies should also detect unusual logins, such as attempts from unexpected locations, unfamiliar devices, or anonymous networks. Privileged and finance-related accounts deserve the strongest controls.

4. Improve protection against email impersonation

Email filtering should identify suspicious links, attachments, sender patterns, and messages that attempt to impersonate executives or vendors.

Organizations should also properly configure SPF, DKIM, and DMARC for their own domains. A DMARC policy set to reject can make it harder for attackers to send messages that appear to come directly from an organization’s legitimate domain.

However, email authentication is not a complete solution. It may not stop messages sent from a compromised vendor account or a convincing lookalike domain. That is why technical filtering must be paired with independent payment verification and approval controls.

5. Train employees using realistic, role-specific scenarios

Annual security training alone is unlikely to prepare employees for a convincing vendor impersonation scheme.

Organizations should conduct regular phishing simulations and provide immediate remedial training when an employee responds incorrectly. Xantrion’s existing guidance recommends sending periodic simulated suspicious messages to identify employees who need additional security-awareness training.

Training should reflect the risks associated with each employee’s role. Accounts-payable teams need practice handling requests to change banking details. Executives should recognize impersonation and urgent transfer requests. IT staff should know how to investigate suspicious forwarding rules, login alerts, and account changes.

Employees should also learn that phishing messages do not always contain obvious spelling mistakes or unusual formatting. Attackers may study real invoices, projects, executives, vendors, and communication patterns before making their request.

6. Make suspicious activity easy to report

Employees are more likely to report a questionable message when the process is obvious and fast.

Provide an email-reporting button or a clearly publicized security address, and instruct employees to report anything unusual, including messages they have already answered. They should not be punished for raising a false alarm or admitting that they clicked a link.

Rapid reporting can give the security team time to disable a compromised account, revoke active sessions, remove malicious inbox rules, block related messages, and alert other employees before the attack spreads.

The goal is not to create a workforce that never makes mistakes. It is to create one that quickly alerts the right people when something feels wrong.

7. Rehearse the response before money is lost

The City of Pittsburg’s recovery effort shows why speed matters. After the fraudulent payment was identified, city officials contacted law enforcement and froze the receiving account, contributing to the recovery of most of the transferred funds. The investigation ultimately involved 18 search warrants covering 116 accounts.

Every organization should maintain a concise incident response plan that identifies:

  • Who has authority to disable accounts and isolate systems
  • Who contacts the bank, insurer, legal counsel, law enforcement, and IT security provider
  • How logs, emails, account records, and other evidence will be preserved
  • Who determines whether customers, regulators, or other stakeholders must be notified
  • How the organization will document what happened and prevent a recurrence

Xantrion recommends rehearsing incident response procedures like a fire drill, so the response team knows what to do during the critical first hours of an incident.

Organizations that send ACH payments should also establish a named fraud contact at their bank and understand the bank’s procedures for recalling or freezing a suspicious transaction. Nacha’s current guidance calls for risk-based processes covering the detection, prevention, and recovery of potentially fraudulent ACH payments.

What to do if a fraudulent payment has already been sent

Contact your financial institution immediately and request that it attempt to freeze or recall the funds. At the same time, notify your IT security team so it can contain any compromised accounts and determine how the attacker gained access.

Preserve relevant emails, audit logs, login records, payment documentation, and communications with the apparent vendor. Contact appropriate law enforcement agencies and report business email compromise to the FBI’s Internet Crime Complaint Center.

Do not wait for a complete internal investigation before contacting the bank. The likelihood of recovering funds generally decreases as criminals move the money through additional accounts.

Build a system that assumes phishing messages will get through

The lesson from Pittsburg is not simply that employees need to be more careful. Modern phishing and business email compromise attacks can be highly convincing, particularly when criminals have gained access to a real email account or studied an organization’s vendors and payment processes.

Effective prevention assumes that a malicious message may eventually reach the right employee. The organization’s other controls must still stop it from producing a successful outcome.

That means combining secure email configuration, phishing-resistant authentication, continuous monitoring, realistic employee training, independent vendor verification, dual payment approval, and a rehearsed incident response plan.

Xantrion helps growing and mid-market organizations build managed cybersecurity programs that include continuous threat monitoring, employee security-awareness training, security assessments, incident response preparation, and strategic guidance.

Protect your organization before the next convincing request reaches your finance team. Talk with Xantrion about assessing your email security, payment workflows, and incident response readiness.

Ready to learn more? Get the latest Xantrion news and IT tips.

Menu
dialpad