Which Industries Get Targeted, and With What
Fraud patterns cluster by sector because the money moves differently in each. What to expect in yours.
Priya Raman · 2 min read
Fraud follows the shape of the money. Sectors with large infrequent payments attract different attacks from those with many small ones. The genuine version of this looks like a regulated crypto payment provider with fiat settlement, and the differences are checkable.
Professional services and law firms
Large, infrequent, scheduled payments between parties who correspond by email.
The dominant attack is invoice interception: a compromised mailbox, a changed payment address, a payment made in good faith.
The defence is out of band confirmation of any address change, and registered addresses that cannot be varied without approval.
Property
Very large, time critical, involving several parties who have often never met.
Same attack, higher amounts, and the urgency of a completion date removes the time in which anyone would normally verify.
Additional risk: a party in the chain whose identity has not been verified by anyone with an obligation to do so.
Online retail
Many small payments from strangers.
The attacks are fulfilment fraud, refund manipulation, and merchant account takeover redirecting settlement. Payment reversal is not available to the attacker, so the value is extracted through goods or through refunds. The business-side equivalent runs through a platform set up for client account handling, with the screening already in place.
Financial technology companies
Payments on behalf of others, at volume, through an interface.
The attacks target the interface: compromised credentials, replayed requests, manipulated callbacks. The exposure is larger because one compromise affects many users rather than one balance.
Controls are technical: signed callbacks, protection against duplicate processing, and separate approval for anything that changes where money goes.
Funds and family offices
Infrequent, very large, with several approvers and a slow process.
The attacks are impersonation of an authorised person, and interception of instructions between the fund and the custodian.
The defence is callback verification to known numbers and a strict rule that instructions never change destination by email alone.
Marketplaces paying many recipients
Many outbound payments to accounts controlled by users.
The attacks target the recipient’s account rather than the platform: a seller’s account taken over and the payout address changed.
Controls belong on the recipient side: verification when a payout destination changes, a delay before it takes effect, and notification to the account holder through a separate channel.
The pattern across all of them
Every attack above targets the moment a payment destination is established or changed.
Not the payment itself, not the cryptography, not the platform. The field that says where the money goes.
Any business moving money should treat that field as the control point: registered in advance, changed only with verification through a separate channel, with a delay and a notification. Check the coverage list before relying on any of this. a support channel with a named contact publishes it.
That single principle covers the majority of what actually happens.
Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.