Active extortion or breach? Call +1 212 457 9797 · Beware impersonation — we e-mail only from @dilendorf.com

Wire is Gone: Recovering Losses After Bank Says No

Wire is Gone: Recovering Losses After Bank Says No

Common wire fraud fact pattern: U.S. company receives an email from a vendor that appears to be ordinary, requesting that it update its bank details before the next payment.

The controller then wires $500,000. Two days later, the vendor calls to ask where the money is.

The company contacts its bank. Bank issues a request to recall the funds.

Within a few hours, it receives a reply that the receiving bank has credited the money and that the account holder has already transferred it out in amounts ranging from $60,000 to $80,000.

There is now nothing left to return.

Business email compromise (“BEC”) is a type of fraud. The FBI’s Internet Crime Complaint Center (IC3) recorded 24,768 BEC complaints and reported losses of $3.05 billion in 2025. This makes it the second-most costly type of cybercrime ([1]).

By the 48-hour mark, when the first account has been emptied, the chances have decreased (although they have not disappeared completely).

Once the bank says that it can’t reverse the transfer, victim company should consider the following protective steps described in this post.

Why the bank can’t simply take the money back

According to Article 4A of the Uniform Commercial Code, once a payment order has been accepted, cancellation is not valid unless the receiving bank agrees to it. There is, however, a narrow exception in the case of unauthorized or mistaken orders ([11]).

Even if deceived, the company agreed to the wire. When the account number and the name do not match, the beneficiary’s bank as a general rule “may rely on the number as the proper identification of the beneficiary” ([12]). And that’s the big problem for the victim company.

A recall is a request (not a default right), and it applies only as long as the money remains in the first account.

However, by the time the victim realizes the fraud, the money is often long gone from that account.

The FBI continues to tell victims to make this request right away, together with “any necessary indemnification documents” ([1]). A request must be made; it is not the final step.

The money is not gone; it has moved

Criminals send the money stolen from victims via “money mules.” These mules get the money from the victims and send the funds to conspirators, many of whom are based overseas ([7]).

According to FBI data, the funds involved in BEC are being sent to over 140 different receiving countries, via intermediary banks in the United Kingdom, Hong Kong, China, Mexico, and the United Arab Emirates.

More and more are going into custodial accounts held by payment processors, peer-to-peer platforms, and crypto exchanges ([2]).

Batches ranging from $60,000 to $80,000 are intended to bypass banks’ AML filters.

Each of those transfers ends up in a different account at another bank, where it can be identified and, depending on the circumstances, frozen.

Step one: complete IC3 complaint

The FBI’s Recovery Asset Team (RAT) operates the Financial Fraud Kill Chain (“FFKC”). The FFKC works with banks, asking them to freeze fraudulent transfers. Dilendorf Law Firm works with retired FBI IC3 agents to facilitate processing of complaints with the IC3 unit.

In 2025, the RAT froze $679 million out of the $1.16 billion that criminals had attempted to steal, achieving a success rate of 58 percent ([1]).

For a company at hour 48, the FBI states that it “will expand the FFKC process beyond the initial recipient bank if information is provided during the FFKC initiation on ‘second hop’ transactions to other domestic or international accounts” ([1]).

FinCEN’s Rapid Response Program handles cases involving wires sent to foreign accounts and has assisted in the recovery of over $1 billion since 2015.

FinCEN says that it is most likely to interdict funds reported to law enforcement within 72 hours; however, it does not claim that recovery is impossible after that time ([3]).

Victims do not contact FinCEN themselves. Instead, they file a complaint with IC3 or the nearest Secret Service field office, providing all account and bank details for both parties along with a summary of the fraud ([3]).

A bare complaint only goes as far as the first account. One that includes all that the bank knows about the onward transfers allows the FBI to pursue the second hop.

Step two: push the banks to use their own tools

FinCEN’s advisory on BEC informs financial institutions that they have a duty to file a suspicious activity report “regardless of whether the scheme or involved transactions were successful.”

Furthermore, the fact that a recovery request has been made does not release them from that obligation ([4]).

Section 314(b) of the USA PATRIOT Act enables banks to share information with one another, benefiting from a liability safe harbor, regarding transactions which may involve fraud proceeds, such as those connected with wire fraud and “money mule” schemes ([5]).

You should ask the company’s bank in writing to activate both of these channels with the receiving bank and with each subsequent bank as it is identified.

Step three: the forfeiture route

Even after the first account has been emptied, the Department of Justice can trace and seize the stolen money and return it.

In a case in Massachusetts, a workers’ union sent $6.4 million via an email that had been spoofed by only one letter.

The government’s complaint states that the money passed “through a series of intermediary bank accounts,” some of it being routed to a cryptocurrency exchange and to banks in Hong Kong, China, Singapore, and Nigeria.

The investigators were still able to trace the funds to seven domestic accounts, seized them, and brought a civil forfeiture action worth about $5.3 million ([8]).

In a case in Florida, $2,462,000 that had been stolen through an email impersonating a vendor was seized, forfeited, and sent “back to the victim” ([9]).

The process involves remission and restoration as set out in 28 C.F.R. Part 9. A person qualifies as a victim if they have suffered a specific pecuniary loss as a direct result of the crime, and the petition must contain “documentary evidence of a specific pecuniary (i.e., monetary) loss and the date the loss occurred” ([6]).

A petitioner could be disqualified if they have recourse to other reasonably available assets or compensation, so the insurance and counterparty issues discussed below should be dealt with carefully ([6]).

Step four: identify every other pocket

Depending on the facts, a victim may have claims or leverage beyond the thief’s accounts:

  • The other party involved. FinCEN recommends that banks record which “compromised or impersonated parties” were involved, note whether auto-forwarding or inbox rules had been set, and indicate whether the authentication compromised was single-factor or multi-factor ([4]). When the vendor’s mailbox has been breached, the question of how to allocate the loss between the two companies is still an open one and will be decided by forensic evidence.
  • The holders of the receiving accounts. The attachment statute in New York allows a court, on an appropriate showing, to attach the property of a defendant who is a nondomiciliary or foreign corporation, or one who “has assigned, disposed of, encumbered or secreted property” with the intent to defraud creditors ([14]). Civil proceedings directed at the identified holders of mule accounts can reach funds that have not been seized criminally.
  • The company’s own bank. Under Article 4A, the risk of an unauthorized payment order is allocated in accordance with the bank’s security procedure ([13]). Where the customer has authorized the wire, the claim is less extensive, but it still needs to be examined.
  • Insurers. Make sure that every policy which could possibly respond to the loss is notified promptly.
  • Taxes. The IRS regards money taken “through fraud or misrepresentation” as stolen, and the loss can be deducted in the year the theft is discovered, but not so long as there is “a claim for reimbursement with a reasonable prospect of recovery” ([15]).

Preserve the evidence

The Secret Service states that “any delays will decrease the likelihood of financial recovery” and advises victims to “maintain records of all potential evidence” ([10]).

Victims should not wipe the devices in question. They must export the full email headers and obtain the mailbox audit logs before the retention periods expire.

How Dilendorf Law Firm helps

Dilendorf Law Firm has arbitrated over 130 cases involving cybercrime and represents victims of business email compromise both in the United States and overseas.

If a bank recall fails, we will work with you on filing the IC3 complaint with the details that the Recovery Asset Team requires.

Through our team of retired IC3 expert witnesses, we contact the FBI and the Secret Service on your behalf, both for U.S. and for non-U.S. companies.

Dilendorf Law Firm also works with retired IC3 law enforcement investigators who can help trace funds and determine which network (the company’s internal systems or the counterparty’s network) was breached.

We apply pressure on the banks through the 314(b) and SAR channels and submit remission and restoration petitions whenever funds are seized.

Contact US

At Dilendorf Law Firm, we represent U.S. and non-U.S. companies whose wires have been diverted through business email compromise, from the first IC3 complaint through tracing, bank negotiations, and forfeiture petitions.

Where appropriate, we may pursue claims against counterparties, account holders, and financial institutions.

You can reach us at +1 212 457 9797 or by email at info@dilendorf.com.

This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.

Frequently asked questions

Frequently asked questions

Should the money be considered lost if the receiving bank says the account is empty?

It does not have to be. When a complaint points out “second hop” transactions to other accounts, the FBI’s Recovery Asset Team will carry forward its freeze requests “beyond the initial recipient bank” ([1]).

For example, in a case from 2024, a BEC wire for $6.4 million was traced via intermediary accounts to seven domestic accounts, and the government asked for the forfeiture of about $5.3 million ([8]). The results depend on how quickly action is taken and on how complete the information provided is.

What prevents my bank from simply cancelling the wire?

The law regards an accepted wire as final. After the beneficiary’s bank has accepted the payment order, cancellation will not take effect unless the receiving bank agrees or a rule of the funds-transfer system permits it, with a limited exception in the case of unauthorized or mistaken orders ([11]).

A bank which pays into the account number stated on a wire can generally rely on that number even if the name does not match ([12]). A recall is a request which the receiving bank may choose to carry out if the funds still exist.

Can you still file with IC3 after 48 hours?

Yes. FinCEN is most likely to recover funds reported within 72 hours, meaning that hour 48 falls within that time frame, and neither FinCEN nor the FBI says that reporting later is pointless ([3]).

The FBI urges victims to file a report “regardless of the amount lost” and to include all details about the transactions ([1]). You should file the report immediately and then add further information as the banks provide details about subsequent transfers.

What information should the complaint include?

When a wire is sent overseas, FinCEN requires the name and account number of the victim, the name and home country of the victim’s bank, a summary of the fraud, the name and account number of the beneficiary, the beneficiary’s bank and country, and the amount, date, and currency of the transfer ([3]).

You should also include any details concerning second-hop accounts that your bank has obtained, so that the FBI can ask for downstream freezes ([1]).

What action can banks take that I myself cannot?

Banks are allowed by law to exchange information with one another regarding proceeds suspected to be the result of fraud, thanks to a legal safe harbor. FinCEN’s Section 314(b) guidance covers wire fraud and “money mule” schemes, and it does not require the bank to have previously identified the specific funds that have been laundered ([5]).

Furthermore, banks are required to file suspicious activity reports in the case of BEC whether or not the wire transaction was successful ([4]). Therefore, you should request in writing that your bank make use of both methods.

How can a victim recover their money after the government has seized it?

By means of remission or restoration as provided in 28 C.F.R. Part 9. The U.S. Attorney’s Office informs known victims, who then submit a petition together with “documentary evidence of a specific pecuniary (i.e., monetary) loss and the date the loss occurred” ([6]).

A victim who has “recourse to other reasonably available assets or compensation” may be deemed ineligible ([6]). In the 2023 Florida BEC case, $2,462,000 was forfeited and paid over to the victim ([9]).

Should I take the people whose accounts were credited with the money to court?

It depends on the specific circumstances. People who act as money mules receive the funds obtained through fraud and pass them on to the offenders, and in some cases they know precisely what they are doing ([7]).

Under New York law, it is possible to attach a defendant’s property if the defendant is not a resident of the state or has disposed of or hidden the property with the intention of defrauding creditors ([14]). Whether it is worthwhile to proceed with a civil action depends on who the account holders are and what is left.

May the company write off the loss?

Yes in general, but the timing is important. The IRS considers money obtained “through fraud or misrepresentation” to be stolen and allows the deduction of theft losses in the year that the theft is discovered ([15]).

If there is “a claim for reimbursement with a reasonable prospect of recovery,” the loss is not recognized until there is reasonable certainty that the reimbursement will not be received ([15]). It is necessary to coordinate the recovery effort with the company’s tax advisers.

At what stage should a lawyer become involved?

As soon as the bank reports that the recall has failed. The company then begins to manage a number of parallel initiatives: the IC3 complaint and second-hop tracing, bank-to-bank information sharing, evidence preservation, possible forfeiture petitions, and any potential claims against a counterparty or account holders.

Dilendorf Law Firm takes charge of all of these actions, including coordination with the FBI and the Secret Service whether the company is based in the U.S. or not, retired law enforcement forensics, and assessment of claims against banks and other parties.

Sources

[1] FBI Internet Crime Complaint Center, 2025 Internet Crime Report, pp. 7–9, 17. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf

[2] FBI IC3, PSA I-091124, “Business Email Compromise: The $55 Billion Scam,” Sept. 11, 2024. https://www.ic3.gov/PSA/2024/PSA240911

[3] FinCEN, Rapid Response Program Fact Sheet, Apr. 15, 2026, pp. 1–2. https://www.fincen.gov/system/files/2026-04/RRPFactSheet.pdf

[4] FinCEN, Advisory FIN-2019-A005, “Updated Advisory on Email Compromise Fraud Schemes,” July 16, 2019, pp. 9–10. https://www.fincen.gov/system/files/advisory/2019-07-16/Updated%20BEC%20Advisory%20FINAL%20508.pdf

[5] FinCEN, Section 314(b) Fact Sheet. https://www.fincen.gov/system/files/shared/314bfactsheet.pdf

[6] U.S. Department of Justice, “Returning Forfeited Assets to Crime Victims,” pp. 2–3, 6. https://www.justice.gov/file/440746/dl

[7] U.S. Department of Justice, Office of Public Affairs, “U.S. Law Enforcement Disrupts Networks Used to Transfer Fraud Proceeds, Taking Over 4,000 Actions,” Feb. 6, 2025. https://www.justice.gov/archives/opa/pr/us-law-enforcement-disrupts-networks-used-transfer-fraud-proceeds-taking-over-4000-actions

[8] U.S. Attorney’s Office, District of Massachusetts, “United States Files Forfeiture Action To Recover Over $5 Million From Business Email Compromise Scheme Targeting Massachusetts Workers Union,” June 5, 2024. https://www.justice.gov/usao-ma/pr/united-states-files-forfeiture-action-recover-over-5-million-business-email-compromise

[9] U.S. Attorney’s Office, Middle District of Florida (published by U.S. Secret Service), “United States Recovers $2.4 Million Obtained In Business Email Compromise,” Oct. 31, 2023. https://www.secretservice.gov/newsroom/releases/2023/10/united-states-recovers-24-million-obtained-business-email-compromise

[10] U.S. Secret Service, “Understanding Business Email Compromise.” https://www.secretservice.gov/investigations/bec

[11] Uniform Commercial Code § 4A-211, Cancellation and Amendment of Payment Order (Cornell LII). https://www.law.cornell.edu/ucc/4A/4A-211

[12] Uniform Commercial Code § 4A-207, Misdescription of Beneficiary (Cornell LII). https://www.law.cornell.edu/ucc/4A/4A-207

[13] Uniform Commercial Code § 4A-202, Authorized and Verified Payment Orders (Cornell LII). https://www.law.cornell.edu/ucc/4A/4A-202

[14] New York Civil Practice Law and Rules § 6201, Grounds for Attachment (New York State Senate). https://www.nysenate.gov/legislation/laws/CVP/6201

[15] Internal Revenue Service, Publication 547 (2025), Casualties, Disasters, and Thefts, pp. 6, 8, 23. https://www.irs.gov/publications/p547

Discuss Your Matter

Confidential consultations by appointment.

Call us now Request consultation