By LCA Fellow Matthew E. Feinberg of PilieroMazza PLLC
Busy Business, Inc. is a successful commercial company offering products and services to the federal government and the private sector. A hard-working billing or accounting staff member receives a standard-looking email or invoice from a trusted vendor, Reliable Service Corp., asking for payment of an outstanding invoice for $400,000 and stating: “Please note our new bank account information in your system for any current and future wire transfers.” The email includes the Reliable logo and the name of the company representative with whom Busy Business typically deals. At first blush, everything seems to be in line with typical practices. However, the staff member fails to notice that the email came from accounts@RELIABLESERVICEC0RP.COM, instead of accounts@RELIABLESERVICECORP.COM, a minor difference that does not immediately catch the eye. Busy Business wires the money to pay the invoice. A few weeks later, Reliable demands payment of its latest invoice. An investigation ensues, and it is discovered that Busy Business, in wiring the money to the new bank account, was actually paying a cyber thief rather than the trusted business partner. Fraudsters have used this brand of social engineering fraud with great success, and companies must take action to protect themselves from substantial financial losses.
Social engineering fraud is affecting companies of all sizes, both domestic and international, across all industries. Although social engineering fraud has been around for years—consider, for a moment, all of the unsolicited emails you have received from so-called Nigerian princes in your lifetime—in 2026, we continue to see a huge rise in the number of social engineering fraud attacks perpetrated across all business sectors. Even more concerning, the thieves are becoming bolder and more brazen, defrauding unsuspecting companies of hundreds of thousands of dollars or more. By the time the company realizes it is a victim of fraud and contacts the bank, the money is long gone, and there are limited options for recovery.
Some social engineering fraud originates out of a cyber attack (phishing and hacking, for example), where a thief gains unauthorized access to a company’s data or computer system. But a computer hack is not necessary. In this digital age, with so much data available online and with the widespread use of Artificial Intelligence, much of the information needed to engage in social engineering fraud is readily available in the public domain. Press releases, website news items, social media profiles, LinkedIn posts, or other public information can be weaponized easily. A fraudster need only create a domain and email address with a slight variation from the company’s actual domain to facilitate the scheme. Just as the accounts payable clerk for Busy Business did in the above example, many individuals, when processing invoices, may not notice the subtle misspelling in the domain name. They simply change the bank account information and issue payment. The result? Hundreds of thousands of dollars in losses, and limited recourse to recover what was lost. So, what can be done to mitigate the risk?
1. Train Employees to Spot Cyber Attacks and Avoid Vulnerabilities.
In some instances, cyber attacks may seem straightforward and obvious to spot. But it can be easy to overlook the more subtle and nuanced schemes. Most employees now enjoy more flexibility to work remotely on less secure wireless internet accounts and, with the potential distractions of working from home, they may not recognize how vulnerable they are to cyber fraud. Annual cyber training can go a long way to preventing social engineering fraud from affecting the company.
2. Trust, But Verify.
Companies should implement mandatory verification protocols for billing and accounting departments before any changes are made to an existing payee or payments are made. Staff members should verify modifications by telephone or initiate a separate email chain from an existing address book or contacts list to ensure the change in bank account information is accurate and authentic. Attention to detail is critical: double and triple check email addresses, invoices, and payment requests for inaccuracies, inconsistencies, misspellings, and deviations from standard practices. Before issuing payment, verify physical addresses and wiring instructions. The few extra minutes on the phone could save the company from substantial losses.
3. Shift the Risk Through Contract Clauses.
If a company provides products or services as a result of a social engineering scam, who bears the risk for the damages? The answer varies a bit by jurisdiction, but, generally, the company that was in the best position to avoid the loss will be responsible for the damage. This is often a fact-intensive inquiry that can expose litigants to increased attorneys’ fees, costs, and risk. One way to mitigate the potential loss is to include risk-shifting or tailored indemnification language in vendor agreements. Such provisions can help allocate loss in the face of a foreseeable risk.
4. Consider Social Engineering Fraud Insurance.
Although traditional corporate liability insurance generally does not cover damage resulting from social engineering fraud, a number of reputable insurance companies offer social engineering fraud endorsements. Companies should review existing policies to identify coverage options. Coverage limits should be adjusted for the level of the company’s risk. If the company regularly makes payments to vendors in the hundreds of thousands of dollars, a policy that offers only $25,000 in coverage offers little in the way of protection from the company’s actual risk.
Taking these steps now will put companies in a better position to outsmart the fraudsters and avoid the significant losses associated with social engineering fraud.
LCA Fellow Matthew E. Feinberg is an accomplished litigator with over 17 years of experience handling federal and state cases, including civil and appellate litigation, administrative proceedings and appeals, and arbitration. In July 2026, Matt became PilieroMazza’s Managing Partner, joining fellow Managing Partner Nichole Atallah in leading the Firm’s strategic direction and continued growth.
As an experienced senior practitioner in PilieroMazza’s Litigation & Dispute Resolution Group and Chair of the False Claims Act (FCA) and Audits & Investigations teams, Matt has a unique perspective on successful litigation strategies to achieve the best possible outcomes for government contractors and commercial businesses. He is particularly adept at identifying weak spots in an opponent’s case, often leading to successful dismissals or early resolution of disputes, ultimately avoiding an expensive trial.
Matt has significant first-chair trial and appellate experience in a diverse array of areas, including the FCA; government investigations; government and private sector contracts; labor and employment; wage and hour disputes; and business litigation, including business torts, unfair competition, trade secrets, and non-compete and non-solicitation disputes. His practice also extends to shareholder direct and derivative litigation, commercial mergers and acquisitions (M&A) disputes, and appeals.







