For Construction | Educational Resource

What Every Contractor Should Know About Payment Fraud, Bid Data, and Job Site Technology

Construction moves big money by email across long chains of companies, on deadlines that don’t move. Here’s how the payments actually get diverted, why bid week is attack week, and what well run construction IT looks like, in plain English.

The diverted draw and sub payment, step by step
Why the weakest inbox on the project decides everyone's risk
What owner and GC prequalification packages now ask
A baseline checklist to review with whoever runs your IT

Get the Free Construction Technology Guide

Six plain English pages: how the payments get diverted, the security baseline, the verification procedure, and the questions owners should ask. Instant delivery.
No spam. Unsubscribe anytime. Your information stays private.

Every Draw
is a payment attackers can see coming
The Chain
owner, GC, subs: one weak inbox exposes all
Deadlines
bids, payroll, and lien dates don't wait for IT
Prequal
security questions now gate the good work

The Realities, In Plain English

Construction doesn’t have a HIPAA. It has something more direct: money moving on schedules everyone can see, and a project chain only as strong as its weakest inbox.

Payments Move on a Published Schedule

Draws, pay applications, and sub payments are large, recurring, and coordinated by email between companies. Attackers can read a project schedule as well as anyone, and they know exactly when the money moves and who emails whom about it.

Your Bids Are Worth Stealing

Estimates, unit pricing, and bid strategies are competitive intelligence. A compromised estimator’s mailbox leaks your numbers to whoever wants them, and you’ll never know why you started losing close bids.

The Office Now Includes Every Trailer

Job site tablets, personal phones, trailer WiFi, shared logins on the plan table PC, and subs and temps cycling on and off projects. Every one is part of your attack surface, whether or not it’s part of your plan.

How the Money and the Week Actually Get Lost

Construction incidents follow the project calendar. Four patterns cover most of the damage.

01

The Diverted Payment

An attacker compromises an inbox somewhere in the chain, a sub, a GC’s AP clerk, a PM, and reads until a draw or pay application is due. Then updated banking details arrive, from the right name, on the right thread, at the right moment. The defense is procedural: any banking change verified by phone at a known number before payment, every company, every time.

02

Ransomware on Bid Week

Estimating, project management, scheduling, and accounting stop together, while bid deadlines, payroll Friday, and lien dates keep running. Attackers time it that way. Contractors with tested, isolated backups restore in hours and keep their commitments. The rest negotiate against the calendar.

03

The Compromised PM Mailbox

One project manager’s account without MFA gives attackers every active project: contacts, schedules, change orders, and the credibility to email as your firm. From there they stage the payment fraud above, or quietly forward your bids. Identity protection has to cover the field, not just the office.

04

The Job Site Sprawl

Shared tablets nobody manages, trailer WiFi with the password on a sticky note, and departed subs whose access nobody removed. None of it feels like an IT problem until the day it’s the way in. A secure, simple lane for field devices closes it without slowing the work.

What Well Run Construction IT Looks Like

Whoever manages your firm’s technology, this is the baseline worth reviewing together. Every item maps to a loss pattern above.

MFA From Office to Field

Every account protected, including PMs, supers, and field logins to email and project management platforms, because one unprotected mailbox exposes every project it touches.

A Written Payment Protocol

Banking changes on draws, pay apps, and sub payments verified by phone at a known number before anything moves. Written, trained, and honored on the busy Fridays too.

Impersonation Resistant Email

Advanced phishing protection tuned for vendor and executive impersonation, plus enforced SPF, DKIM, and DMARC so criminals can’t send as your company.

Backups Sized to the Calendar

Daily backups of estimating, project management, and accounting data with one copy ransomware can’t reach, restore tested and timed against bid deadlines and payroll Friday.

Managed Field Devices

Job site tablets and phones enrolled and protected, trailer connectivity secured and separated, and shared logins retired for good.

Offboarding and Monitoring

Subs, temps, and departing staff losing access the day they roll off, and systems watched around the clock, because the fraud lands on Friday afternoon by design.

Common Questions

Attackers compromise or impersonate an email account somewhere in the payment chain, a subcontractor, a GC’s accounts payable, a project manager, then send updated banking details at the right moment: on a draw request, a pay application, or a subcontractor payment. Construction payments are large, recurring, and coordinated by email across many companies, which makes them a favorite target. Verification by phone at a known number before any banking change is the defense.

Construction combines large recurring payments across long chains of companies, hard deadlines around draws, payroll, and lien dates, valuable bid and estimate data, and a workforce spread across job sites on shared devices and trailer WiFi. Attackers only need to compromise the weakest inbox in the project chain, and every project adds more inboxes.

Estimating, project management, scheduling, and accounting stop together. Bids in progress miss their deadlines, payroll processing stalls, draw documentation is unreachable, and lien and notice deadlines keep running regardless. Contractors with tested, isolated backups restore in hours and keep their commitments. Those without them negotiate under the worst possible calendar.

Increasingly, yes. Larger owners and general contractors have learned that project incidents often start inside a partner, so prequalification packages and contracts increasingly include security questions and requirements. Firms that answer confidently prequalify smoothly. Firms that can’t lose scores they never see.

A six page plain English guide covering how construction payments get diverted, the realities from bid data to job site sprawl, a construction security baseline checklist, the payment verification procedure, and the questions owners and executives should ask about their IT.

Start With the Guide. Decide From There.

Download the Construction Technology Guide and review the baseline with whoever runs your IT. If you’d rather have the answers verified for you, a free confidential security assessment for your firm is available too.

Fill the information below to download a PDF with everything you need to know about Penetration Test: