Almost everything written about cyber fraud tells you how to prevent it. That is important, and we write about it constantly. But there is a moment nobody seems to cover, and it is the moment that matters most if it ever happens to you: the money has already left. A fraudulent wire went out. Maybe your business paid a fake invoice, maybe an employee was tricked into sending funds, maybe a criminal got into an account and moved the money themselves. It is gone from your account, and your stomach drops. Now what?
Here is the single most important thing to know, and it is the reason this article exists: you may be able to get that money back, but only if you act immediately. There is a narrow window, measured in hours, where recovery is genuinely possible, and it slams shut fast. This is your hour-by-hour playbook for exactly what to do after the money moves. If you are reading this in a calm moment, save it, because if you ever need it, you will not have time to search. Let us go.
Why the clock is everything
Before the steps, understand the stakes, because they are what should make you move fast rather than freeze. When money is wired to a criminal, it does not sit there waiting. The criminal's whole plan is to pull it out and scatter it, often moving it through other accounts and out of reach, as quickly as possible. Every hour that passes, more of it is gone for good.
The numbers make this vivid. The FBI's Internet Crime Complaint Center runs a unit called the Recovery Asset Team, whose entire job is to help freeze fraudulent wire transfers. Their reported recovery rate is around 66 percent when the fraud is reported within roughly 72 hours, and it drops sharply after that. Read that again: report fast, and the odds are genuinely in your favor. Wait, and they collapse. The practical recovery window is about 24 to 72 hours from when the wire was sent, and the first 24 hours are the most critical part of it. This is not a situation where you file some paperwork next week. It is one where the next few hours decide the outcome.
So the mindset is simple: the moment you suspect a fraudulent wire, drop everything and act. Speed is not just helpful here. It is the whole game.
The playbook: what to do, in order, right now
These first steps should happen within minutes of realizing what happened, and several of them at the same time. If you have people who can help, divide these up and do them in parallel.
Step 1: Call your bank's fraud department immediately and request a recall
This is the first call, and it cannot wait. Contact your bank, specifically the fraud department, not the general line if you can avoid it, tell them a fraudulent wire transfer has been sent, and request a wire recall or reversal. Your bank can attempt to contact the receiving bank to freeze the funds before they are withdrawn. The sooner they start, the better the chance the money is still there to freeze. Be clear, be urgent, and use the words "fraudulent wire transfer" and "recall." Ask them to initiate a SWIFT recall if it was an international wire. Do this first, and do it now.
Step 2: File a complaint with the FBI at IC3.gov, at the same time
Simultaneously, ideally with a second person while you are on the phone with the bank, file a complaint with the FBI's Internet Crime Complaint Center at ic3.gov. This is the step most victims do not know about, and it is critical, because a complaint filed here is what can activate the FBI's Recovery Asset Team and the process they use to freeze fraudulent transfers, working with the banks involved. File it as soon as possible and within that 72-hour window, and include every detail you have: the amount, the date and time, the account numbers, the receiving bank, and how the fraud happened. The bank call and the IC3 filing are a one-two punch that should happen together, not one after the other days apart.
Step 3: Contact the receiving bank
If you can identify the bank that received the funds, contact them as well to report the fraud and request that they freeze the account. Your bank and the FBI process may handle much of this, but a direct report to the receiving institution adds another push to freeze the money before it moves. Every channel that gets the receiving bank to act quickly improves your odds.
Step 4: Report to law enforcement
File a report with your local police, and consider contacting your local FBI field office directly, especially for larger amounts. A police report documents the crime, is often needed for insurance and other follow-up, and adds official weight. Law enforcement also tracks these crimes and may connect yours to a larger case.
Step 5: Lock down and preserve everything
Once the money-recovery steps are in motion, secure the situation so it cannot get worse. If the fraud involved a compromised email or account, that account is still a danger, so change its password from a clean device and turn on multi-factor authentication, and watch for others. Preserve all the evidence, the fraudulent emails, invoices, wire confirmations, and any communications, without deleting anything, because it helps the investigation and any claim. This is where the systems side of the response begins, and our guide on what to do after a cyberattack walks through securing your accounts and systems in detail. This article is about the money; that one is about the systems, and a real incident needs both.
Step 6: Notify your insurer and get professional help
If you have cyber insurance or crime coverage, notify your carrier promptly, as many require quick reporting and some provide response help. For significant losses, professional incident response and legal counsel are worth involving. You do not have to navigate this alone, and the right help early can improve both recovery and everything that follows.
What affects your odds
It helps to understand, calmly, what influences whether you get the money back, so your expectations are realistic. Speed is the biggest factor by far, which is why this whole article hammers it. The amount and destination matter too: the FBI's specific fast-freeze process has criteria around larger transfers and traceable routing, though you should report regardless of the amount, because your bank can still attempt a recall. Domestic transfers reported immediately tend to have better odds than funds already moved overseas and withdrawn. And whether the funds have already been pulled out of the receiving account is often the deciding factor, which, again, comes back to speed.
The honest truth is that recovery is possible but never guaranteed, and some victims do not get their money back. That reality is exactly why the same energy is worth pouring into never being in this position at all.
The lesson underneath the playbook
Here is the sobering, important truth that this whole scenario points to. The best outcome is the one where you never have to run this playbook, because a wire like this depends on a mistake that was preventable. Nearly all of these fraudulent wires trace back to business email compromise and a payment made without verification. The single habit that would have stopped it, verifying any payment or banking change by phone through a known number before sending money, costs nothing and defeats the overwhelming majority of these frauds. Multi-factor authentication on your email keeps the criminals from getting inside to set the scheme up in the first place.
In other words, the same fifteen seconds of verification that feels like a hassle before a wire is what saves you from the frantic, uncertain scramble after one. We go deep on protecting your money in our guide on how to protect your business bank account. If reading this recovery playbook makes you a little anxious, let that anxiety turn into the one prevention habit that makes the playbook unnecessary.
How we think about it
Helping businesses avoid ever needing a recovery playbook, and being ready if they do, is central to how we think at Red Door Shield, through a simple framework we call KIT: Keep, Inspect, Trust. Keep what is valuable secure, with multi-factor authentication on the email accounts these schemes depend on. Inspect what is coming in, with monitoring and email protection that catch the compromise before it becomes a wire. And trust through validation, the verify-before-you-send habit that stops the fraudulent wire from ever leaving. The recovery window is a last resort. Our whole aim is to make sure your money never enters it.
What ready looks like
Picture two versions of the same near-miss. In one, a fraudulent wire goes out, and because you knew exactly what to do, you called your bank's fraud department and filed with the FBI within the hour, and the funds were frozen before the criminal could withdraw them. In the other, the wire never went out at all, because the verify-by-phone rule caught the fake request before a dollar moved. Either way, you were ready, either to recover fast or to prevent entirely, instead of frozen and unsure while the clock ran out.
That is what ready feels like. Not panicking when money is on the line, but knowing the exact steps to reclaim it, and better still, having the habits that keep you from ever needing them.
If a fraudulent wire ever leaves your account, move now: call your bank's fraud department and file at ic3.gov, at the same time, within the hour. And if you would rather never face that moment, the prevention is simple and worth putting in place today. To make sure your business is protected against the frauds that lead to these wires, our free Business Security Assessment is the place to start, and it is a conversation worth having before the money is ever at risk.
Learn about business email compromise, read about contractor payment fraud, or see our guide on deepfake voice scams.
Know Where Your Business Stands
Our free Business Security Assessment gives you a clear, professional picture of your current security posture in less than 10 minutes. No technical knowledge required.
Not sure where your business actually stands?
Take our free Business Security Assessment. In under 10 minutes, you will know exactly where your gaps are and what it would take to close them.
Get My Free Security Assessment

