Itwerx is a service-disabled veteran-owned managed IT and cybersecurity provider serving Seattle-area businesses, founded in 2005. What follows is an account of a real incident, told because the control that failed is missing at most companies rather than unusual.
This happened to a client, and it is worth telling as something that actually occurred rather than a hypothetical, because the pattern is common across companies of every size and industry, not a one-off. The client’s name is withheld; the mechanism is the point.
How it played out
The client did business with a small vendor and placed a large order. Given the size of the order, the vendor asked for a deposit before starting the work, which is a reasonable and unremarkable request. The client asked for wire instructions, and the vendor sent them. The accounting team queued the wire, and the executive team approved it, exactly as the process was supposed to work.
The client’s internal controls also required a follow-up call to confirm the vendor had received the funds. That call is where the fraud surfaced: the vendor had no idea what wire the client was talking about, because the vendor had never sent wire instructions at all.
The gap
Every control fired in order: a deposit request that made sense, a confirmation step, an approval step, and a follow-up verification call. And the money still went to a fraudster, because the verification happened after the wire was sent, not before the banking details themselves were trusted. By the time anyone checked, the transfer was already complete.
The actual fix
The control that would have caught this has to sit earlier in the process: any new or changed banking details, for any vendor, verified by a phone call before a wire is initiated, using a number obtained independently of the email thread that supplied the instructions, not a number pulled from the same message. This is not a large company problem or a small company problem. It is a gap in the order of operations, and it exists in accounts payable departments of every size until someone deliberately moves the verification step to before the money moves instead of after.
Itwerx Corp is a service-disabled veteran-owned small business providing IT services across Seattle, Bellevue, Everett and Snohomish County. This is the kind of thing our cybersecurity work deals with – talk to us about yours.

