
Insights·Fraud and verification
Capital call fraud, how it works and how funds prevent it
Capital call fraud works by arriving when a real capital call is expected. Someone who has compromised emails between a fund and its investors sends a drawdown notice with its own payment instructions, timed against a commitment that genuinely exists, and the investor pays because the request is not a surprise.
So how do you prevent it? By confirming the payment details through a channel the notice did not arrive on.
The best-documented case of capital call fraud shows something the usual advice does not: the compromise sat at the investee rather than at the investor who paid. This means the party whose systems failed was not the party that lost the money.
What does a fraudulent capital call look like?
It looks like the one the investor was already waiting for.
In July 2025, Ireland's National Treasury Management Agency (NTMA) paid EUR 5m against a fraudulent capital call. The commitment behind it was real. The Ireland Strategic Investment Fund had invested in the vehicle; that investee had already made a first capital call, and a second was expected. The fraudulent request was built around that relationship and arrived at the point in the cycle where a genuine one would have. NTMA paid on 7 July 2025 and identified the problem the following day. Its 2025 financial statements recognise a EUR 2.5m net loss after recoveries, meaning EUR 2.5m was recovered. NTMA said there was no evidence of any breach of its systems.
Frank O'Connor, chief executive of the NTMA, told an Oireachtas committee on 22 July 2025 that the request was "designed and timed to pass as a legitimate and expected request for funds".
This sentence outlines the whole mechanism. This was a sovereign wealth fund with institutional controls, paying against a commitment it had made, on a schedule it was expecting. The compromise sat at the investee rather than at NTMA, which means NTMA's own perimeter was never the thing that failed. Deloitte conducted an independent investigation, and the agency said it implemented the recommendations, though that report is not public.
Two things about the figures. EUR 5m left, EUR 2.5m came back, and EUR 2.5m is what the accounts carry as the loss; those describe one event at three points in time rather than competing estimates of its size. And NTMA was the investor paying in, not an outsourced administrator, so its controls are not the controls a fund administrator runs.
Who else has this happened to?
Fewer named parties than the volume of warnings would suggest.
The Massachusetts Public Employee Retirement Administration Commission issued Memorandum 12 of 2025 on 27 March 2025, recording recent investment fraud attempts against public retirement boards. In one, an email was sent to a board administrator "imitating a capital call originating from their investment consultant". The regulator named the tell: the sender mimicked the name of a legitimate investment consultant employee but used an email extension the consultant does not use. It also stated the structural rule plainly, that "a capital call would only come from the fund manager, it will never come from the investment consultant". Separately an investment manager had detected two instances of fraudulent capital calls by someone impersonating one of its own employees. All three attempts were detected and prevented, and no dollar amounts were disclosed.
Three attempts at unstated dates is an incident notice rather than a prevalence study, and it should not be turned into a rate. What makes it useful is that a government body wrote down the pattern, rather than a vendor describing it in the abstract.
Beyond those, the public record thins out fast, and the reason is the next section.
Why is there so little enforcement record for this?
Because there is none, at least in the United States, and this is a finding rather than a gap in our reading.
Swelv searched the enforcement and prosecution records of the Commodity Futures Trading Commission, the Securities and Exchange Commission, the Department of Justice, and the Financial Industry Regulatory Authority for a public action arising from inbound capital call fraud against a private fund or its service providers. None was found. Every documented payment fraud case Swelv could locate against a fund or a provider runs the other way, on money leaving rather than money coming in.
A second search reached the same wall from a different direction. Swelv read the published guidance, warnings and thematic work of seven authorities on 10 September 2026, covering the Financial Conduct Authority, the Commission de Surveillance du Secteur Financier, the Central Bank of Ireland, the Jersey Financial Services Commission, the Guernsey Financial Services Commission, the European Banking Authority and the European Securities and Markets Authority. Not one of the documents read names capital call fraud, drawdown notice fraud, LP bank detail compromise, or distribution redirection.
Read those carefully, because they are easy to overstate. Absence of enforcement is not absence of loss. It is consistent with losses being settled privately, absorbed as operational cost, or never reaching a threshold that triggers a public action. What it does establish is that a manager looking for an official account of how this fraud works, who bears it, and what stopped it will not find one, and that any figure circulating about its frequency is not coming from a regulator.
The general fraud statistics are no help at this level of detail either. The FBI's Internet Crime Complaint Center recorded 24,768 business email compromise complaints and $3,046,598,558 in losses in 2025. That is the category capital call fraud sits inside, and IC3 does not break out fund payments. Its Recovery Asset Team froze 58% of the value it actioned in 2025, down from 82% in 2020 as case volume tripled, which is the more useful number here because it says what happens after the money leaves.
Where does the money actually go wrong?
Not where the warnings point.
Swelv's position is that the capital call notice, rather than the banking rail, is the entry point for wire fraud in private markets. The reasonable objection is that limited partner portals have already secured notice distribution, so the notice is no longer the weak point. The answer is that a portal secures delivery of a document. It does not verify the payee inside it, and a compromised notice delivered through a secure portal is still a compromised notice.
The NTMA case sharpens that. The compromise was at the investee. The notice was genuine in form, correct in timing, and consistent with a real commitment. Nothing about the delivery mechanism was the failure. What failed was that the payment details inside a plausible document were trusted because the document was plausible.
Which points to the practical difficulty. Capital call fraud is the version of this everyone talks about, and the version with no enforcement record and no regulatory definition. The losses that reach an enforcement file or a court record run outbound, on distributions and vendor payments, where no investor is making a payment decision because the payment is scheduled work at the administrator. NTMA is the counterexample, and it is an inbound loss, which is part of why it is worth this much attention: it is documented, and its category is almost empty. A control programme built from the volume of warnings rather than from the evidence will be aimed at the flow with the most notice, the most standardisation and the most attentive counterparty.
What actually prevents it?
Verification through a channel the notice did not arrive on, applied to the calls a stranger could predict.
The mechanism gives the specification. A fraudulent call succeeds by being expected, so the control cannot be based on whether a request looks reasonable. It has to be based on confirming payment details with a party that a compromised mailbox does not control, using contact details held before the notice arrived rather than any supplied within it.
That leaves a question of scope, because verifying everything is not free. The calls worth verifying are the ones an outsider could anticipate. A fund with a published drawdown schedule, a commitment disclosed in an annual report, a first call already made with a second implied, or a subsequent close due, is legible from the outside. So is any call arriving near a date a genuine one was expected. ILPA's Capital Call and Distribution Notice Best Practices treats ten business days as the standard notice period, and records that limited partners it consulted regarded a call above 20 to 25% of unfunded commitment as warranting more warning than that. That window is what a fraudulent call has to fit inside. That threshold is a reasonable second filter, because a call large enough to deserve extra notice is large enough to deserve a phone call.
Three things follow for whoever signs off the payment, which at an institutional limited partner is usually the head of investment operations and at an administrator the head of payment operations. List the capital calls expected in the next quarter and mark the ones whose timing or amount would be predictable to somebody outside the relationship. For those, confirm the payment details against contact details held on file before the notice arrived, and record who confirmed them and when. Treat a change of payment details on an existing relationship as a separate event from the call itself. In the NTMA case the relationship was genuine and only the destination was not; in the Massachusetts attempts the impersonated party was one that never issues capital calls at all. Those are different attacks and a control aimed only at the first will not see the second.
The last one matters most for the same reason the NTMA case does. The commitment was real, the timing was right, and the counterparty existed. Everything about the request was true except where the money went.
Read more

Fraud and verification
How fund administrators verify LP bank account details
Four methods are in use. Three prove something narrower than the question being asked, and all four run at the payment, when the exposure was created at the record change.

Verified payments
Capital-call wire fraud, and how verified payments end it
The most exploited opening in private markets is a wire instruction sent over email. Verified payments close it by design.
Frequently asked questions
Someone who has compromised emails between a fund and its investors sends a drawdown notice with its own payment instructions, timed against a commitment that genuinely exists. The investor pays because the request is expected, not a surprise.
By confirming the payment details through a channel the notice did not arrive on, using contact details held before the notice arrived, and prioritising the calls whose timing or amount an outsider could predict.
Swelv found no public US enforcement or prosecution action for inbound capital call fraud across CFTC, SEC, DOJ and FINRA records. That is not evidence the fraud is rare: losses may be settled privately or absorbed as operational cost.
A portal secures delivery of a document. It does not verify the payee inside it, and a compromised notice delivered through a secure portal is still a compromised notice.