swel
Capital-call wire fraud, and how verified payments end it

Insights·Verified payments

Capital-call wire fraud, and how verified payments end it

The most exploited message in private markets

A capital call is the perfect target. It is large, it is expected, and it arrives with instructions to wire money to an account. When those instructions travel by email, an attacker does not need to break anything. They need one spoofed reply, one changed account number, and the money lands somewhere it should not.

This is business email compromise, and it is not a rare event. It cost reported victims more than three billion dollars in a single year, and private funds sit squarely in its path, because a capital call is exactly the message it was built to imitate.

When wire instructions travel by email, the attacker does not break in. They reply.

Why trust was the only control

For a long time, the controls against this were human. A verbal callback to confirm the account. A small test payment to check the details. A second pair of eyes on the email.

None of these are verification in any structural sense. A callback confirms a phone number, not an account. A test payment confirms that money moved, not that it moved to the right place. They are habits layered on top of a process that was never designed to carry money safely, because it was built for a smaller, slower era when a wire instruction over email was a reasonable thing to trust.

Verified payments: the details never travel loose

Verified payments close the opening by changing where the payment details live.

The payment reference and the collection account are generated with the capital call and delivered inside the notice itself. They do not travel as a separate email for someone to read off and key in. The limited partner's account is verified when they are onboarded, once, rather than reconfirmed by phone every quarter. Every incoming payment is matched to its notice by its reference on arrival. And if a detail ever needs to change, that happens out of band, through the platform, not in a reply to a thread.

There is nothing loose for an attacker to intercept, and nothing to spoof, because the instruction was never an email in the first place.

Over email, today
01Capital callRaised by the GP
02Wire details emailedSent as a separate message
03The openingA reply is spoofed, the account swapped
04Wrong accountThe money lands off-target
With verified payments
01Capital callRaised by the GP
02Sealed in the noticeReference and account ride inside
03Paid by wireThe LP pays from its own bank
04Matched by referenceReconciled on arrival

What "verified" actually means

Four properties, together, are what make a payment verified:

  • Verified at onboarding. The account is confirmed once, when the relationship is established, not re-trusted on every call.
  • Delivered inside the notice. The reference and collection details ride with the call, not as loose email text.
  • Matched by reference. Each payment is reconciled to its notice automatically on receipt.
  • Changed only out of band. Details never change through an email reply.

Remove any one of these and you are back to trusting a message. Together, they mean the message an attacker relies on does not exist.

Removed, not watched for

The difference is worth stating plainly. Fraud training teaches people to notice a spoofed email. Verified payments make sure there is no spoofable email to notice.

That is a structural fix rather than a vigilant one, and it scales the way vigilance never can: it does not get tired at quarter-end, it does not depend on the most junior person on the desk, and it does not weaken as a fund runs more calls across more vehicles. The wire-instruction vector, the specific opening that business email compromise depends on, is closed by construction.

It does not make a fund immune to every kind of fraud. It closes the one that has cost the industry the most.

Read more

Frequently asked questions

A fraud where an attacker intercepts or imitates a capital call's wire instructions, usually over email, so a limited partner's payment is sent to the attacker's account instead of the fund's. It is a form of business email compromise.

The payment reference and collection account ride inside the notice rather than a separate email, the account is verified at onboarding, and every payment is matched to its notice by reference. There is no loose instruction to intercept or spoof.

Yes. The LP pays by bank wire from its own bank, using the details in the notice. Verification is structural; it does not change how the LP pays.

It replaces what they were trying to achieve. A callback confirms a phone number and a test payment confirms money moved; verified payments confirm, structurally, that a payment can only match the right notice and account.