
Invoice Phishing, CEO Impersonation, and Why Spring Hiring Season Puts Your Office and Field Teams at Risk
Spring is the busiest hiring season in construction. General contractors are staffing up for the building season, project managers are joining mid-project, and office teams are onboarding alongside new field crews. This surge in new hires is great for project capacity — and genuinely dangerous from a cybersecurity standpoint. Research from Keepnet (2025) found that new employees are 44% more susceptible to phishing attacks than their experienced colleagues, and that CEO impersonation attacks are 45% more effective on new hires. In the construction industry, where phishing emails routinely disguise themselves as subcontractor invoices and payment change requests, a new employee who does not yet know what legitimate communications look like is exactly the target attackers are looking for.
Why New Construction Employees Are Prime Phishing Targets
A new project manager joining your team is absorbing an enormous amount of information simultaneously: learning Procore, understanding your subcontractor relationships, getting access to Sage 300 CRE for billing, figuring out who approves what, and trying to demonstrate competence quickly. That cognitive overload creates the exact conditions phishing attacks exploit — a person who is uncertain about normal procedures, eager to be responsive, and unlikely to question an urgent-seeming request from someone who appears to be in authority.
The chaotic reality of a new employee's first weeks in construction compounds the risk. Job sites are busy. Office teams are dealing with competing priorities. Nobody has time to walk a new hire through every communication protocol in detail. A phishing email that arrives during that window does not look like an obvious threat — it looks like one more unfamiliar request that needs to be handled quickly.
In construction specifically, new employees in accounts payable, project coordination, and field superintendent roles face the highest phishing risk because they handle exactly what attackers want: payment processing, subcontractor communications, and access to project management platforms. A new AP clerk who processes a fraudulent subcontractor invoice because it looks like every other invoice they have seen this week has given attackers what they came for.
How Attackers Impersonate GCs, Owners, and Subcontractors
Construction phishing attacks take several forms, all of them targeted at the industry's specific workflows. Invoice fraud — emails that appear to come from a subcontractor or supplier with updated payment instructions — is the most common. The email looks like a routine accounts payable communication. The only difference is that the bank account information has been changed to route payment to the attacker.
CEO and GC impersonation attacks target new employees specifically because new staff have not yet established a personal relationship with company leadership. An email appearing to come from your CEO or project executive asking a new coordinator to process an urgent payment or share access credentials for a project file in Procore is far more effective on someone who has never sat across the table from that executive.
Attackers also impersonate owners, architects, and even government permitting agencies — all parties that construction companies routinely communicate with and treat with urgency. A spoofed email appearing to come from a project owner requesting access to Autodesk Construction Cloud project files or asking for updated bid documents is a targeted attack on the specific trust relationships that construction projects depend on.
Fix #1: Configure Access Before the First Day
New employees should arrive on their first day with their platform access already properly configured — Procore permissions set to their relevant projects, Sage 300 CRE access scoped to their role, and clear documentation of what they have access to and why. When new staff have to navigate system access on their own, they become vulnerable to social engineering from people who offer to help them get set up.
Role-based access controls are the right approach: a new project coordinator does not need access to your company's complete financial history in Sage 300 CRE. A new field superintendent does not need administrative rights in Procore. A new AP clerk does not need access to HR records. Scoping access to role requirements at the start limits the damage any single phished account can cause.
Fix #2: Define What Legitimate Payment Requests Look Like
The most effective thing a construction company can do to stop invoice fraud and payment redirect attacks is to establish a clear, firm policy on how payment changes are verified. Define it explicitly: no changes to subcontractor or supplier bank account information are processed without a phone verification call to a known contact at that company. No email-only payment change requests are honored, regardless of how official they appear.
This policy needs to be communicated to every new hire before they process their first invoice. It is not enough to tell them generally to be careful about phishing — you need to give them specific, actionable rules that protect your company's most vulnerable processes. In construction, where payment volumes are large and timelines are tight, a fraudulent wire transfer can mean real financial harm before anyone realizes what happened.
Fix #3: Give New Employees a Security Point of Contact
New employees who are uncertain about a communication need a fast, accessible way to verify it before they act. Designate a specific person as the security point of contact for your office and field teams — someone new hires know they can reach with a quick call or text when something feels off. Make this introduction on day one, before new employees process their first request.
Without a clear escalation path, new employees default to their own judgment under social pressure. They do not want to look incompetent by questioning a request that might be legitimate. A designated contact removes that barrier and creates a culture where verification is the norm, not the exception.
The Subcontractor Invoice Fraud Problem
Business email compromise (BEC) attacks that impersonate subcontractors are among the costliest cybersecurity incidents in the construction industry. Attackers compromise a subcontractor's email account, monitor payment communications, and then intervene at exactly the right moment — typically just before a large payment is due — to redirect the funds to an attacker-controlled account.
The fraud is particularly effective because the email comes from a legitimate account (the subcontractor's actual email, compromised by attackers) with a plausible explanation (new banking information, updated ACH details). New AP staff who have not yet built personal relationships with subcontractor contacts are the most likely to process these requests without additional verification.
What Your Construction Company Should Do This Spring
- Add a phishing and invoice fraud awareness module to every new hire's onboarding
- Establish and document a payment change verification policy — phone verification required, no exceptions
- Configure role-based access in Procore, Sage 300 CRE, and other platforms before new hires' first day
- Designate a security point of contact and introduce them to every new hire
- Run a simulated phishing test for new employees within their first 30 days
- Brief your office and field teams specifically on subcontractor invoice fraud and payment redirect attacks
Qual IT works with Salt Lake City construction companies to keep office and field systems running securely. Schedule a free discovery call to learn how we can protect your new hires and your payment processes.
Frequently Asked Questions
Q: How do we protect against invoice fraud when we work with dozens of subcontractors?
The core protection is a mandatory phone verification policy for any payment change request — no exceptions. Before updating bank account information for any subcontractor or supplier, your AP team calls a known phone number for that company (from your existing records, not from the email requesting the change) to confirm the request is legitimate. This single step stops the vast majority of BEC-based invoice fraud attacks. Qual IT can also help you configure email filtering rules that flag unusual payment request patterns and flag newly registered sender domains impersonating known subcontractors.
Q: Our field teams are on their phones constantly — how do we manage phishing risk for them?
Mobile phishing is a growing risk in construction because field teams receive legitimate communications from owners, architects, and GCs via text and email on personal phones. The best protections for field teams are: security awareness training that specifically covers mobile phishing (smishing via text message is increasingly common), a policy that no payment or credential changes are processed via mobile without office confirmation, and mobile device management (MDM) that can remotely wipe a device if a field team member's phone is lost or compromised. Qual IT provides MDM solutions scaled for construction field operations.
Q: What should a new hire do if they receive a suspicious email?
They should not click anything in the email, and they should contact your designated security point of contact immediately. If they have already clicked a link, they should report it immediately — without embarrassment. The faster a potential compromise is reported, the faster it can be contained. Firms with a strong security culture make it easy and non-judgmental to report potential incidents. Training your new hires to report first and ask questions later — rather than hoping the click was harmless — is the difference between a contained incident and a full breach.

