The finance team of a large residential project received an email from the formwork subcontractor they'd worked with for months: "Please pay this month's progress payment to our new account — there's a lien on our company account; we're using our partner's account until it's resolved." The message was in the subcontractor's genuine writing style; the progress-payment number and amount were exactly right. Financial distress among subcontractors is so ordinary in construction that the explanation struck no one as odd. The payment went to the new account. When the real subcontractor called the site manager two weeks later, the money had long been withdrawn.
Construction offers fertile ground for email attacks: project-based, temporary business relationships; a long subcontractor/supplier chain; regular, high-value progress payments; and scattered communication between site and headquarters. In this article we cover the sector's threat vectors and the path to defense.
1. Why Does the Construction Workflow Produce an Attack Surface?
- Project-based transience: Every project starts email relationships from scratch with dozens of new subcontractors and suppliers. Money starts moving before a "familiar sender" memory can form — the identity-verification reflex is at its weakest.
- The progress-payment rhythm: Monthly progress payments are regular, predictable, and high-value. An ideal target: when, to whom, and roughly how much can be guessed even from the outside.
- Subcontractors' volatile finances: Account changes, liens, and "using a partner's account" genuinely happen often in this sector — perfectly camouflaging fake "account changed" requests.
- Site–headquarters disconnect: Decisions sit at HQ; the work is in the field. Every email chain in between (site manager → project manager → finance) is one more link the attacker can slip into.
2. The Four Threat Vectors We See in the Sector
2.1 Progress-Payment / Payment-Redirection Fraud
The opening scenario — the sector's most expensive vector. The subcontractor's account is compromised, or impersonated via a look-alike domain; when the progress-payment period arrives, a "new account" request is dropped into the genuine conversation. The lien/financial-distress story is so believable in construction that no need for confirmation is felt.
2.2 Fake Guarantees, Fake Bank Letters
In tender and contract processes, guarantee letters, reference letters, and bank confirmations circulate by email. Attackers send "your guarantee letter is attached" emails from fake bank domains — both as document forgery and as a carrier for malicious attachments.
2.3 Tender and Project Document Leakage
Bid files, quantity surveys, and unit-price analyses are tender-losing information when they reach competitors. Their leakage via targeted phishing or account takeover is direct competitive damage — construction's counterpart to design leakage in automotive. (See our automotive article.)
2.4 Account Takeover on Site Accounts
Site teams often reach email from mobile devices, shared computers, and weak networks; MFA discipline is looser than at HQ. A compromised site account allows the attacker to speak "from the inside" with both HQ and subcontractors — internal traffic that gateway protections can't see. Quishing (QR lures) is also effective in this sector due to heavy mobile use in the field; details in our quishing article.
3. Field Note: The "Lien Story" Phenomenon
The most striking pattern we see in Türkiye's construction field: nearly all fake account-change requests arrive with a financial-distress story — a lien, a blockage, a tax-debt restructuring, "we're using our partner's account." These stories fit sector reality so well that they raise no suspicion; on the contrary, payments get accelerated so as not to leave the subcontractor in a bind. A second observation: email relationships close unarchived at project end; when the same subcontractor's "new" address appears on the next project, nobody compares it with the old one.
4. Defense: Three Layers That Fit the Project Rhythm
Process
In progress payments, an account change — whatever the justification, liens included — is not processed without a call-back to the phone number registered in the contract plus a wet-signed or registered-mail written request. This dual-channel rule should be written into the contract and the subcontractor handbook — so "urgency" pressure hits a procedure, not a person.
Technology
Check Point Harmony Email & Collaboration provides the following in construction scenarios:
- Look-alike and newly registered domain detection — flags single-letter subcontractor impersonations.
- Correspondence-pattern learning — contextually catches the bank-change + urgency combination arriving in the progress-payment window.
- Attachment analysis (sandboxing) and click-time URL protection on fake bank/guarantee lures.
- Internal and outbound traffic scanning — sees emails going from a compromised site account to HQ or subcontractors; QR decoding cuts mobile-targeted quishing at the email layer.
People
Sector-specific simulations for finance, procurement, and site management: a fake progress-payment account change (with a lien story), a fake guarantee email, a QR field lure. The one-sentence rule to embed: the trio of "financial-distress story + account change + urgency" must always trigger the procedure.
Frequently Asked Questions
Our subcontractors are small firms; most don't even have IT. How do we secure the chain?
You can't control the subcontractor's security, but you can control your own process: the dual-channel account-change rule protects you even if the other side's account is compromised. On the technology side, behavioral analysis catches the "fake request from a real account" scenario via contextual signals.
We work with dozens of new suppliers on every project — how do we verify them all?
Verify not all of them, but the money movement: account confirmation before the first payment + the dual-channel rule on changes. These two points scale independently of the number of new relationships.
Everyone on site reads email on their phone; we can't change that.
You don't need to — cutting the attack at the email layer before it reaches the phone (QR decoding, URL analysis, behavioral flagging) and adding mobile threat protection to devices with corporate access is enough. Mobile use is a reality; the defense is designed around it.
Can we see what our current protection misses in progress-payment scenarios?
Yes. In a 14-day monitor-mode trial, without touching your existing protection, we report the missed threats — including subcontractor impersonation, look-alike domains, and BEC.
What Should You Do Now?
If your monthly progress payments are managed over email traffic and you've seen at least one "our account has changed" request in the past year, your risk is worth measuring.
- Free Field Audit: Your SPF/DKIM/DMARC report card, look-alike domain risks, and subcontractor-impersonation exposure.
- 14-Day Check Point Trial (monitor mode): Missed threats reported without touching your existing protection.
About this article: The fifth article of our Sector Series. Kinetik Bilişim is the Türkiye partner of Check Point Software Technologies at the Advanced Partner 2026 level, holding Email, Endpoint & Browser, Mobile, and SASE Solution Specialization accreditations. The author, Kemal Özleyen, is a cybersecurity engineer certified as a Check Point Workspace Security Expert. Field scenarios are shared in anonymized form.