Thoughts on verifying ACH changes over the phone vs just trusting email?

Jul 09, 2026 Last reply: 1 week ago 6 Replies

I just heard a total horror story about a guy losing over $210k because a hacker got into his email and set up some sneaky rules in Outlook to hide replies in some Conversation History folder. The hacker told his contractors that the ACH info changed, and since it came from his real address, they almost all fell for it. One lady at a different firm actually called him to verify, and that was the only reason he caught it before losing even more. It’s wild how easily $211,000 can just vanish because of a tiny setting in an inbox. Now I'm wondering if relying so much on email for the money side of the concrete business is a mistake. I realy want to keep things simple for my clients, but I'm torn on wheather the convenience is worth the risk of someone intercepting a thread. Do you guys have a strict policy for bank changes, or do you still find email is the most efficient way to get things done? Is a simple phone call really enough to stop this, or are there better ways to handle the security side of things without being a tech expert?


We had a close call last summer when we were pouring a massive 5,000 sq ft slab for a warehouse in Dayton. A supplier claimed our routing numbers were wrong via email. Luckily, my office manager knows never to touch that stuff without a voice on the line. We now have a printed sheet in our onboarding packet that says we will never, under any circumstances, change payment info thru an email thread. If they see a message like that, it’s fake. I still use QuickBooks for the bulk of my invoicing becasue it’s easier than tracking paper, but for the actual ACH setup, I make every new client call my cell. It takes two minutes to verify the last four digits of the account. It might feel like a hassle when you’re busy loading the mixer or checking forms, but losing six figures over an Outlook rule is a nightmare I don't want to live through. People get lazy with security because they want to save time, but a quick phone call is the cheapest insurance policy you can buy.

Phone calls are a good start, but honestly, I don't think they’re enought anymore with how good scammers are getting at spoofing. We do alot of curb and gutter work around the county, and when we're juggling five diferent 4,000 psi pours in a week, my brain is too fried to remember who I'm supposed to call for every invoice update. We stopped sending payment details over email or text entirely about two years ago.

Instead, we moved everythign into a secure portal through Jobber. If a client needs to see where their money is going or change their card on file, they have to log in with their own credentials. On our end, everyone in the office is required to use a physical Yubikey for their email login. Even if a hacker gets the password, they can't get into the inbox to set up those sneaky rules without that physical key plugged into the USB port. It’s a bit of a learning curve for the crew, but it keeps the bank account safe while we're out on the job site.

That is exactly why I moved all my billing over to Jobber. It uses a secure portal for everythign, so my clients aren't even looking at emails for payment instructions. It keeps that ACH info totally seperate from your inbox, wich is the only way to be safe these days. I found it way more reliable than just hoping a client remembers to call me before sending twenty grand. Plus, it organizes my crew's schedule better than any spreadsheet. If you want to stop worrying about your email getting spoofed, Jobber is the way to go for any concrete outfit.

Have you guys ruled out that this wasn't just a simple case of no 2FA on the account? Everyone jumps to these crazy 'hacking' stories, but half the time it’s just someone reusing a password they used for a lunch order. I’m skeptical that switching to a portal like Jobber fixes the core issue if your main email login is still wide open. If they have your email, they can ussually reset the password for those portals anyway, right? I'd look into wether he acutally had multi-factor turned on before blaming the inbox settings themselves.

It's honestly concerning how many in the industry overlook the inherent fragility of the Simple Mail Transfer Protocol itself, wich lacks any native encryption or authentication mechanisms unless one is specifically configuring SPF, DKIM, and DMARC records to ensure the integrity of the sender's identity. In my experiance pouring high-PSI decorative slabs where the margin for error is razor-thin, I apply that same obsessive attention to detail to our financial protocols by utilizing password-protected, encrypted PDF attachments for any sensitive banking credentials, which provides a neccesary layer of security that prevents the kind of opportunistic scraping of account numbers that these Outlook rules are designed to facilitate.

Look, those Outlook rules are nasty, but if you're running a serious crew with a Schwing S 36 X or even just a few Western Star 4700s, you can't be messing with manual ACH. I switched my firm over to a dedicated treasury management service with dual-authorization required for any bank change. One person initiates, I approve on my phone via a hardware token. It’s the same as checking your slump—you don’t just eyeball it and hope for the best when you're pouring a 4,500 psi mix on a bridge deck. You use the tools. If your bank doesn't offer a hard token or a 'Positive Pay' service for ACH, you're using the wrong bank for this industry.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required