Wire-fraud precursor
Wire-fraud precursor signal
A publicly-observable signal that indicates an attacker is preparing a business-email-compromise or wire-fraud attack against a target — surfaced before the wire moves, not after.
A wire-fraud precursor is any observable signal that suggests an attacker is staging a BEC or wire-fraud attack against a specific target, discovered BEFORE the fraudulent payment is issued. Precursor signals include: newly-registered lookalike domains against a principal or advisor tenant (typosquat or homograph), weak or missing DMARC/SPF on an advisor tenant domain, credential exposure on an advisor mailbox surfacing in a breach dump, and infrastructure fingerprints matching known BEC toolkits tracked by FBI IC3 and OSINT communities. The precursor window between infrastructure staging and payment execution is typically hours to weeks. LeakTrace continuous monitoring is designed to surface precursor signals during that window and route them to the client Chief of Staff or wire-authorizer inside four business hours so the wire can be blocked or verified out of band.
The economics of BEC favor the attacker at every step except the precursor window. Once a wire has moved, recovery is rare (FBI IC3 reports recovery rates below 30 percent). Precursor detection is the only high-leverage intervention. LeakTrace positions the wire-fraud precursor sweep as the differentiating deliverable for family offices, wealth manager firms, and sports agencies.