AI Phishing in Construction: Supplier Fraud | Konnetix Blog
Back to Blog
Cyber Security

AI Phishing in Construction: Would You Spot a Fake Supplier Email?

A convincing supplier email can put your next payment at risk. As attackers use AI to make their approaches more targeted, construction businesses need consistent protection across the office, the site and the people they work with.

Construction office workspace with a laptop, work phone, building plans and hard hat

Imagine an email arriving from what looks like your usual materials supplier. The invoice looks familiar, the wording is professional, and there is a request to use new bank details. Your accounts team is busy, the site needs the delivery, and everything feels urgent.

But is the request genuine? A convincing message can exploit a rushed decision, especially when the people approving payments are juggling project deadlines, deliveries and subcontractor queries.

What AI Changes, and What It Does Not

Microsoft's 2026 Digital Defense Report, published on 1st October, describes how attackers are incorporating AI into reconnaissance, social engineering and other parts of their attacks. AI can help them tailor their approaches and work at greater speed and scale.

The underlying routes into businesses remain familiar: people, identities, exposed systems and trusted access. This is not a reason to panic about a completely new category of threat. It is a reason to check whether the security fundamentals are being applied consistently.

Good spelling, familiar branding and a believable explanation are not proof that an email is safe. A message might come from a lookalike address or from a genuine supplier account that has been compromised. Checking the sender is useful, but it should not be your only safeguard.

Why This Matters to Construction Businesses

Construction brings together office teams, site managers, suppliers and subcontractors. Information moves between people working in different locations, often through email and mobile devices. Requests worth checking carefully include:

  • A supplier asking you to change their bank details before the next payment
  • An urgent invoice or payment request apparently sent by a director
  • A document-sharing link that asks you to sign in unexpectedly
  • A subcontractor requesting confidential project or employee information

These requests are not automatically fraudulent. The risk is treating a familiar name or an urgent deadline as a substitute for verification. A clear process helps staff make the right decision without having to become cyber security specialists.

1. Verify Payment Changes Before Acting

Confirm new bank details through a trusted contact number you already hold, not a number supplied in the email or on an amended invoice. For significant changes, have a second authorised person approve the update before a payment is released.

Make that process routine, including when the request appears to come from a senior colleague. If money has already been sent and fraud is suspected, contact your bank immediately and involve your IT provider to investigate the related accounts and messages.

2. Protect Accounts with Stronger Sign-In Controls

Use phishing-resistant sign-in methods, such as passkeys or suitable security keys, where your systems support them. Not all multi-factor authentication methods provide the same protection, so it is worth reviewing how people actually sign in rather than simply checking that MFA is switched on.

Keep access appropriate to each person's role, review shared access and remove accounts promptly when staff or contractors leave. Strong sign-in controls reduce account compromise risk, but they do not replace payment checks or prevent someone being persuaded to authorise a fraudulent transaction.

3. Manage Devices in the Office and on Site

Office laptops, site tablets and work phones all need an agreed approach to updates, protection and access to business information. A device used away from the office should not become a gap in your security simply because it is harder to keep track of.

Know which devices can access email, project files and finance systems. Keep supported software up to date, monitor for suspicious activity and have a process for lost or stolen devices. Where personal devices are used, agree how business data will be protected.

4. Give Staff Practical Cyber Awareness Training

Training should reflect the situations your team actually faces: supplier invoices, delivery updates, shared drawings, contract documents and last-minute requests. Staff need to know what to question, how to verify it and who to contact when something feels wrong.

Make reporting easy and avoid blaming someone for raising a concern or admitting a mistake. A quickly reported suspicious message or unexpected sign-in prompt gives your support team a better chance to investigate before the problem spreads.

5. Check That You Can Recover

Backups should be tested, not simply assumed to work. Identify the information your business needs to keep operating, including project documents, finance records and communications, and check how it would be restored if systems became unavailable.

Agree who takes responsibility for the response and how staff will communicate if normal email cannot be trusted. Recovery planning limits disruption, but backups cannot reverse a fraudulent bank transfer or undo information that has already been disclosed.

A Joined-Up Approach to IT and Security

The answer is not another disconnected tool or a longer list of tasks for your accounts team. It is well-managed technology, sensible business processes and someone responsible for the bigger picture.

Complete 365 is Konnetix's fully managed IT, cyber security and business assurance service, with protection built in as standard. It brings support, monitoring, device management, backup and ongoing oversight into one structured service.

For businesses balancing office operations with busy sites, that means a consistent approach to protecting systems and supporting the people who depend on them. Learn more about Complete 365 for construction businesses.

Source: Microsoft's insights from the 2026 Digital Defense Report, published 1st October 2026. The construction examples and practical recommendations above are Konnetix's application of those findings, not construction-specific statistics from the report.

How Confident Are You in Your Construction Business's Security?

If you are unsure how well your accounts, devices and recovery arrangements are protected, speak to Konnetix about a Complete 365 Security Review.

Book a Free Complete 365 Security Review