Active Incident? 24/7 Response →
Witness

For Individuals, Families, and Attorneys

Wire Fraud Recovery
Forensics, evidence, and recovery coordination.

Wire fraud recovery for individuals, businesses, and attorneys after a fraudulent wire transfer. We document the business email compromise or real estate closing wire fraud chain, preserve evidence, and produce the court-admissible case file required for IC3 Recovery Asset Team, cyber insurance, civil suit, and bank coordination.

You sent a wire. The instructions looked legitimate. The email came from someone you had been corresponding with for weeks, sometimes months. The amount was consistent with what you were expecting to send for a real estate closing, a vendor payment, an attorney trust transfer, or an investment commitment. Then the real recipient called and asked where the money was. Your bank says the funds have already been released downstream and they cannot get them back. The sums involved are typically in the tens or hundreds of thousands of dollars. This is the moment we step in.

Quinnlan Varcoe, Founder and CEO, oversees every wire transfer fraud investigation and reviews every case before findings leave the practice. Jose Santana, Lead Technical Consultant, oversees the practitioner team executing the technical work. Engagements are confidential, NDA-protected, and structured to begin within 24 to 48 hours of the consultation because wire-recall windows are short. Pricing is hourly at $550 per hour with a $5,500 starter retainer; a typical case runs 15 to 30 hours for a total range of $8,250 to $16,500. Optional fixed-fee tracks for well-bounded scope and sliding-scale pricing for individuals who lost retirement or home-purchase funds are available on the first call.

What this is

A forensic wire fraud recovery engagement produces the documented evidentiary record that the FBI Internet Crime Complaint Center Recovery Asset Team, your bank's fraud department, the receiving bank, your cyber and crime insurance carrier, civil counsel, and where applicable, federal prosecutors and plaintiff trial counsel can act on. The investigation traces how the fraudulent wire instructions reached you (mailbox compromise of a counterparty, lookalike-domain spoofing, account-takeover at a title company or real estate brokerage, social-engineering phone follow-up), reconstructs the timeline of unauthorized email access where it occurred, identifies any ongoing criminal access to your accounts or the counterparty's accounts, and produces a written report structured for the specific recovery pathways that apply in your case. We do not chase money through correspondent banking; we produce the case file that the institutions with that authority use to chase it.

This page is for people who have already been hit by wire fraud. If you are researching the criminal statute, the federal sentencing guidelines, or the elements of 18 U.S.C. 1343 for a law-school assignment or a news article, this is not the right page. We are a forensic investigation firm, not a legal-research service, and we will redirect you to the appropriate resources.

Who this is for

How the engagement works

  1. Free confidential consultation by phone or video. NDA-protected. 30 to 60 minutes. Direct conversation with Quinn, the founder and CEO who oversees every engagement. We hear the timeline, identify the recovery pathways still open (SWIFT recall, IC3 RAT freeze, insurance, civil), and tell you whether forensic investigation will materially help or whether you are better served by going straight to your bank and counsel.
  2. Scoped engagement with a written proposal and pricing. $5,500 starter retainer covers intake, evidence preservation, and the first round of email-header and account-access forensics. Hourly with milestone caps for the full investigation; fixed-fee where scope is well-bounded.
  3. Forensic acquisition of relevant artifacts. Email accounts on both sides of the impersonation chain (with consent of the counterparty where applicable), email server logs, mail-rule and forwarding-rule history, mobile devices that received SMS or call confirmations of the fraudulent instructions, banking and brokerage account exports, wire-confirmation pages, and the original closing or contract documentation.
  4. Investigation and reconstruction. Source of compromise, timeline of unauthorized inbox access, lookalike-domain analysis, spoofing-versus-account-takeover determination, identification of any persistent criminal access (mail rules hiding criminal activity from the legitimate user, OAuth tokens granting silent inbox access), and where applicable, payment-rail tracing through correspondent banking to identify off-ramp jurisdictions for law-enforcement seizure pursuit.
  5. Written report to court-admissible standards, structured for the specific pathways that apply in your case: IC3 Recovery Asset Team, FBI Cyber Division referral, cyber insurance claim under Travelers / AIG / Beazley / Coalition / Resilience policy forms, UCC Article 4A claim against the receiving bank, civil action against negligent counterparties, and where applicable, plaintiff trial counsel for wire-fraud civil litigation.
  6. Coordination with bank fraud teams (originating and receiving), the IC3 Recovery Asset Team, FBI Cyber Division, USPIS, your insurance carrier, civil counsel, and where applicable, federal prosecutors. We do not replace these institutions; we produce the case file that makes their work materially more tractable.

What we will not do

Real estate closing wire fraud is the highest-volume vector

The FBI IC3 2023 report logged over $446 million in real estate wire fraud losses across more than 9,500 victims, with losses concentrated in markets where home prices and closing-wire amounts are highest. Florida, California, Texas, New York, and the Northeast corridor account for a disproportionate share of total losses; Naples, Marco Island, and the broader SW Florida high-end retiree market sit inside one of the most concentrated targeting zones in the country. The forensic methodology for real estate wire fraud is consistent across cases (where did the email compromise originate, how were the fraudulent instructions inserted, what banking persistence remains), and a Florida-based forensic investigator who lives in the targeting environment, knows the FL state and federal pathways, and works alongside Florida real estate counsel produces materially better case outcomes than a remote firm chasing a one-off engagement.

Related Witness services

How We Work

A confidential, structured engagement.

01

Confidential Consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process.

02

Scoped Engagement

A clear written proposal with defined deliverables, timeline, and pricing. No hidden costs.

03

Investigation and Findings

Forensic work conducted to court-admissible standards, with regular communication and a written summary you can act on.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded Witness in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

Certified Expertise

GIAC · AWS · Splunk · CompTIA

Frequently asked about wire fraud recovery

Quinnlan Varcoe, Founder & CEO

Schedule Your Session

Schedule a confidential consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process. Most engagements begin within 48 hours.

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management