- The FBI's IC3 reporting for 2025 put US losses to cyber-enabled crime at close to $21 billion, with business email compromise among the principal drivers.
- The 2026 AFP Payments Fraud and Control Survey found more than 75% of surveyed US organisations experienced payments fraud in 2025, with wire transfers a leading target.
- Aviation has been directly targeted: a 2025 phishing campaign harvested aviation executives' credentials and used them to alter and resend invoices to customers.
- Data-protection enforcement in the aviation supply chain is active, including a substantial Spanish DPA fine against Amadeus over a traveller-profiling project.
Why charter payments are a target
Charter payments have every characteristic a fraudster looks for. The values are large. The timelines are short, frequently same-day. The parties often have no prior relationship. The payment method is usually a wire transfer, which is fast and difficult to reverse. And the email traffic surrounding a trip contains, in plain text, the identity of every party, the amount and the deadline.
Business email compromise exploits exactly this. The attacker does not need to break a payment system; they need to compromise or convincingly imitate one mailbox in the chain and then send a plausible instruction to change bank details. In a market where operators and brokers routinely exchange new banking details for each deal, that instruction does not look unusual.
The broker sits at the worst point in the chain. Client funds arrive with the broker; operator payments leave from the broker. Both directions can be attacked, and in both directions the broker will be asked to explain the loss.
The numbers behind the threat
The scale is documented. The FBI's Internet Crime Complaint Centre reported that US victims lost close to $21 billion to cyber-enabled crime in its 2025 reporting year, with investment scams, business email compromise, tech-support fraud and data breaches identified as the principal drivers. The full IC3 annual report remains the primary source.
Corporate exposure is close to universal. The Association for Financial Professionals' 2026 Payments Fraud and Control Survey, based on 465 finance professionals and published in April 2026, found that more than 75% of US organisations experienced payments fraud in 2025, with business email compromise attempts rising sharply and wire transfers among the most targeted payment types. Nacha's coverage of the same survey reported that close to three-quarters of surveyed organisations experienced BEC attempts.
The same research noted that adoption of AI-based fraud mitigation is lagging the adoption of AI by attackers. For a small brokerage without a treasury function, that gap is closed by procedure rather than by technology.
Aviation-specific cases
This is not a generic corporate risk borrowed from another sector. In July 2025 a reported campaign targeted aviation executives with fake Microsoft 365 login pages, harvesting credentials and finance-related email, which attackers then used to edit and resend fraudulent invoices to customers and collaborators. That is precisely the charter payment chain.
Client-data exposure has also materialised at the top of the market. NetJets confirmed in April 2025 that an intruder had accessed systems and taken client data before attempting extortion, describing the impact as affecting a small number of owners. In August 2025, Air France and KLM disclosed a breach at a third-party customer-service platform exposing customer personal data — a reminder that a brokerage's data can leak through a supplier it does not control.
Convenience features can enlarge the target. Avinode's April 2026 addition allowing wire instructions to be attached directly to marketplace contracts speeds up settlement and simultaneously places payment detail inside a document that circulates widely. The feature is not the problem; treating the document as inherently trustworthy is.
Controls that actually work
The controls that stop this fraud are unglamorous and cheap. Callback verification on any new or changed bank detail, using a number held before the request arrived, stops the overwhelming majority of attempts. Dual authorisation above a threshold stops most of the remainder. Neither requires software.
Structural controls help too. Holding client funds in a segregated client account, or using a recognised escrow arrangement for large deposits, separates client money from working capital and creates an additional check before release. Escrow does not by itself transfer liability for a fraudulent instruction, so it complements rather than replaces verification.
Technical hygiene closes the initial access route: multi-factor authentication on every mailbox, phishing-resistant where possible; alerting on mailbox forwarding rules, which attackers create to monitor a deal quietly; and domain protections such as SPF, DKIM and DMARC to make impersonation of your own domain harder. Finally, tell clients in writing, at onboarding, that your bank details will never change by email — so that an attempt looks wrong to them before it looks wrong to you.
The data-protection side
Brokers hold passport data, dates of birth, travel patterns, health information for medical flights and payment details. Under GDPR that is a substantial processing operation, and some of it is special-category data requiring a stronger basis than convenience.
Enforcement in the aviation supply chain is live. The Spanish data protection authority fined Amadeus IT Group over an unauthorised traveller-profiling pilot, finding breaches of the lawfulness and transparency provisions of the GDPR; reported figures vary between sources and decisions, so brokers should read the regulator's decision record rather than press summaries. The principle it establishes is directly relevant: travel data collected for one purpose cannot be repurposed for profiling without a proper basis and notice.
The practical programme for a brokerage is modest but must exist. Maintain a record of processing activities. Define retention periods and actually delete — passport scans held indefinitely are a liability with no commercial value. Put data processing agreements in place with every platform, CRM and outsourced service. Keep special-category data such as medical information in a restricted store with named access. And be able to answer a client's subject access request within the statutory period, because sophisticated corporate clients now test this.
Practical checklists
- Callback verification on every new or changed bank detail, using a pre-held number
- Dual authorisation for payments above a defined threshold
- Client funds segregated, or escrow used for large deposits
- Multi-factor authentication on all mailboxes; alerting on new forwarding rules
- SPF, DKIM and DMARC configured on your sending domain
- Onboarding notice to clients that bank details never change by email
- Record of processing activities maintained and current
- Defined retention periods, with deletion actually executed
- Data processing agreements with every platform and outsourced supplier
- Special-category data (medical, security) held with restricted named access
- Documented process for subject access requests and breach notification
Frequently asked questions
- Should I use escrow rather than direct wires for large deposits?
- Escrow or a segregated client account adds a control point and separates client money from working capital, which is worthwhile. It does not by itself shift liability for acting on a fraudulent instruction — verification still does that work.
- What are my GDPR obligations for passenger data?
- You need a lawful basis, transparency at collection, defined retention, appropriate security, processing agreements with suppliers, and the ability to respond to access and deletion requests. Medical and security-related data needs a stronger basis and tighter access control.
- How do I verify a last-minute change of bank details?
- By voice, on a number you already held before the request arrived, with a person you already knew, and never on details supplied in the same message. Record who verified and when.
- If my mailbox is compromised and a client wires funds to a fraudster, am I liable?
- It depends on jurisdiction, contract and the facts, but a broker whose systems were the point of compromise and who had no verification procedure is in a poor position. Crime or cyber cover, and documented controls, are the practical protections.
- • Wire transfers under time pressure are the sector's structural vulnerability.
- • Voice callback on pre-held numbers defeats most BEC attempts.
- • Aviation has been specifically targeted; this is not a borrowed generic risk.
- • Retention discipline turns a data liability into a manageable one.