The Long Con: How “Pig-Butchering” Scams Now Target Your Finance Team

A patient, calculated form of fraud is making its way into businesses across South Florida and beyond. “Pig-butchering” scams, long aimed at individuals through dating apps and social media, have shifted their sights onto small and midsize businesses. The new targets are your employees, especially the ones who can move money.

The name comes from the Chinese phrase “sha zhu pan,” or “pig-butchering plate.” It describes the method: criminals spend weeks or months “fattening” a victim with trust and connection before the financial “slaughter.” Unlike a quick-strike scam that demands payment now, this one runs on patience, which is exactly what makes it hard to spot until the damage is done. The reassuring part is that the same patience is its weakness, because a few basic payment controls give your team many chances to catch it before any money leaves.

Key Takeaways

  • It’s a slow scam, not a quick one: Attackers may spend three to six months building trust before ever mentioning money.
  • Your finance team is the target: Anyone who can initiate or approve a transfer is a high-value mark, and so are executives with deal authority.
  • The relationship feels real: Scammers research their target and build a genuine-seeming professional or personal bond, which disarms normal skepticism.
  • Your employee is the victim, not the culprit: The goal is to protect and support the person being manipulated, and to make it safe for them to report an approach.
  • Payment controls stop most of it: Dual authorization and callback verification defeat the fraudulent transfer even when the manipulation succeeds.

What Pig-Butchering Is and Why It Works

The scam unfolds in four stages. It starts with contact, often through a professional networking platform, social media, or a text that looks like a wrong number. Then comes the relationship, cultivated patiently until it feels like a genuine connection. Next, the “opportunity” appears, usually a fake cryptocurrency platform or an exclusive investment. Finally, once real money is committed, the criminals restrict access to the funds and vanish.

What sets this apart from ordinary fraud is the timeline. Rather than asking for anything up front, an attacker may spend three to six months building credibility with daily messages, invented personal stories, and fake screenshots showing investment “success.” They build elaborate false identities from stolen photos and detailed backstories, posing as entrepreneurs, investment advisors, or potential partners. Because they research their targets first, referencing shared connections, industry knowledge, and company details pulled from public profiles, the persona feels real. That emotional foundation is the whole point: it quietly bypasses the skepticism that would normally flag a stranger asking about money.

The Financial Impact on Businesses

The losses are severe. Business Email Compromise losses reached $3,046,598,558 across 24,768 complaints in 2025 according to the FBI’s Internet Crime Complaint Center, and researchers are documenting a growing overlap where pig-butchering tactics feed traditional BEC schemes. When a criminal successfully manipulates an employee who has financial authority, the resulting loss can be enough to threaten a small or midsize business.

The most dramatic example is Heartland Tri-State Bank in Kansas, where former CEO Shan Hanes transferred $47 million after falling victim to a pig-butchering scam. He received a 24-year prison sentence, and the bank failed. Security firm Huntress has documented quieter but more relatable cases, where accounting staff at small and midsize businesses were talked into redirecting company wire transfers after weeks of rapport-building. Individual losses there typically run from $177,000 to $200,000, and when the victim was moving company funds rather than personal savings, the business absorbed the entire hit.

Why Attackers Moved From Dating Apps to LinkedIn

Criminals have changed their hunting grounds from dating apps to professional networks like LinkedIn, and they now target specific roles rather than random people. They look for employees who can authorize payments, reach financial systems, or influence big decisions. Before making contact, they study company structures, roles, recent news, and industry terminology so the outreach feels tailored. An accounting manager might get a connection request from a supposed fintech expert, followed by weeks of professional discussion that slowly turns personal before investing ever comes up.

The most concerning twist is the blend with Business Email Compromise. The long relationship phase doubles as reconnaissance, letting the attacker learn payment processes, vendor relationships, and approval workflows. Once trust is in place, they use that knowledge to push a change to payment instructions, an approval for a fraudulent wire, or a transfer to a fake investment platform.

Who They Target and How

Certain roles carry more risk because of their financial authority and system access. Seeing which ones attackers favor, and the lure they use for each, helps you focus your protections.

Target Role Typical Lure What the Attacker Wants
Accounts payable and accounting staff A “vendor” or peer who builds rapport, then reports updated banking details Redirected vendor payments and wire transfers
Controllers and treasury staff An “industry contact” sharing process or investment insights over weeks Approval of large or international transfers
Executives and senior managers An exclusive investment, board seat, or confidential partnership requiring discretion Sign-off on large transactions, sometimes aided by deepfakes

Finance and Accounting Staff

Employees with wire transfer authority are the most valuable targets, because accounts payable specialists, accounting managers, controllers, and treasury staff can initiate or approve significant transactions. Attackers research org charts and approval hierarchies first, identifying who processes vendor payments, who approves new banking relationships, and who handles international wires. The opening usually looks like ordinary business development: a supposed client, consultant, or peer offering to share insights. Over weeks, the conversation drifts from business to personal, and that is where the emotional hook gets set.

Executives and Senior Managers

Leaders face a different version of the same threat. Their authority over large transactions and strategic deals makes them attractive, and the lures are framed as exclusive investments, board positions, or confidential partnerships. Artificial intelligence has raised the stakes here. Criminals now use AI-generated deepfakes to impersonate trusted contacts on video calls, and an executive’s public footprint, from earnings calls to conference talks, gives them plenty of audio and video to build a convincing fake. That turns a text-based con into a multi-sensory one that can defeat even a video check, so “I saw them on the call” is no longer proof of who you were really talking to.

How the Approach Unfolds on LinkedIn

The first contact looks completely normal: a connection request with a polished profile, an appropriate job title, mutual connections, and messages about shared interests or industry trends. Once there is a little rapport, the attacker moves the conversation to WhatsApp, Telegram, or personal email, explaining it away as easier or more discreet. That migration is deliberate, because it pulls the exchange off corporate systems where security tools and normal oversight might otherwise notice. Throughout, the scammer’s evident grasp of your industry and challenges, all gathered from public sources, keeps the relationship feeling valuable rather than suspicious.

What an Approach Looks Like, and How to Make Reporting Safe

The most important thing to understand is that the employee here is the target, not the wrongdoer. These operations are engineered to fool careful, competent people, so the goal is to help your team recognize an approach and to build a culture where flagging one is welcomed, never punished. The warning signs below are patterns to educate people about, not reasons to surveil them.

What the Manipulation Looks Like

A common thread is a new outside contact that develops slowly across several channels, often someone the employee has never met in person, whose conversations gradually turn from networking toward investing, cryptocurrency, or forex. Another is an unsolicited “opportunity” from a supposed partner, investor, or consultant that seems unusually generous and runs mostly through a messaging app rather than a verifiable organization. Legitimate business development tends to follow established channels and real companies, so an exclusive deal that lives entirely in Telegram is worth pausing over.

When you teach these patterns, frame them as “here is how smart people get taken in,” which lowers the shame that keeps victims silent. An employee who understands the playbook is far more likely to raise a hand early, and early is when these situations are still recoverable.

Financial Requests That Should Always Trigger Verification

Some requests warrant an automatic check regardless of who is asking. An urgent wire to an unfamiliar account or a crypto platform is one, especially when it comes with pressure to skip the normal approval steps for reasons of speed or secrecy. A change to an established vendor’s payment details is another, since redirecting a real payment by claiming the vendor “updated their banking information” is a signature move. Any change like that should be confirmed independently through a phone number already on file. And any push for the company itself to invest in an unfamiliar trading platform that an employee heard about through a personal contact deserves a hard look, because real opportunities arrive through established advisors, not social media friendships.

Building a Safe-to-Report Culture

Scammers coach their victims to treat security steps as obstacles and to keep the relationship quiet, so the countermeasure is a workplace where the opposite is true. Make clear that verifying a payment is doing the job right, not failing to trust a colleague, and that reporting an odd contact carries zero blame. When employees know they can say “something about this feels off” without fear, you convert your biggest vulnerability, a manipulated insider, into your best early-warning system.

How to Protect Your Business

Defending against this is less about fancy technology and more about a few disciplined financial habits backed by awareness. The patient nature of the scam works in your favor, because every control adds another moment where the fraud can be caught.

Quick Wins That Stop Most Losses

  • Require dual authorization for wire transfers and significant payments, so one person initiates and a different authorized person approves and releases. No single manipulated employee can complete a fraudulent transfer.
  • Use callback verification for any new payee, changed bank details, or unusual wire, confirming through a phone number already in your records rather than one supplied in the request. This one step defeats most payment redirection.
  • Separate financial duties so that requesting, entering, approving, executing, and reconciling a payment are not all in one person’s hands.

Update Your Awareness Training

Traditional training teaches people to spot a bad link, but this threat unfolds over months across many channels, so the training has to reflect that. Role-specific scenarios help: finance teams practicing vendor impersonation and payment-change scams, managers working through urgency and authority-based pressure, and everyone learning to recognize a slow relationship that eventually turns toward money. Realistic simulations built on plausible situations, rather than obviously fake ones, are far more useful, paired with immediate, supportive coaching when someone misses a sign. Keep the tone educational, since the aim is confidence and early reporting, not fear.

Supporting Technology

Technology plays a supporting role. Email security that flags impersonation attempts, such as lookalike addresses, newly registered domains, and senders with no prior history, catches many first contacts and links to fraudulent platforms. Behavioral monitoring tools can surface unusual patterns, like repeated contact with brand-new external accounts or a fast escalation toward financial topics, that a person might not notice in the moment. And because attackers work hard to pull conversations onto personal apps and devices, reinforcing that sensitive business stays on business systems removes one of their favorite blind spots.

If You Suspect an Incident

Speed is everything if money has already moved. Contact your bank immediately to request a wire recall, hold, or clawback, and ask them to reach the receiving institution directly, since criminals move funds through multiple accounts fast. Activate your incident response plan and bring in finance leadership, IT security, legal counsel, and management, treating it as both a fraud event and a security incident if any accounts or credentials were involved. Preserve everything, including emails, chat logs, payment instructions, screenshots, and bank confirmations, and report the incident to the FBI’s Internet Crime Complaint Center, whose reports aid pattern-matching and sometimes fund recovery. If you carry cyber, crime, or fraud coverage, notify the carrier right away, because time-sensitive notice requirements can affect your ability to claim.

Pig-butchering scams keep evolving, but the fundamentals of defense do not. Patient fraud meets its match in patient process: strong payment controls, informed employees, and a culture where checking and reporting are rewarded rather than second-guessed. If it would help to review how your current financial controls and security posture hold up against this kind of threat, that is a straightforward conversation to have whenever you are ready.