Getting paid · 8 min read
Invoice fraud: spotting fake invoices and payment redirection
The most effective invoice fraud does not look like fraud. It looks like a routine email from a supplier you already work with, about an invoice you were already expecting to pay.
Invoice fraud works because it targets a process rather than a person's judgement. Paying suppliers is routine, it happens under time pressure, and everyone involved is trying to be efficient. A fraudulent request that fits the routine gets processed by the routine.
This matters whichever side of the invoice you are on. If you send invoices, someone impersonating you can cost your client money and your relationship. If you pay them, a single redirected payment can be significant and is often unrecoverable.
Worked example
Worked example: the change that did not happen
A design agency has invoiced the same manufacturing client monthly for two years. In September the client's accounts team receives an email from what appears to be the agency's account manager: a friendly note saying the agency has switched banks, with updated details, asking that the September invoice be paid to the new account.
- Point 1
- The email signature is correct. The tone is right. The invoice attached is a genuine one.
- Point 2
- The client's process stops it at one step. Their supplier record holds verified bank details, and any change requires voice confirmation on the number already on file. The accounts clerk calls the agency's main line — not the number in the signature — and the account manager confirms no change has been made. The sending domain turns out to differ from the real one by a single character.
- Point 3
- Nothing clever caught this. One rule, applied without exception, did.
Original diagram
Invoice fraud: spotting fake invoices and payment redirection decision flow
- 1The main patterns
- 2Controls that actually prevent it
- 3Protecting your clients from someone impersonating you
- 4If a payment has already gone
The main patterns
Payment redirection:
The most damaging and most common. A fraudster, having gained access to or convincingly imitated a supplier's email, notifies the buyer that bank details have changed. The next invoice is paid to the fraudster's account. The buyer has no reason to doubt it: the invoice is real, the amount is right, the sender looks correct.
The tell is almost always in the detail rather than the content — a domain with a transposed or substituted character, a reply-to address that differs from the display name, or a change notification arriving separately from any invoice.
Fake supplier invoices:
An invoice arrives from a business you have never used, for something plausible and modest — a directory listing, software renewal, office supplies, a domain service. The amount is deliberately small enough to clear without scrutiny. These are sent in volume on the assumption that a small percentage will be paid without checking.
Altered legitimate invoices:
A genuine invoice is intercepted in transit and modified, usually only in the payment details, before being forwarded on. Everything else is authentic, because it is authentic.
Urgent payment requests:
A message appearing to come from a senior person instructs someone to make an urgent payment outside the normal process, often framed as confidential. The urgency and the authority exist specifically to prevent the usual checks being applied.
Controls that actually prevent it
These are deliberately simple, because complex controls get bypassed under pressure.
- Verify every change of bank details by voice, using a number you already held before the request arrived. Never a number from the email or the invoice.
- Apply a two-person rule above a threshold you set. One person prepares, a different person releases.
- Match invoices to something you approved. A purchase order, a signed quote, a contract. An invoice that matches nothing should never be paid on the strength of looking plausible.
- Keep a supplier record with verified bank details and treat any deviation as a stop, not a note.
- Make a small test payment after any verified change, and confirm receipt before releasing the balance.
- Use account name checking where your banking system offers it, and take a mismatch seriously rather than overriding it.
- Remove urgency as an override. The process should be that nothing bypasses the process. Say so explicitly, so a junior employee is not deciding alone.
Protecting your clients from someone impersonating you
If you send invoices, your email account and your invoice template are both attack surfaces. Several habits reduce the risk substantially:
- Tell clients at onboarding that your bank details will never change by email. State it in your terms and repeat it in the footer of your invoices.
- Keep your payment details visually consistent on every invoice, in the same position and format, so a substitution looks wrong immediately.
- Secure your email with strong multi-factor authentication. Most supplier impersonation starts with a compromised mailbox or a domain that closely resembles yours.
- Consider registering obvious lookalike domains if your business name is easy to imitate.
- Send invoices from a consistent address so clients have a stable expectation.
- Respond quickly if a client queries an invoice they did not expect. That query is often the first sign that someone is imitating you.
If a payment has already gone
Speed matters more than anything else, because funds are typically moved onward quickly.
Afterwards, review what the control gap was rather than who made the mistake. These frauds are designed to be missed by careful people working quickly, and a process fix protects you far better than increased vigilance ever will.
- Contact your bank's fraud team immediately and ask them to attempt a recall.
- Tell the genuine supplier or client, so they can warn others being targeted at the same time.
- Report it to the appropriate authority in your country — the route differs by jurisdiction, so check the correct one.
- Preserve everything. Original emails with full headers, attachments, and a timeline. Do not delete anything.
- Check for continuing access. If a mailbox was compromised, change credentials and review forwarding rules, which are frequently left behind.
Common questions
Helpful clarifications
What is a payment redirection scam?
A fraudster impersonates a supplier and tells the buyer that bank details have changed, so the next payment goes to an account they control. The message often arrives as a convincing email from a lookalike address, sometimes referencing a real invoice. Because the buyer believes they are paying a legitimate debt, the payment is authorised normally and can be very hard to recover.
How can I tell if an invoice I received is genuine?
Check it against something you already hold rather than against the message that delivered it. Does it match a purchase order or an agreement you have on file? Do the bank details match the ones used for previous payments to that supplier? Is the sender's email domain exactly right, character for character? If anything differs, verify by phoning a number you already had, never a number printed on the invoice itself.
A supplier emailed to say their bank details changed. What should I do?
Treat it as unverified until you have confirmed it by voice with a known contact on a number you already held. Do not reply to the email or call a number it supplies, because both may be controlled by the fraudster. Make a small test payment first where practical, and confirm receipt before releasing anything larger. Legitimate suppliers expect this and will not be offended.
How do I protect my own clients from someone impersonating me?
Tell clients at onboarding that your bank details will never change by email, and that any such message should be verified by phone. Keep your details visually consistent on every invoice so a change stands out. Secure your email account with strong multi-factor authentication, since most supplier impersonation begins with a compromised or closely-spoofed mailbox.
What should I do if a payment has already gone to a fraudulent account?
Act immediately, because recovery chances fall sharply within hours. Contact your bank's fraud team and ask them to attempt a recall, notify the genuine supplier or client so they can warn others, and report it to the relevant authority in your country. Preserve the original emails and files rather than deleting them, since they are evidence. Reporting routes differ by jurisdiction, so check the correct one locally.