Knowledge base · Due diligence guides · All countries

Invoice fraud: how it works and how to stop it

Almost every invoice fraud is the same single move: a payment you intended to make anyway, diverted to the wrong account. That is what makes it both devastating and stoppable: the attack only works if a routine-looking request goes unverified.

If you have a suspicious request in front of you right now, skip to the verification steps; the rest of the guide explains the patterns so the next one never gets that far.

How invoice fraud works

Four variants of one idea:

  • Bank-detail change fraud. An email, apparently from a real supplier mid-relationship, advises new payment details. The invoice is genuine; the account is not.
  • Supplier impersonation. The approach comes from a lookalike domain or a compromised mailbox, often timed to a real expected payment.
  • Clone companies. A fake entity borrows a real company's registered identity so casual checks pass.
  • Fake suppliers. Invoices for goods or services never supplied, relying on weak approval processes.

The common thread is that nothing looks unusual: the fraud is designed to ride an existing payment habit.

The moment of maximum risk: a change of bank details

Treat every change of payment details as a fraud attempt until verified, however plausible. Verify by a known channel: call a number you already hold (not one in the email or on the new invoice) and confirm with a person you know. Check the account name matches the registered company exactly; a personal name, a different company, or a "payment agent" is the answer.

Where possible, make a small first payment and confirm receipt before releasing the balance. Never let urgency prevent you from exercising caution: creating a time pressure is a scamming method.

Controls that stop it

Five habits, in order of value:

  1. Independent verification of any detail change: the known-channel call, every time.
  2. Account-name matching on every new payee; our supplier vetting guide covers this control.
  3. Dual approval for payee changes, so that no single person under pressure can approve a change alone.
  4. Verification of new suppliers before the first payment; see our guide to checking a company is legitimate.
  5. A standing rule that bank details are never accepted or changed by email alone, published to suppliers so the genuine ones expect the call.

The cross-border problem

These controls strain when the supplier is overseas: the known channel may not exist yet, the registered name is in another language and the account sits with an unfamiliar bank. That is verification work an in-country report does properly: confirming the company, its standing and its details from official local sources, before the first payment establishes the "habit" a fraudster can later exploit.

Common questions

What is invoice fraud?

Payment diverted by false or altered payment instructions, usually via a changed bank detail or impersonated supplier. The invoice itself is often genuine; the destination account is not.

Can the bank recover the money?

Sometimes, if alerted within hours. Recovery becomes unlikely once funds are moved on, so contact your bank immediately and treat speed as everything.

Doesn't my bank check the account name automatically?

In the UK, Confirmation of Payee checks names on domestic transfers. Internationally there is no universal equivalent, so cross-border payments rely on your own checks.

How do fraudsters know which supplier to impersonate?

Through compromised mailboxes, public contract information and simple observation of supplier relationships. Assume the relationship is visible and verify accordingly.

Verify the company behind the invoice

A company report confirms the registered identity, standing and details of any supplier in 200+ countries, from official and in-country sources, delivered in plain English.