← All terms

Invoice Fraud

Invoice fraud tricks a company into paying a fake or altered invoice, typically by impersonating a real supplier and changing the bank account details.

Invoice fraud is a financially devastating social engineering attack in which criminals trick an organization into paying money to an account they control — either by submitting a fake invoice or, more commonly, by impersonating a legitimate supplier and "updating" the bank details on a real one. Because the invoice matches an expected purchase from a known vendor, the payment sails through normal accounts-payable processing and the theft often goes unnoticed until the genuine supplier chases the unpaid bill weeks later.

How it works

The most dangerous variant, vendor email compromise, starts with the attacker breaking into a supplier's email account — often via spear phishing — and quietly reading correspondence for weeks. They learn the invoice cadence, formatting, reference numbers, and the names on both sides of the relationship. Then, at exactly the right moment, they send a perfectly plausible message from the supplier's real mailbox (or a look-alike domain): "Please note our updated banking details for the attached invoice." Everything about the invoice is genuine except the account number.

Simpler variants skip the compromise entirely: attackers mass-mail fake invoices for plausible services (domain renewals, directory listings, office supplies) hoping busy AP teams pay small amounts without scrutiny. At the other end of the scale, invoice fraud overlaps with CEO fraud when the "executive" personally pushes finance to settle a fraudulent invoice fast — and the same bank-detail-change trick aimed at HR instead of accounts payable is payroll diversion.

How to defend against it

The controls are procedural. Verify every bank-detail change by calling the supplier on a number from your master vendor file — never one printed on the invoice or email requesting the change. Require dual approval for new payees and account changes, match invoices against purchase orders and goods received, and hold first payments to changed accounts for an extra review cycle. Monitor for look-alike domains of your key suppliers.

Then train the people who sit at the choke point. Accounts-payable and procurement staff are among the highest-value targets in any organization, and their susceptibility can be measured and improved like any other human risk — run payment-fraud simulations against finance teams, not just email phishing tests against everyone.

Related terms

Business Email Compromise (BEC)Business email compromise is a targeted attack where criminals impersonate executives or trusted partners via email to trick employees into transferring money or sensitive data.CEO FraudCEO fraud is a social engineering attack where criminals impersonate a senior executive to pressure an employee into urgent wire transfers or data disclosure.Spear PhishingSpear phishing is a targeted phishing attack that uses personalized information about the victim to increase its effectiveness.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo