Invoice Fraud
Invoice fraud tricks a company into paying a fake or altered invoice, typically by impersonating a real supplier and changing the bank account details.
Invoice fraud is a financially devastating social engineering attack in which criminals trick an organization into paying money to an account they control — either by submitting a fake invoice or, more commonly, by impersonating a legitimate supplier and "updating" the bank details on a real one. Because the invoice matches an expected purchase from a known vendor, the payment sails through normal accounts-payable processing and the theft often goes unnoticed until the genuine supplier chases the unpaid bill weeks later.
How it works
The most dangerous variant, vendor email compromise, starts with the attacker breaking into a supplier's email account — often via spear phishing — and quietly reading correspondence for weeks. They learn the invoice cadence, formatting, reference numbers, and the names on both sides of the relationship. Then, at exactly the right moment, they send a perfectly plausible message from the supplier's real mailbox (or a look-alike domain): "Please note our updated banking details for the attached invoice." Everything about the invoice is genuine except the account number.
Simpler variants skip the compromise entirely: attackers mass-mail fake invoices for plausible services (domain renewals, directory listings, office supplies) hoping busy AP teams pay small amounts without scrutiny. At the other end of the scale, invoice fraud overlaps with CEO fraud when the "executive" personally pushes finance to settle a fraudulent invoice fast — and the same bank-detail-change trick aimed at HR instead of accounts payable is payroll diversion.
How to defend against it
The controls are procedural. Verify every bank-detail change by calling the supplier on a number from your master vendor file — never one printed on the invoice or email requesting the change. Require dual approval for new payees and account changes, match invoices against purchase orders and goods received, and hold first payments to changed accounts for an extra review cycle. Monitor for look-alike domains of your key suppliers.
Then train the people who sit at the choke point. Accounts-payable and procurement staff are among the highest-value targets in any organization, and their susceptibility can be measured and improved like any other human risk — run payment-fraud simulations against finance teams, not just email phishing tests against everyone.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo