← Latest news
· 4 min read

How invoice fraud actually works, and the controls that stop it

How invoice fraud actually works, and the controls that stop it

The reason invoice fraud succeeds isn't that finance teams are careless. It's that a good version of it doesn't look like fraud at any point. It looks like a routine email from a supplier you have used for years, about an invoice you were expecting, for goods you actually received.

This is the mechanism, and the controls that interrupt it.

The common version

Invoice redirection. Someone gains access to an email account — often the supplier's, not yours — and watches. When an invoice goes out, they intercept it, change the bank details, and send it on. Or they send a separate "our bank details have changed" notice shortly before a payment run.

Everything else about the document is genuine. Correct amount, correct reference, correct goods, correct supplier. One field is wrong, and it's the field nobody checks because it's never been wrong before.

Payment goes to the fraudster. You find out weeks later when the real supplier chases an invoice you're certain you paid.

Why it works

The bank details field is the one nobody re-reads. You check the amount and the reference. You don't check the IBAN against the last invoice, because why would it have changed.

It's the one field that's hard to sense-check. A wrong supplier name is obvious. A wrong total is obvious. An IBAN with different digits looks exactly like an IBAN.

Timing is deliberate. These arrive during a payment run, near month-end, or when the person who'd normally notice is on leave. The email often mentions a deadline.

The account is real. Emails come from the actual supplier's domain because the account is genuinely compromised. Domain checks pass.

Two others worth knowing

Fake invoices for things you nearly buy. Directory listings, domain renewals, safety certificates. Small amounts, plausible descriptions, aimed at getting through a process where anything under a threshold isn't questioned. Often addressed to someone who left.

CEO fraud. An urgent email from the owner asking for a payment made quickly and quietly, usually while they're travelling. Preys on not wanting to question the boss.

The controls that actually work

Verify bank detail changes by phone, on a number you already had. The single most effective control available. Not a number from the email, not a reply to it — the number already in your records.

Every version of this fraud requires you to accept new bank details on the strength of an email. Break that and the whole thing fails.

Flag the field, don't just extract it. If your process reads bank details off documents, the useful question isn't "did it read the IBAN" but "does it tell me when the IBAN differs from last time, or when it wasn't read confidently".

A supplier's bank details changing is a rare event. It should be surfaced, not silently updated — which is the practical reason a blended accuracy percentage is worthless on this particular field.

Approval that includes the person who ordered. They know whether goods arrived. Someone in finance approving a plausible invoice for something they didn't order is approving the paperwork, not the purchase.

A rule for new suppliers. First invoice from anyone gets checked properly, including the bank details, against something that isn't the invoice.

Separate the person who can change supplier records from the person who runs payments. Hard in a small team, but even a light version — a second pair of eyes on changes to existing supplier records — removes the single point of failure.

What doesn't help much

Telling people to "be vigilant". Vigilance isn't a control. The whole design of this fraud is that it looks normal to a vigilant person.

Spam filtering. The email is genuine, from a genuine account.

Checking the sender address. Often correct, because the account is compromised rather than spoofed.

If it happens

Call the bank immediately. Same day matters — recall is sometimes possible if the money hasn't moved on.

Report it. In the UK, Action Fraud. Your bank will usually want a reference.

Tell the supplier. Their email is likely compromised and other customers are getting the same treatment.

Look at the other invoices from that period. If details were changed once, check whether anything else was.

The one thing

If you take a single control from this: bank detail changes get a phone call, on a number you already had.

Everything else is layers. That one breaks the mechanism.


Cribble scores every field separately and flags the ones it isn't confident about. Bank details are the field most often misread and the most expensive to get wrong, which is why they shouldn't be buried in an average.

See your own paperwork read.

One simple plan. Sign up and forward your first document today.

Get started