Invoice and vendor fraud

Also called: mandate fraud · false billing · supplier fraud · invoice redirection · directory scam

Invoice fraud redirects a payment a business genuinely owes, usually by changing bank details on an invoice sent from a compromised supplier mailbox. Because the debt and the supplier are real, nothing looks wrong. Canadian reports fell 90% between 2021 and 2025 while loss per victim roughly tripled.

Key facts

Category
Business & payments
First documented
2010
Typical loss
$3k–$500k USD, per victim
Main channels
email, compromised supplier mailbox, lookalike domain, postal letter, phone call
Who is targeted
Small and mid-sized businesses without a second-approver rule; Accounts payable staff, whose job is to pay invoices when asked; Charities, schools, churches and local authorities with lean finance teams; Construction and trades, where subcontractor invoices are frequent and large; Any business whose smaller suppliers have weaker email security than it does
Documented origins
Nigeria, United Kingdom, Romania, South Africa, United States
Main targets
United States, United Kingdom, Canada, Australia, Germany, Netherlands, Ireland, New Zealand
Case files
3 documented cases
Last reviewed
2026-09-06
Anatomy of invoice fraudAnatomy of invoice fraud. The invoice is for a real debt to a real supplier. Only the bank details are wrong. 1. A supplier relationship exists: Real work, real invoices, a real payment cycle. Nothing has to be invented. 2. One mailbox is taken: Usually the supplier's, not yours. A small firm's email is the route into a larger one. 3. Quiet reading: Amounts, terms, tone, who signs off, when invoices fall due. Rules hide the replies. 4. New bank details: A revised invoice, or a letter on headed paper: "we have changed banks, please update." 5. Paid correctly, to the wrong place: Approved through the normal process by someone doing their job properly. 6. Discovered by the real supplier: Weeks later, chasing an unpaid invoice. The debt is still owed; the money is gone. The diagram marks stage 4 as the point where the scheme can still be stopped: A change of payment details is the entire scam, whatever explanation accompanies it. Confirm every change by voice on a number you already held for that supplier — not the number on the invoice, and not by replying to the thread, which the attacker may be reading.Anatomy of invoice fraudThe invoice is for a real debt to a real supplier. Only the bank details are wrong.1A supplierrelationship existsReal work, real invoices, areal payment cycle. Nothinghas to be invented.Ongoing2One mailbox is takenUsually the supplier's, notyours. A small firm's emailis the route into a largerone.One login3Quiet readingAmounts, terms, tone, whosigns off, when invoicesfall due. Rules hide thereplies.Weeks4New bank detailsA revised invoice, or aletter on headed paper: "wehave changed banks, pleaseupdate."One email5Paid correctly, tothe wrong placeApproved through the normalprocess by someone doingtheir job properly.Minutes6Discovered by thereal supplierWeeks later, chasing anunpaid invoice. The debt isstill owed; the money isgone.WeeksWhere it can still be stopped — stage 4A change of payment details is the entire scam, whatever explanation accompanies it. Confirm every change by voice on a number you already held for thatsupplier — not the number on the invoice, and not by replying to the thread, which the attacker may be reading.Stages documented in FBI IC3 business email compromise advisories and Canadian Anti-Fraud Centre vendor-fraud reporting, 2021 to 2025.howscamswork.com
The stages of the scheme, in order, with the point where it can still be stopped.

What it is

Invoice fraud is the theft of a payment a business was going to make anyway.

A supplier you have worked with for years sends an invoice. The work was done, the amount is right, the reference matches, the email comes from the address you have always used. One thing has changed: the bank details, with a short explanation. New banking arrangements. A restructure. An account under review.

The explanation is not what makes it work. What makes it work is that everything else is genuinely true. There is no fake company, no imaginary product and, in the most damaging version, no forged email — an attacker has been sitting in the supplier’s mailbox reading the conversation, and sends the revised invoice at exactly the moment one is expected.

The shape of the crime has changed sharply. Canadian vendor fraud reports fell from 4,120 in 2021 to 426 in the first nine months of 2025 — around 90% — while loss per victim rose from roughly C$3,200 to roughly C$8,500, peaking near C$15,500 in 2024. The cheap mass version is being defeated by ordinary purchase-order controls. The targeted version is not.

How it actually works

  1. A real supplier relationship

    Real work, real invoices, a real payment cycle. Nothing has to be invented, which removes every step at which a business would normally have questioned something.

  2. One mailbox is taken

    Credential phishing or a reused password, occasionally a stolen session token. Usually the supplier’s mailbox rather than yours — a small firm is the route into a large one.

  3. Quiet reading

    The attacker does nothing for days or months. Amounts, terms, tone, who approves what, when invoices fall due. Inbox rules divert replies so the real owner never sees the thread.

  4. New bank details

    A revised invoice, or a letter on headed paper announcing a change of bank. Sometimes from the genuine account; sometimes from a domain one character out.

    Where it could have stopped

    The change of payment details is the scam, whatever explanation accompanies it. Confirm every change by voice, on a number you already held for that supplier — not the number on the invoice, and not by replying to the thread, which the attacker may be reading.

  5. Approved through the normal process by someone doing their job properly. Nothing anomalous happens from the bank’s point of view, and no control fires.

  6. Discovered by the real supplier

    Weeks later, chasing an unpaid invoice. And here is the part businesses find hardest: paying the wrong account generally does not discharge the debt. You are out the money and still owe it.

Why it works

Nothing about it is false except eleven digits. The supplier is real, the work was done, the amount is correct. Fraud detection is built to find anomalies, and there is no anomaly.

The compromise is usually somewhere you cannot see. A company can have excellent email security and still lose a large payment through a subcontractor’s reused password.

Accounts payable is doing its job. The person who pays the invoice paid an invoice. There is no lapse to point at, which is why blame lands unfairly and why these incidents are so rarely discussed openly between businesses.

Timing comes free. The attacker has read the mailbox and knows when a payment is due. No urgency needs manufacturing.

Small organisations have no second person. The control that reliably stops this is another human confirming the change on a different channel. Charities, schools, small builders and local authorities are over-represented in the case record because that person does not exist.

And the debt survives. Unlike consumer fraud, where the loss is the loss, a business that pays the wrong account often has to pay again — which doubles the damage and makes the incident harder to absorb quietly.

Where it comes from

Invoice fraud follows the business email compromise enforcement record closely, and the same division of labour applies: the people who compromise mailboxes, the people who send the emails, the people whose accounts receive the money and the people who convert it into exportable goods are usually different people in different countries.

West African networks, particularly Nigerian groups operating both from Nigeria and from diaspora communities, appear repeatedly in prosecutions — including the Houston conspiracy that laundered proceeds from business email compromise, romance fraud and unemployment fraud by buying salvaged cars and shipping them to Nigeria. Eastern European and Russian-speaking groups feature more in the credential-access half of the market, selling mailbox access rather than running the fraud.

The postal version has a different and largely domestic history: invoices for directory listings, office supplies or domain renewals, posted in bulk to businesses in the hope that somebody pays without checking. Canada’s directory category records its defeat almost precisely — 43 reports in 2021, three in 2022, three in 2023, one in 2024.

Real cases

Ten times fewer reports, ten times the loss each

2025 CA · AU Ongoing $1.8m

Canadian vendor fraud reports fell from 4,120 in 2021 to 426 in the first nine months of 2025 — a fall of about 90% — while loss per victim rose from roughly C$3,200 to roughly C$8,500, and spiked to C$15,500 in 2024. Australia's false billing category shows the same divergence. Invoice fraud is reaching far fewer businesses and taking far more from each.

Read the case file · 2 sources

Payment redirection: the only major Australian scam category still growing

2025 AU Ongoing $107.5m

Australia's National Anti-Scam Centre reported combined losses of A$166.8 million to payment redirection scams in 2025, up 9.3% on 2024. Every other category in the country's top five fell or grew more slowly: investment losses dropped 11.4% and romance 10.8%, while remote access fell 34.1%. Payment redirection — the Australian name for business email compromise — was the outlier.

Read the case file · 1 source

Ten years of business email compromise: $55.5 billion in global exposed losses

2024 US Ongoing $55.5bn

In September 2024 the FBI's Internet Crime Complaint Center published a decade of business email compromise figures: $55.5 billion in global exposed losses across complaints filed between October 2013 and December 2023, including 158,436 US victims and $20.1 billion in US exposed losses. The same advisory records a 9% increase in identified global exposed losses in a single year, and a shift in where the stolen money is sent.

Read the case file · 2 sources

Red flags

  • Any change of bank details. New account, new bank, “our usual account is under audit”. There is no benign version arriving by email.
  • A letter announcing new banking arrangements, on headed paper, from a supplier you know.
  • An invoice for the right amount at the right time that you were not quite expecting yet.
  • A reply-to address that differs from the sender, or a domain one character out.
  • A thread that resumes after a gap with a slightly different writing style, or that drops other recipients.
  • Pressure to pay before a deadline that has just been brought forward.
  • A phone call confirming the emailed details using a number from the email. That is the same channel twice.
  • An invoice for something nobody can identify a purchase order for.
  • A supplier chasing an invoice you are sure you paid. This is often the first sign.
  • Payroll change requests redirecting an employee’s salary to a new account.

If it’s happening to you

If a payment has just gone to the wrong account, the next hour decides the outcome.

  1. Call your bank immediately. Ask for a recall of the funds and any indemnification paperwork, and say “business email compromise” — most banks have a specific process.
  2. Ask your bank to contact the receiving bank directly. Recovery works on funds still sitting in the receiving account.
  3. Report it the same day. In the US, ic3.gov triggers the FBI’s Recovery Asset Team. See where to report.
  4. Assume a mailbox is still compromised — yours or the supplier’s. Do not discuss the incident on the affected email system. Reset passwords, revoke sessions, and check for forwarding and inbox rules the attacker created; those rules are often the only artefact left.
  5. Warn the supplier on a known-good number. If the compromise was theirs, their other customers are being targeted right now.
  6. Preserve the emails with full headers, not screenshots.
  7. Tell your insurer — cyber and crime policies often have short notification windows.
  8. Get legal advice about the debt, which you may still owe.

Preventing it. One rule does most of the work, and it needs to be a rule rather than a judgement call: a change of payment details is confirmed by voice, on a number you already held, by a second person, before the payment goes out.

Around it: keep a verified supplier bank-details register that only two people can change; set a payment threshold above which a second approver is mandatory; put external-sender warnings on email; register and block lookalike domains; and use phishing-resistant multi-factor authentication on mailboxes. And say out loud, to the people who pay invoices, that querying a payment is never a problem — because the social cost of appearing to doubt a supplier or a director is exactly what this scheme spends.

Where the money goes

A redirected invoice payment lands in a receiving account prepared for it — a mule account, or a real business account whose owner was recruited or deceived. It rarely stays more than a few hours.

From there it splits and converts. IC3 records a growing share going directly to institutions holding custodial accounts for third-party payment processors, to peer-to-peer processors and to cryptocurrency exchanges — routes that did not exist when the recall process was designed. In 2025, 86% of reported BEC transactions went by wire or ACH, the fastest and least reversible conventional rail.

The end of the chain is often physical and entirely mundane: goods bought with the proceeds and exported. A car has paperwork, a buyer at the other end, and a value that survives the crossing.

The other half of this story

Our sibling site Clean on Paper explains how redirected invoices are laundered — through goods, exports and invoicing, and why that is so much harder to unwind than moving money between accounts.

By the numbers

No agency publishes a line item for most of the schemes on this site, so these charts show the official categories that contain this scheme. Each series is labelled with the agency's own category name. See how the mapping works.

How contact was made, CA, 2025Horizontal bars of reported losses by contact channel in 2025, led by Email at $23m.How contact was made, CA, 2025Reported losses by the channel the scammer used, for the agency categories covering this scheme.Email$23mEmail: $23mText message$3.3mText message: $3.3mOther/unknown$3.2mOther/unknown: $3.2mDirect call$2.3mDirect call: $2.3mNot Available$491,054Not Available: $491,054Internet-social network$258,476Internet-social network: $258,476Door to door/in person$81,852Door to door/in person: $81,852Internet$76,977Internet: $76,977Mail$1,431Mail: $1,431$0$10m$20mAggregated across every agency category that maps to this scheme, so it inherits those categories’ breadth.Reported losses only. Every agency here says most fraud is never reported to it, so treat these as a floor, not a total.Sources: Canadian Anti-Fraud Centre / RCMP. Pulled 2026-09-06.
Full dataset, methodology and downloads
Reported losses over timeLine chart of reported losses from 2021 to 2025 for the agency categories that cover this scheme: BEC (US); Payment redirection (AU); Spear Phishing (CA); Vendor Fraud (CA).Reported losses over timeEach line is one agency category that covers this scheme. Agency categories are usually broader than the scheme itself.$0$1.0bn$2.0bn$3.0bnBEC (US), 2023: $2.9bnBEC (US), 2024: $2.8bnBEC (US), 2025: $3.0bnPayment redirection (AU), 2024: $101mPayment redirection (AU), 2025: $115mSpear Phishing (CA), 2021: $43mSpear Phishing (CA), 2022: $45mSpear Phishing (CA), 2023: $44mSpear Phishing (CA), 2024: $49mSpear Phishing (CA), 2025: $30mVendor Fraud (CA), 2021: $6.4mVendor Fraud (CA), 2022: $2.7mVendor Fraud (CA), 2023: $3.0mVendor Fraud (CA), 2024: $6.1mVendor Fraud (CA), 2025: $1.8m20212022202320242025BEC (US)Payment redirection (AU)Spear Phishing (CA)Vendor Fraud (CA)Categories are the publishers’ own and are broader than this scheme, so these lines bound it rather than measure it exactly. Lines are notcomparable to each other: different countries, different reporting systems.Reported losses only. Every agency here says most fraud is never reported to it, so treat these as a floor, not a total.Sources: Canadian Anti-Fraud Centre / RCMP; FBI Internet Crime Complaint Center (IC3); National Anti-Scam Centre (ACCC), Australia(transcribed from the published report). Pulled 2026-09-06.
Full dataset, methodology and downloads

Sources

Every factual claim above traces to one of these. Statistics are reported losses; see methodology for what that does and does not measure.

  1. Business Email Compromise: The $55 Billion Scam. FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: $55.5bn in global exposed BEC losses 2013–2023, the shift toward custodial and crypto recipients, and the recall guidance.
  2. Canadian Anti-Fraud Centre Fraud Reporting System Dataset. Canadian Anti-Fraud Centre / RCMP. Accessed 2026-09-06. Supports: Vendor fraud, false billing and directory category reports, victims and losses, 2021 to 30 September 2025.
  3. Targeting scams: report of the National Anti-Scam Centre on scams data and activity 2025. National Anti-Scam Centre (ACCC), Australia. Accessed 2026-09-06. Supports: A$166.8m in Australian payment redirection losses in 2025, the ReportCyber and Scamwatch split, and false billing among CALD reporters.
  4. Fraud remains a national security threat as criminals steal almost £1.3 billion. UK Finance. Accessed 2026-09-06. Supports: UK authorised push payment fraud totals for 2025 and the invoice and mandate category.
  5. 2025 Internet Crime Report. FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: $3,046,598,558 in 2025 BEC losses from 24,768 complaints, and the 86% wire and ACH payment split.

Common questions

What is the difference between this and business email compromise?

Mostly framing. BEC is the umbrella; invoice fraud is the variant where the pretext is a supplier payment rather than an executive instruction. The FBI counts them together, Canada files invoice redirection under Spear Phishing, Australia calls the family payment redirection and UK Finance splits invoice and mandate fraud from CEO fraud.

Our security is good. Why are we still exposed?

Because the compromise is usually at a supplier, not at you. A small subcontractor with a reused password is the route into a company with excellent controls, and the email arrives from a real account you have corresponded with for years.

What single control actually works?

Confirming every change of bank details by voice, on a number you already held, before the payment goes out. Not a number on the invoice, and not by replying to the thread. Everything else — payment thresholds, external-sender warnings, lookalike-domain blocking — helps, but this is the one that has to hold.

We paid a fraudulent invoice. Do we still owe the supplier?

Generally yes, and that is the part businesses find hardest. Paying the wrong account does not discharge the debt, so you are out the money and still owe it. Get legal advice quickly, and notify your insurers — many policies have short notification windows.

What about the fake invoices that arrive in the post?

That is the older and cheaper version: an invoice for a directory listing, an office supply order or a domain renewal that was never bought, sent in bulk hoping accounts payable pays without checking. Purchase-order controls defeat it, which is why Canada's directory-scam category has almost disappeared — 43 reports in 2021, one in 2024.

Can the money be recovered?

Sometimes, within hours. Call the bank immediately, ask for a recall and the indemnity paperwork, and report it the same day. Recovery drops sharply once the funds move on, and IC3 records this money increasingly going straight into custodial and crypto accounts where recalls do not reach.

Where a redirected invoice payment goesWhere a redirected invoice payment goes. 86% of reported BEC transactions in 2025 went by wire or ACH — the fastest and least reversible conventional rail. Where a redirected invoice payment goes86% of reported BEC transactions in 2025 went by wire or ACH — the fastest and least reversible conventional rail.The paying businessA mule account, or areal business accountwhose owner wasrecruited or deceivedA prepared receivingaccountRoutes that did notexist when the recallprocess was designedCustodial and P2Pprocessors, exchangesA car has paperwork, abuyer at the otherend, and a value thatsurvives the crossingGoods bought andexportedReversibilityA recall is realistically possible only at the first hop, and only in the first hours. After the money is converted it becomes an investigation, not a refund.How redirected invoice money is moved — Clean on Paper, our sibling sitehttps://cleanonpaper.site/techniques/trade-based-money-laundering/IC3 records a growing share of BEC funds going directly to institutions holding custodial accounts for third-party payment processors, to peer-to-peer processors and to cryptocurrency exchanges.howscamswork.com
Where the money goes after it leaves, and where it becomes hard to recover.

Report it

Reporting is what produces the enforcement data on this page. Find the right agency and phone number for your country on the report page. If money moved in the last few hours, call your bank first.