Invoice fraud redirects a payment a business genuinely owes, usually by changing bank details on an invoice sent from a compromised supplier mailbox. Because the debt and the supplier are real, nothing looks wrong. Canadian reports fell 90% between 2021 and 2025 while loss per victim roughly tripled.
Key facts
Category
Business & payments
First documented
2010
Typical loss
$3k–$500k USD, per victim
Main channels
email, compromised supplier mailbox, lookalike domain, postal letter, phone call
Who is targeted
Small and mid-sized businesses without a second-approver rule; Accounts payable staff, whose job is to pay invoices when asked; Charities, schools, churches and local authorities with lean finance teams; Construction and trades, where subcontractor invoices are frequent and large; Any business whose smaller suppliers have weaker email security than it does
Documented origins
Nigeria, United Kingdom, Romania, South Africa, United States
Main targets
United States, United Kingdom, Canada, Australia, Germany, Netherlands, Ireland, New Zealand
Case files
3 documented cases
Last reviewed
2026-09-06
The stages of the scheme, in order, with the point where it can still be stopped.
What it is
Invoice fraud is the theft of a payment a business was going to make anyway.
A supplier you have worked with for years sends an invoice. The work was done, the amount is right,
the reference matches, the email comes from the address you have always used. One thing has changed:
the bank details, with a short explanation. New banking arrangements. A restructure. An account under
review.
The explanation is not what makes it work. What makes it work is that everything else is genuinely
true. There is no fake company, no imaginary product and, in the most damaging version, no forged
email — an attacker has been sitting in the supplier’s mailbox reading the conversation, and sends the
revised invoice at exactly the moment one is expected.
The shape of the crime has changed sharply. Canadian vendor fraud reports fell from 4,120 in 2021 to
426 in the first nine months of 2025 — around 90% — while loss per victim rose from roughly C$3,200
to roughly C$8,500, peaking near C$15,500 in 2024. The cheap mass version is being defeated by
ordinary purchase-order controls. The targeted version is not.
How it actually works
A real supplier relationship
Real work, real invoices, a real payment cycle. Nothing has to be invented, which removes every
step at which a business would normally have questioned something.
One mailbox is taken
Credential phishing or a reused password, occasionally a stolen session token. Usually the
supplier’s mailbox rather than yours — a small firm is the route into a large one.
Quiet reading
The attacker does nothing for days or months. Amounts, terms, tone, who approves what, when
invoices fall due. Inbox rules divert replies so the real owner never sees the thread.
New bank details
A revised invoice, or a letter on headed paper announcing a change of bank. Sometimes from the
genuine account; sometimes from a domain one character out.
Where it could have stopped
The change of payment details is the scam, whatever explanation accompanies it. Confirm every change by voice, on a number you already held for that supplier — not the number on the invoice, and not by replying to the thread, which the attacker may be reading.
Paid correctly, to the wrong place
Approved through the normal process by someone doing their job properly. Nothing anomalous
happens from the bank’s point of view, and no control fires.
Discovered by the real supplier
Weeks later, chasing an unpaid invoice. And here is the part businesses find hardest: paying the
wrong account generally does not discharge the debt. You are out the money and still owe it.
Why it works
Nothing about it is false except eleven digits. The supplier is real, the work was done, the amount
is correct. Fraud detection is built to find anomalies, and there is no anomaly.
The compromise is usually somewhere you cannot see. A company can have excellent email security and
still lose a large payment through a subcontractor’s reused password.
Accounts payable is doing its job. The person who pays the invoice paid an invoice. There is no
lapse to point at, which is why blame lands unfairly and why these incidents are so rarely discussed
openly between businesses.
Timing comes free. The attacker has read the mailbox and knows when a payment is due. No urgency
needs manufacturing.
Small organisations have no second person. The control that reliably stops this is another human
confirming the change on a different channel. Charities, schools, small builders and local authorities
are over-represented in the case record because that person does not exist.
And the debt survives. Unlike consumer fraud, where the loss is the loss, a business that pays the
wrong account often has to pay again — which doubles the damage and makes the incident harder to
absorb quietly.
Where it comes from
Invoice fraud follows the business email compromise enforcement
record closely, and the same division of labour applies: the people who compromise mailboxes, the
people who send the emails, the people whose accounts receive the money and the people who convert it
into exportable goods are usually different people in different countries.
West African networks, particularly Nigerian groups operating both from Nigeria and from diaspora
communities, appear repeatedly in prosecutions — including the Houston conspiracy that laundered
proceeds from business email compromise, romance fraud and unemployment fraud by buying salvaged cars
and shipping them to Nigeria. Eastern European and Russian-speaking groups feature more in the
credential-access half of the market, selling mailbox access rather than running the fraud.
The postal version has a different and largely domestic history: invoices for directory listings,
office supplies or domain renewals, posted in bulk to businesses in the hope that somebody pays
without checking. Canada’s directory category records its defeat almost precisely — 43 reports in
2021, three in 2022, three in 2023, one in 2024.
Canadian vendor fraud reports fell from 4,120 in 2021 to 426 in the first nine months of 2025 — a fall of about 90% — while loss per victim rose from roughly C$3,200 to roughly C$8,500, and spiked to C$15,500 in 2024. Australia's false billing category shows the same divergence. Invoice fraud is reaching far fewer businesses and taking far more from each.
Australia's National Anti-Scam Centre reported combined losses of A$166.8 million to payment redirection scams in 2025, up 9.3% on 2024. Every other category in the country's top five fell or grew more slowly: investment losses dropped 11.4% and romance 10.8%, while remote access fell 34.1%. Payment redirection — the Australian name for business email compromise — was the outlier.
In September 2024 the FBI's Internet Crime Complaint Center published a decade of business email compromise figures: $55.5 billion in global exposed losses across complaints filed between October 2013 and December 2023, including 158,436 US victims and $20.1 billion in US exposed losses. The same advisory records a 9% increase in identified global exposed losses in a single year, and a shift in where the stolen money is sent.
Any change of bank details. New account, new bank, “our usual account is under audit”. There is no benign version arriving by email.
A letter announcing new banking arrangements, on headed paper, from a supplier you know.
An invoice for the right amount at the right time that you were not quite expecting yet.
A reply-to address that differs from the sender, or a domain one character out.
A thread that resumes after a gap with a slightly different writing style, or that drops other recipients.
Pressure to pay before a deadline that has just been brought forward.
A phone call confirming the emailed details using a number from the email. That is the same channel twice.
An invoice for something nobody can identify a purchase order for.
A supplier chasing an invoice you are sure you paid. This is often the first sign.
Payroll change requests redirecting an employee’s salary to a new account.
If it’s happening to you
If a payment has just gone to the wrong account, the next hour decides the outcome.
Call your bank immediately. Ask for a recall of the funds and any indemnification paperwork,
and say “business email compromise” — most banks have a specific process.
Ask your bank to contact the receiving bank directly. Recovery works on funds still sitting in
the receiving account.
Report it the same day. In the US, ic3.gov triggers the FBI’s Recovery Asset Team. See
where to report.
Assume a mailbox is still compromised — yours or the supplier’s. Do not discuss the incident on
the affected email system. Reset passwords, revoke sessions, and check for forwarding and inbox
rules the attacker created; those rules are often the only artefact left.
Warn the supplier on a known-good number. If the compromise was theirs, their other customers
are being targeted right now.
Preserve the emails with full headers, not screenshots.
Tell your insurer — cyber and crime policies often have short notification windows.
Get legal advice about the debt, which you may still owe.
Preventing it. One rule does most of the work, and it needs to be a rule rather than a judgement
call: a change of payment details is confirmed by voice, on a number you already held, by a second
person, before the payment goes out.
Around it: keep a verified supplier bank-details register that only two people can change; set a
payment threshold above which a second approver is mandatory; put external-sender warnings on email;
register and block lookalike domains; and use phishing-resistant multi-factor authentication on
mailboxes. And say out loud, to the people who pay invoices, that querying a payment is never a
problem — because the social cost of appearing to doubt a supplier or a director is exactly what this
scheme spends.
Where the money goes
A redirected invoice payment lands in a receiving account prepared for it — a mule account, or a real
business account whose owner was recruited or deceived. It rarely stays more than a few hours.
From there it splits and converts. IC3 records a growing share going directly to institutions holding
custodial accounts for third-party payment processors, to peer-to-peer processors and to
cryptocurrency exchanges — routes that did not exist when the recall process was designed. In 2025,
86% of reported BEC transactions went by wire or ACH, the fastest and least reversible conventional
rail.
The end of the chain is often physical and entirely mundane: goods bought with the proceeds and
exported. A car has paperwork, a buyer at the other end, and a value that survives the crossing.
No agency publishes a line item for most of the schemes on this site, so these charts show the
official categories that contain this scheme. Each series is labelled with the agency's
own category name. See how the mapping works.
Every factual claim above traces to one of these. Statistics are reported losses; see
methodology for what that does and does not measure.
Business Email Compromise: The $55 Billion Scam.
FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: $55.5bn in global exposed BEC losses 2013–2023, the shift toward custodial and crypto recipients, and the recall guidance.
Canadian Anti-Fraud Centre Fraud Reporting System Dataset.
Canadian Anti-Fraud Centre / RCMP. Accessed 2026-09-06. Supports: Vendor fraud, false billing and directory category reports, victims and losses, 2021 to 30 September 2025.
2025 Internet Crime Report.
FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: $3,046,598,558 in 2025 BEC losses from 24,768 complaints, and the 86% wire and ACH payment split.
Common questions
What is the difference between this and business email compromise?
Mostly framing. BEC is the umbrella; invoice fraud is the variant where the pretext is a supplier payment rather than an executive instruction. The FBI counts them together, Canada files invoice redirection under Spear Phishing, Australia calls the family payment redirection and UK Finance splits invoice and mandate fraud from CEO fraud.
Our security is good. Why are we still exposed?
Because the compromise is usually at a supplier, not at you. A small subcontractor with a reused password is the route into a company with excellent controls, and the email arrives from a real account you have corresponded with for years.
What single control actually works?
Confirming every change of bank details by voice, on a number you already held, before the payment goes out. Not a number on the invoice, and not by replying to the thread. Everything else — payment thresholds, external-sender warnings, lookalike-domain blocking — helps, but this is the one that has to hold.
We paid a fraudulent invoice. Do we still owe the supplier?
Generally yes, and that is the part businesses find hardest. Paying the wrong account does not discharge the debt, so you are out the money and still owe it. Get legal advice quickly, and notify your insurers — many policies have short notification windows.
What about the fake invoices that arrive in the post?
That is the older and cheaper version: an invoice for a directory listing, an office supply order or a domain renewal that was never bought, sent in bulk hoping accounts payable pays without checking. Purchase-order controls defeat it, which is why Canada's directory-scam category has almost disappeared — 43 reports in 2021, one in 2024.
Can the money be recovered?
Sometimes, within hours. Call the bank immediately, ask for a recall and the indemnity paperwork, and report it the same day. Recovery drops sharply once the funds move on, and IC3 records this money increasingly going straight into custodial and crypto accounts where recalls do not reach.
Where the money goes after it leaves, and where it becomes hard to recover.
Reporting is what produces the enforcement data on this page. Find the right agency and phone
number for your country on the report page. If money moved in the last
few hours, call your bank first.