A fake invoice email scam is most dangerous when the message does not look fake at all. The invoice may use a familiar vendor name, arrive during the normal billing process, contain an amount that seems reasonable, or even appear inside a genuine email conversation that your staff has been following for weeks.
That is why a small business cannot make payment security depend entirely on spotting bad grammar, strange logos, or suspicious senders. A convincing payment-diversion attack may arrive through a lookalike address, an impersonated executive, or a genuinely compromised vendor mailbox.
The practical defense is to separate vendor identity from payment-destination verification.
If an invoice introduces a new bank account, beneficiary, payment method, or other destination for money, treat that change as its own verification event.
Stop the payment, contact a known vendor representative using a phone number obtained independently of the new message or invoice, verify the change, document who confirmed it, obtain the required internal approval, and only then update the vendor record and release payment.
That approach closely matches current FBI/IC3 guidance, which recommends using a secondary channel to verify account-information changes and verifying changes in payment procedures with the person making the request.
The rest of this guide turns that principle into a routine a bookkeeper, owner, office manager, executive assistant, or small accounts-payable team can actually use.
How Fake Invoice Email Scams and BEC Actually Reach Businesses
Not every fake invoice email scam follows the same path. Some criminals send invoices for products or services the business never bought. Others imitate a genuine supplier and divert a real payment. Business Email Compromise, or BEC, can be more difficult because a legitimate business email account may actually have been compromised.
The FBI describes BEC as a scam involving businesses or individuals making legitimate transfers of funds, often involving compromised business email accounts, impersonation, and fraudulent changes in payment instructions.
For accounts-payable staff, the important distinction is what the attacker is trying to change.
A completely fabricated invoice asks you to pay something you do not owe. A payment-diversion attack may leave the real vendor name, invoice number, amount, products, and due date untouched while changing only the destination of the payment.
That second situation is particularly dangerous because several checks can appear to pass. The vendor exists. The invoice exists. The amount is correct. The email conversation looks familiar. Only the bank instructions are wrong.
| Attack Type | What It Looks Like | Best Verification Step |
| Unknown fake invoice | Bill from a company you do not recognize | Match invoice to an actual purchase, contract, or authorization |
| Vendor impersonation | Familiar company name but questionable sender details | Independently contact the real vendor |
| Payment-update diversion | Realistic invoice plus “new banking details” | Freeze the change and perform independent callback verification |
| Compromised vendor mailbox | Message arrives from the real vendor account or thread | Verify the payment destination outside email |
| Executive impersonation | Urgent instruction supposedly from an owner or executive | Confirm through an established internal channel and normal approval process |
| New-beneficiary request | Vendor asks to send the next payment somewhere new | Treat the beneficiary as unverified until independently confirmed |
The FTC’s May 2026 warning to small businesses specifically addresses phony invoices and recommends clear purchase and invoice-approval procedures rather than automatically paying an unfamiliar bill.
For broader warning signs around generic phishing messages, staff can also review this background guide on how to spot and report phishing emails. Invoice-payment attacks require an additional control, however: verification of where the money is being sent.
Lookalike Domains
One form of invoice fraud uses an email address that resembles a legitimate company’s address without actually being the same domain. The FBI recommends examining email addresses, URLs, and spelling carefully because small differences can mislead a recipient.
For the employee paying the bill, the check should stay simple.
Expand the sender address rather than relying on the display name. Compare the domain to the one in your vendor master record or previous verified correspondence. Check whether the Reply-To address sends responses somewhere different.
Signals worth investigating include an unexpected character variation, extra word, different domain ending, or sender address inconsistent with the vendor’s established contact information.
Do not make this a pass/fail test. A strange address is a reason to investigate, but a correct address is not proof that the payment instruction is genuine.
That distinction matters because a legitimate mailbox may itself be compromised.
Hijacked Email Threads Are Harder to Spot
A business email compromise small business incident becomes much more convincing when the attacker is operating through a real account.
A compromised vendor mailbox may expose an existing email conversation. As a result, a malicious payment-update message can appear alongside genuine purchase discussions, scheduling notes, prior invoices, names, signatures, and other familiar context.
That defeats one of the most common informal security habits: “I recognize the sender, so the request must be real.”
It may also defeat email-authentication clues that help with simple domain spoofing. SPF, DKIM, and DMARC can help receiving systems identify certain forms of unauthorized email use, but they cannot independently tell your bookkeeper that the person controlling an authenticated vendor mailbox is trustworthy at that moment.
This leads to one of the most useful rules in accounts payable:
Known vendor does not mean known payment destination.
Trust the business relationship, but independently verify any material change to where the money goes.
Urgency Should Increase Verification, Not Reduce It
Payment scams frequently attempt to turn an ordinary invoice into an emergency.
The message may say that payment must be made today, a shipment will be stopped, banking information has just changed, a late charge is imminent, the executive is unavailable, or month-end processing requires an immediate transfer.
The FBI specifically advises extra caution when someone is pressing the recipient to act quickly. The FTC similarly warns small businesses against allowing urgency to override normal payment judgment.
Urgency does not prove fraud. Real vendors have overdue invoices, legitimate account changes, and genuine deadlines.
But urgency should never eliminate verification.
If the request would normally require a callback or second approval, the words “urgent,” “today,” or “CEO approved” should not create an exception.
Invoice Fraud Red Flags to Check Before Paying

Useful invoice fraud red flags are not limited to spelling mistakes or ugly formatting. The strongest signals are often changes in the business transaction itself.
An unexpected beneficiary deserves more attention than a misplaced logo. A different currency matters more than whether the signature font has changed. A request to bypass the owner who normally approves payments matters more than whether the email sounds friendly.
The goal is not to teach employees to declare an invoice fraudulent from one clue. It is to identify which requests require escalation or independent confirmation.
| Signal | Why It Matters | What to Do |
| New bank account | Changes where company money will go | Stop payment and independently verify |
| New beneficiary name | May indicate payment diversion | Compare against vendor master and call known contact |
| Different payment method | Breaks established vendor pattern | Confirm why the method changed |
| Different currency | May materially change destination or transaction | Verify commercial reason and instructions |
| Different country | May indicate an unexpected destination | Escalate and independently confirm |
| Mismatched Reply-To | Response may be routed away from known vendor | Do not verify through that thread |
| Unusual invoice number | Could be a fabricated or altered bill | Compare with vendor records or portal |
| Unexpected amount | May not match order, contract, or historical billing | Match supporting documentation |
| Altered remittance instructions | Directly affects payment routing | Treat as a payment-change event |
| Request to bypass approval | Attempts to defeat an internal control | Refuse exception and escalate |
| Unexpected attachment | Could contain a fake invoice or other threat | Verify before interacting with it |
| Strange footer or formatting | May indicate imitation | Treat as a clue, not proof |
| High-pressure deadline | Can discourage normal checking | Slow the process and verify |
Domain, Reply-To, and Display-Name Checks
The visible sender name is one of the weakest identity signals available to an employee.
A message may display “Acme Supply Accounts Receivable” even though the actual address does not belong to that supplier. Expand the sender field and inspect the address.
Next, check the Reply-To field if your mail system shows one. A different Reply-To is not automatically malicious—business systems sometimes legitimately route replies elsewhere—but an unexpected mismatch deserves investigation when money is involved.
Compare these values with information that existed before the new payment request.
The purpose is not to conduct a forensic examination of email headers. Small companies can gain substantial value from simply teaching the person who pays invoices to expand the sender details instead of trusting the display name.
Formatting Is Evidence, Not Verification
A fake vendor invoice may differ subtly from previous invoices.
The logo could look different. Bank information may appear in a new location. The invoice layout may have changed. Contact details, signature blocks, footer language, tax fields, or remittance instructions might not match earlier documents.
These differences justify further review.
But the reverse is equally important: matching formatting does not prove authenticity. Invoice templates, company branding, and signatures may be copied, and a compromised account can distribute altered documents within a genuine conversation.
The correct question is not “Does this PDF look professional?”
It is “Does this transaction make sense, and has any payment destination changed?”
Timing Can Change the Risk
Consider whether the request fits the vendor’s normal billing cycle.
An unexpected invoice arriving weeks early, immediately before a holiday, near quarter-end, at an unusual time, or from a contact who normally does not handle accounts receivable deserves closer review.
Again, timing alone does not establish fraud.
Its value comes from context. If an unusual-time invoice also introduces a new beneficiary and demands same-day payment, the combined signals justify treating the request as high risk.
Vendor Payment Update Phishing: Make Bank Changes a Separate Event

Vendor payment update phishing is where many ordinary invoice-review habits fail.
Imagine that your company has paid the same supplier for three years. A realistic email arrives:
“Our banking information has changed. Please use the attached instructions beginning with this invoice.”
The vendor name is correct. The outstanding balance is real. The invoice number appears genuine.
The dangerous temptation is to treat the change as an administrative edit.
Do not.
Never approve a new bank account or beneficiary solely because an email says the vendor changed it.
Instead, separate the transaction into two questions:
- Is this a legitimate invoice from a legitimate vendor?
- Is this the legitimate payment destination for that vendor?
Question one cannot answer question two.
A compromised vendor mailbox can distribute an authentic invoice while supplying fraudulent bank instructions. Asking, “Did your company issue invoice 7821?” therefore does not adequately verify a bank change.
You need to confirm the change itself.
The Callback Verification Rule for Bank-Detail Changes

A callback verification procedure creates an independent path between the payment request and the person authorizing the destination.
The FBI specifically recommends verifying account-information changes through secondary channels and directly contacting requestors before complying with suspicious payment changes. Its BEC guidance also says account-number or payment-procedure changes should be verified with the person making the request.
For a small company, the procedure can be straightforward:
- Stop the payment. Do not update the beneficiary while verification is pending.
- Do not reply to the new email to verify it. If the mailbox or thread is compromised, the same person who sent the fraudulent instructions may answer.
- Find a trusted phone number that existed independently of the request.
- Call a known vendor contact.
- Confirm the invoice and the fact that payment instructions changed.
- Confirm limited identifying details, such as bank name, effective date, and an appropriate non-sensitive account reference such as last four digits where the vendor’s procedures permit it.
- Record who confirmed the change and when.
- Obtain internal approval.
- Only then update the vendor master record.
- Release the payment through the normal process.
Do not make email the only verification channel for the same request that originated by email.
Use a Known Number, Not the Number in the New Message
The callback number must come from an independent source.
Suitable sources can include the phone number already stored in the vendor master file, a previously signed contract, an earlier verified onboarding record, or the vendor’s official website navigated to independently.
Do not use the number printed on the changed invoice.
Do not use a telephone number newly supplied in the payment-change email.
Do not rely on a contact added for the first time inside the same email conversation.
IC3 has specifically advised businesses to call a company’s main number to confirm an email contact rather than relying on telephone numbers supplied through the email itself.
This control matters because “call us to confirm” provides no independence if the attacker also supplied the number you are calling.
How to Verify a Bank Change Request
When you need to verify bank change request instructions, use a fixed workflow:
Request received → payment hold → independent callback → second approval → vendor master updated → payment released → verification record stored
During the call, identify yourself using your normal business relationship and explain that company policy requires independent verification whenever payment instructions change.
Verify the commercial facts, not passwords or credentials.
Useful questions may include:
- Did your company request a change in our payment instructions?
- Is the change effective for this invoice?
- Which invoice number and amount are affected?
- What bank name should we expect?
- Can you confirm an agreed non-sensitive identifier for the destination?
- When did the change become effective?
Avoid transmitting full account credentials through channels that have not been approved for sensitive banking information.
Most importantly, do not stop at “Yes, we sent the invoice.”
Confirm the destination change.
Callback Verification Record
A short audit record is enough for many small businesses.
| Field | What to Record |
| Vendor | Legal or established vendor name |
| Invoice | Invoice number or other transaction reference |
| Change requested | Bank, beneficiary, payment method, or other destination change |
| Callback source | Where the trusted telephone number came from |
| Vendor representative | Name or role of person who confirmed |
| Confirmation date/time | When verification occurred |
| Details confirmed | Limited non-sensitive verification points |
| Internal approver | Person who authorized the change |
| Vendor record updated | Date payment master was changed |
| Notes | Exceptions or additional supporting information |
The purpose is accountability and reconstruction. If someone asks six months later why a beneficiary changed, the company should be able to show how it was independently verified.
How Dual Approval Works Even in a Tiny Business
Dual approval does not require an enterprise finance department.
Suppose a small business consists of an owner, bookkeeper, and office manager. The bookkeeper can prepare payments while the owner approves new bank destinations. Alternatively, the office manager can enter vendor changes while the bookkeeper or owner reviews them before release.
The separation can be narrow.
You do not necessarily need two people to inspect every routine utility payment. Instead, reserve mandatory second approval for higher-risk events.
Common policy triggers include:
- every vendor bank-detail change;
- every first payment to a new vendor;
- creation of a new beneficiary;
- unusual foreign or cross-border payment instructions;
- payments over a company-selected threshold;
- payments that bypass the normal purchase or invoice cycle.
There is no universal dollar threshold appropriate for every company.
A $2,000 second-approval limit may be meaningful to one business and impractical for another. Set the threshold based on your normal payment sizes, cash position, staffing, banking controls, and operational needs.
Bank Changes Should Be Dual-Approved Even When the Payment Is Small
Payment amount is not the only source of risk.
A fraudulent beneficiary may first receive a relatively small payment that does not attract attention. If that destination remains in the vendor master, future invoices could be sent there without another change request.
Therefore, bank-detail changes deserve approval because they modify the company’s payment infrastructure, not merely because of the amount of today’s invoice.
A useful rule is:
Two-person approval for payment-destination changes; amount-based approval for otherwise routine payments.
What If Only One Person Pays the Bills?
A sole proprietor or one-person accounting operation cannot manufacture genuine separation of duties.
Instead, substitute other friction:
- pause every destination change;
- require a live independent callback;
- maintain a vendor master record;
- use beneficiary-management controls offered by the bank;
- enable transaction and beneficiary alerts;
- keep daily transfer limits appropriate to normal operations;
- delay optional high-risk changes until verification is complete;
- reconcile accounts promptly.
If your banking platform can require a separate confirmation when a beneficiary is created or modified, use it.
Ask the bank which controls are actually available because capabilities vary by institution and account type.
A Five-Minute Verification Routine for Every Payment Request
A usable control must be fast enough that employees will follow it.
The following routine makes ordinary invoices easy while escalating payment-destination changes automatically.
Step 1: Does the Invoice Make Sense?
Confirm four basics:
Vendor: Do we actually do business with this company?
Amount: Is the amount consistent with the order, quote, contract, subscription, or recent activity?
Timing: Is an invoice expected now?
Purchase: Can somebody identify the product or service being billed?
If your business uses purchase orders, match the invoice against the PO and evidence that the goods or services were received.
If you do not use purchase orders, the supporting record might be a signed estimate, email authorization, recurring service agreement, delivery receipt, calendar booking, or known monthly expense.
Step 2: Did Any Payment Detail Change?
Compare the invoice with the vendor master.
Look for:
- new account;
- new beneficiary;
- new payment link;
- different bank;
- different payment method;
- new country;
- new currency;
- changed remittance address.
If nothing changed and the invoice is otherwise expected, proceed through normal approval.
If the destination changed, stop.
Step 3: Verify Independently
Use the callback verification procedure.
Call the known vendor contact using information that existed independently of the new request.
Do not reply to the suspect thread and ask whether it is legitimate.
Step 4: Obtain Approval
Apply your company’s approval rule.
A high-value invoice may require second approval even without a payment change. A bank-detail change should receive heightened approval regardless of payment size.
Step 5: Save the Verification Record
Store the invoice together with enough documentation to show:
- what was checked;
- whether details changed;
- who verified the change;
- who approved it.
That can take minutes and provides a far stronger control than asking staff to rely on intuition.
Payment Request Risk Levels
| Risk Level | Example | Required Check |
| Low | Expected recurring vendor, normal amount, unchanged destination | Normal invoice approval |
| Medium | Unexpected amount, unusual invoice timing, unfamiliar contact | Match purchase and independently clarify anomalies |
| High | New bank account, new beneficiary, new currency, urgent payment change | Hold payment, independent callback, enhanced approval |
Not every invoice needs a telephone call. That would make the process burdensome and could cause employees to stop following it.
Callbacks should concentrate on material changes: new vendors, new payment destinations, unusual high-risk instructions, and significant anomalies.
Practical Small-Business Invoice Verification Workflow
Use the following end-to-end procedure as the operating checklist for accounts payable:
- Receive the invoice or payment request.
- Match it to an expected purchase, service, contract, or recurring expense.
- Inspect the sender domain and Reply-To information.
- Compare the vendor and payment destination with the vendor master record.
- If the destination is unchanged and nothing else is suspicious, follow normal approval.
- If bank or payment details changed, place the payment on hold.
- Retrieve an independently verified vendor telephone number.
- Call the known vendor contact.
- Confirm the change itself, not merely the invoice.
- Record the verification.
- Obtain the required second approval.
- Update the vendor master only after verification.
- Release the payment.
- Save the invoice and verification record.
- Reconcile the payment after it settles.
The workflow separates four decisions that are too often blended together:
Is the email plausible?
Is the vendor legitimate?
Is the payment destination verified?
Is the payment internally approved?
Passing one check does not automatically satisfy the next.
What to Do in the First Hour After Paying a Fraudulent Invoice
Once money has been sent, the task changes from prevention to containment and recovery assistance.
Do not spend the first hour debating who made the mistake.
Contact the financial institution.
The FBI’s current BEC page tells victims to contact their financial institution immediately and request that it contact the financial institution where the transfer was sent. IC3 also directs victims to report BEC through its complaint system.
Nacha’s credit-push fraud checklist similarly tells a corporate originator to recognize the misdirected payment, review the payment details, contact its originating financial institution, and discuss recovery options.
First-Hour Fraud Response Workflow
- Stop additional payments. Freeze the affected vendor destination until it has been reverified.
- Contact the bank or financial institution immediately.
- Ask for the fraud team or the group that handles the relevant payment rail.
- Explain that the payment was induced by suspected invoice or BEC fraud.
- Ask what recovery action is appropriate, such as a wire recall, ACH recovery/return request, payment trace, hold request, check stop-payment request, or card dispute procedure.
- Save the payment confirmation, reference numbers, beneficiary information, dates, and amounts.
- Preserve the fraudulent email and invoice.
- Secure affected email accounts.
- Review account access, forwarding rules, recovery settings, and suspicious mailbox rules.
- Contact the genuine vendor through independently verified contact information.
- Notify the owner, controller, or other appropriate internal leaders.
- Report BEC to the FBI Internet Crime Complaint Center and other appropriate authorities.
- Monitor banking and email activity for related transactions or unauthorized access.
- Document every action and communication.
No procedure can guarantee recovery. The payment method, transaction status, financial institutions involved, facts of the authorization, and applicable rules can all affect available options.
Payment Rail Matters
A business should describe the transaction accurately when speaking with its bank rather than assuming every payment can be “reversed.”
| Payment Rail | Immediate Response | Who to Contact |
| Wire | Report fraud immediately and ask whether a recall, trace, receiving-bank contact, or other recovery action is available | Originating bank’s fraud/wire team |
| ACH credit | Report the fraudulent payment and ask the bank what recovery or return-request options apply | Originating bank/ODFI |
| Check | Ask whether stop payment is still possible; if already processed, report the fraud immediately | Bank or credit union |
| Card | Report the transaction and ask about the applicable fraud/dispute process | Card issuer or relevant payment provider |
For wires, both FBI guidance and CFPB guidance use wire recall terminology and emphasize contacting the sending institution promptly.
For ACH, terminology requires more care. Nacha’s rules distinguish permitted reversals from other fraud-recovery tools, and an ACH payment induced under false pretenses should not be casually described as though the originator can unilaterally reverse it. Contact the originating financial institution and let it determine the proper recovery procedure for the facts.
For an unprocessed check, a stop-payment order may be available, but the process varies by financial institution.
For card transactions, the appropriate terminology generally involves reporting the transaction and using the issuer or provider’s fraud/dispute process rather than requesting a wire-style recall. Visa, for example, directs unauthorized-charge issues to the card issuer.
Why Speed Matters
Misdirected funds may become harder for institutions to recover as time passes or circumstances change.
The employee’s job is not to determine whether recovery will succeed.
The job is to make the call immediately, give the bank accurate information, preserve transaction evidence, and follow its fraud team’s instructions.
Reporting Business Email Compromise
Current FBI guidance directs victims of BEC to the FBI Internet Crime Complaint Center. The current complaint form collects information about the affected person or business, financial transactions, subjects when known, the incident narrative, and technical information where available. It also instructs complainants to retain original evidence.
Reporting to IC3 is separate from contacting your bank.
Do both when appropriate.
Depending on the circumstances, your business may also decide to contact local law enforcement or other relevant agencies. The CFPB’s current fraud guidance points consumers toward the FBI, FTC, state attorneys general, and local police or sheriff departments for reporting scams.
Preserve Evidence Before Cleaning Things Up
Keep copies of:
- the fraudulent email;
- the invoice or attachment;
- payment instructions;
- payment confirmation;
- transaction reference information;
- callback and verification notes;
- account-security alerts;
- relevant email-account activity;
- easily available original email headers;
- internal approvals and communications.
Do not unnecessarily alter source material before saving it.
If law enforcement, your financial institution, insurer, attorney, forensic specialist, or another authorized party later needs information, preserving the original evidence helps reconstruct what happened.
Secure the Email Account After Suspected Compromise
Invoice fraud can involve either the vendor’s email system, your own system, or both.
If there is reason to believe one of your business accounts was accessed without authorization, take account-security actions rather than assuming the fraudulent payment was an isolated bookkeeping mistake.
Appropriate defensive steps can include:
- change the affected account password;
- review or reset MFA as appropriate;
- sign out active sessions where your provider supports it;
- review recent account activity;
- inspect recovery email addresses and telephone numbers;
- examine forwarding rules;
- examine mailbox rules or filters you do not recognize;
- review delegated mailbox access and connected applications.
Google’s compromised-account guidance directs users to review account activity and security settings after suspected unauthorized access. Microsoft also provides an account-wide sign-out option for suspected unauthorized access, although provider-specific steps differ.
MFA Helps, but Payment Verification Is Still Necessary
CISA recommends requiring MFA for business accounts and advises organizations to use stronger, phishing-resistant methods where practical. Email and employees handling sensitive information are sensible priorities.
MFA substantially raises the difficulty of many account-takeover attacks.
It does not prove that every email arriving from another company’s legitimate account is safe.
A vendor could be compromised. An already-authorized session could be abused. Social engineering could occur without compromising your own mailbox.
Therefore:
MFA protects account access. Callback verification protects payment changes.
Use both controls rather than treating one as a substitute for the other.
Contact the Real Vendor and Reconcile the Actual Invoice
Once suspected payment diversion is identified, contact the genuine vendor through a trusted independent channel.
Explain what happened without assuming whose systems were compromised. Ask the vendor to confirm the legitimate outstanding invoice and freeze further payment-detail changes until both sides establish the correct destination.
The fraud loss and the commercial obligation are separate issues.
Your company may still have a legitimate invoice outstanding even though money was sent to the wrong recipient. Conversely, contractual terms, insurance, banking actions, or other circumstances may affect how the parties ultimately resolve the loss.
Do not automatically issue a second payment simply because the vendor says the original invoice remains unpaid.
First reconcile:
- invoice number;
- goods or services received;
- legitimate amount due;
- original fraudulent payment;
- recovery efforts;
- verified payment destination;
- internal approval for any replacement payment.
That process reduces the risk of paying a legitimate invoice twice while everyone is reacting to the incident.
Why Billing Platforms Can Reduce Some PDF Invoice Spoofing Risk
Structured billing platforms can make certain forms of invoice substitution harder to execute because the payment transaction may occur in an environment that already contains the customer’s account, vendor profile, invoice history, payment destination, and audit records.
A customer might receive an email notification but independently sign into the vendor’s known portal to view the invoice and outstanding balance.
That gives the business another source against which to compare the emailed request.
A platform may also provide:
- controlled vendor or customer accounts;
- authenticated logins;
- change histories;
- role-based access;
- payment-destination controls;
- invoice status;
- audit logs;
- MFA.
These features vary significantly between products. A billing portal is not automatically secure merely because it is a portal.
Billing Platform vs. PDF Invoice
| Factor | Billing Platform | PDF/Email Attachment |
| Invoice source | Can be retrieved from an established account | Arrives as a file in email |
| Payment destination | May already be stored by platform | Can appear directly in document |
| Change controls | May support roles, logs, or approval workflows | Often depends on manual business procedure |
| Verification | User can independently navigate to known portal | Recipient often relies heavily on email context |
| Audit trail | Platform-dependent but potentially available | Usually requires separate bookkeeping records |
| Account compromise risk | Still possible | Email account compromise can affect delivery |
| Spoofing risk | Fake login pages or messages remain possible | Fake or substituted attachments remain possible |
The safer behavior is not “trust portals.”
It is:
Navigate to the portal independently, authenticate normally, and compare the invoice there instead of relying exclusively on the email notification.
Why PDF Attachment Workflows Need Extra Care
A PDF is simply a document.
It can contain legitimate bank details or fraudulent ones. It may be attached to a genuine message or an impersonated one.
The accounts-payable risk arises when the document itself becomes the authority for changing the payment destination.
If yesterday’s vendor master says one bank account and today’s PDF says another, the PDF should not automatically overwrite the master.
The change should trigger independent verification.
Payment Links and QR Codes
An emailed payment link can be convenient when it leads to a billing system you already trust, but the appearance of a professional payment button does not authenticate its destination.
When practical, open your existing bookmark or manually navigate to the vendor’s known portal rather than relying exclusively on an emailed button.
The same caution applies to QR codes printed on invoices. A QR code is another method of navigating somewhere; its presence on a realistic-looking document does not establish that the destination is genuine.
If the portal supports MFA, enable it.
How to Train the One Person Who Pays the Bills
Small-business invoice security does not need to become a cybersecurity certification program.
The person paying bills needs several enforceable rules and permission to stop when those rules are triggered.
Teach these seven habits:
1. No payment-destination changes by email alone.
Email can initiate a request, but it cannot complete verification.
2. Every bank change gets an independent callback.
Use a number that existed before the request.
3. Urgency never cancels verification.
A same-day demand receives the same controls as a routine change.
4. Every invoice must correspond to a real business expense.
Match it to a purchase, quote, order, agreement, or recurring obligation.
5. High-risk changes receive additional approval where possible.
New beneficiaries and bank details deserve special handling.
6. Keep the vendor master current.
Staff need a trusted baseline against which to compare incoming instructions.
7. Report mistakes immediately.
Employees should know that hiding an error wastes time that the bank and business need for response.
This training works because it tells staff what to do, not merely what to fear.
A poster saying “Beware of phishing” leaves the bookkeeper making a judgment call under pressure.
A procedure saying “Changed beneficiary = hold + known-number callback + approval” gives them an action.
What to Say When the CEO Says “Pay It Now”
Security procedures often fail because employees believe hierarchy overrides process.
A bookkeeper may recognize an unusual request yet fear appearing unhelpful by challenging an owner, controller, executive, or important vendor.
The solution is to make verification organizational policy rather than personal suspicion.
A useful response is:
“We verify all new bank details before release. I’ll call the vendor using our existing contact and then process it.”
The employee is not saying:
“I think this email is fraudulent.”
They are saying:
“This payment request triggered the standard rule.”
Executives should reinforce the rule by following it themselves. If senior people regularly demand exceptions, staff will eventually learn that urgency outranks security.
Build a One-Page Payment-Change Policy
A small-business policy can fit on a single page.
It should state that:
- new bank accounts and beneficiaries require independent verification;
- verification cannot rely solely on the email requesting the change;
- callback telephone numbers must come from an independent trusted source;
- payment-destination changes require the designated approval level;
- verification must be documented;
- urgent requests cannot bypass the policy;
- suspicious changes must be escalated;
- fraudulent payments must be reported to the bank immediately.
The policy should also identify who may edit vendor payment records.
If the accounting system supports permissions, consider limiting beneficiary editing to people who actually need that capability.
New Vendor Onboarding
Good bank-detail verification starts before the first invoice.
For a new supplier:
- establish the legal or recognized business identity;
- collect the business and tax documentation appropriate to your process;
- identify a known commercial contact;
- independently establish reliable contact information;
- agree on the normal payment method;
- record the approved payment destination through an appropriate secure process;
- document the verification;
- explain that future payment-detail changes will require re-verification.
Do not treat the vendor master as a loose address book.
It is the baseline your staff will use later when a change request arrives.
Vendor Change Form
A simple structured change form can record:
- vendor name;
- date requested;
- reason for change;
- payment method being changed;
- effective date;
- independent callback source;
- representative who confirmed;
- internal approver;
- date vendor master was updated.
There is no need to reproduce complete banking credentials in every audit note. Store sensitive financial information only in systems and locations appropriate for that purpose.
Bank and Email Controls That Do Not Require Enterprise Software
Process is the foundation, but relatively basic banking and email features can add another layer.
Beneficiary Approval and User Roles
Some business-banking platforms allow one user to create a beneficiary while another user approves it, or one employee to initiate a payment while another releases it.
Availability varies by bank and account.
Ask your institution about:
- beneficiary approval;
- dual authorization;
- separate user roles;
- transaction limits;
- administrator controls.
Even a three-person company may be able to use these functions.
Daily Payment Limits
A transfer limit does not determine whether an invoice is legitimate.
It can, however, restrict how much can leave through a particular payment capability before an additional banking step is required.
Choose limits around normal operations rather than copying an arbitrary figure from another company.
If a temporary increase is necessary for an unusual payment, consider requiring additional approval for the increase.
Alerts
Depending on the institution and platform, useful alerts may include:
- beneficiary creation or modification;
- outgoing wire;
- large ACH transaction;
- unusual login;
- security-setting change.
Treat alerts as detection tools, not substitutes for approval.
Email Authentication
SPF, DKIM, and DMARC can help receiving email systems evaluate whether messages are authorized for a domain. The FTC recommends email-authentication technology as one component of business impersonation protection.
These tools are worth configuring correctly for your own domain.
But an accounts-payable employee should not be told that “authenticated email equals verified bank change.” A legitimate compromised mailbox can create a payment problem even when domain authentication behaves exactly as designed.
Prompt Reconciliation
Bank reconciliation is a detection control rather than a substitute for pre-payment verification.
Review settled transactions promptly and compare them with approved payment records.
Reconciliation can expose:
- unfamiliar beneficiaries;
- duplicate payments;
- unexpected transfers;
- incorrect amounts;
- transactions that were not properly recorded.
The earlier an unexplained transaction is identified, the sooner the business can contact its financial institution.
Common Invoice Fraud Mistakes
Most invoice-payment failures involve ordinary business habits, not sophisticated technical errors.
| Mistake | Risk | Better Approach |
| Trusting the sender display name | Display name is not proof of sender identity | Expand and inspect sender information |
| Assuming a familiar thread is safe | A real mailbox may be compromised | Verify payment changes independently |
| Replying “Is this really you?” | Response may go back to the compromised account | Use an independent communication channel |
| Calling the number on the changed invoice | Fraudulent instructions may supply fraudulent contact details | Use a previously trusted number |
| Accepting a bank change and paying immediately | No independent destination verification | Hold payment until callback is complete |
| Rushing because an executive asks | Urgency defeats normal controls | Apply policy regardless of seniority |
| Skipping approval because amount is small | Bad beneficiary may persist for later payments | Approve destination changes separately from amount |
| Treating perfect formatting as proof | Appearance can be copied | Verify transaction and payment destination |
| Waiting until tomorrow to call the bank | Delays recovery efforts | Report suspected fraud immediately |
| Leaving email account unsecured afterward | Compromise may still be active | Review account security and access |
| Buying complex tools without enforcing procedure | Technology cannot rescue an ignored workflow | Establish simple mandatory controls first |
The last mistake deserves attention.
Small businesses sometimes assume meaningful fraud prevention requires expensive enterprise security systems.
Useful technology can help, but a tool cannot compensate for a process that lets any employee replace a vendor’s bank account based on a single email.
Small-Business Invoice Verification Checklist
Use this checklist before releasing vendor payments:
- Confirm the vendor is expected.
- Confirm the invoice corresponds to a real purchase, service, contract, or recurring obligation.
- Inspect the sender domain rather than relying on the display name.
- Check the Reply-To when appropriate.
- Compare the amount with expected billing.
- Compare payment details with the vendor master.
- Treat every changed beneficiary or payment destination as high risk.
- Do not verify the change by replying to the same email.
- Retrieve a telephone number from an independent trusted source.
- Call a known vendor contact.
- Confirm that the payment destination actually changed.
- Record who confirmed the change and when.
- Obtain second approval where required.
- Update the vendor master only after verification.
- Use beneficiary controls and transaction alerts when your bank offers them.
- Reconcile payments promptly.
- Escalate unusual or urgent payment requests instead of rushing them.
- Contact the financial institution immediately after discovering a fraudulent payment.
- Preserve emails, invoices, and transaction records.
- Secure affected email accounts after suspected compromise.
- Report BEC through appropriate official channels, including IC3 when applicable.
Frequently Asked Questions
What is a fake invoice email scam?
A fake invoice email scam uses an invoice or payment request to persuade a business to send money it does not owe or send a genuine payment to the wrong destination. The invoice may be entirely fabricated, imitate a real vendor, or use genuine transaction information with fraudulent payment instructions.
How can I tell if a vendor invoice email is fake?
Check whether the vendor, amount, timing, goods or services, sender information, and payment destination match your existing records. An unexpected payment change is particularly important. No single visual clue proves an invoice is genuine or fraudulent.
Can a real vendor email account be hacked and used for invoice fraud?
Yes. BEC can involve compromised legitimate email accounts. That is why a familiar sender address or authentic-looking conversation should not, by itself, authorize a changed bank account.
What are the biggest invoice fraud red flags?
High-risk invoice fraud red flags include a new beneficiary, changed bank details, unusual payment method, unexplained currency or country change, mismatched Reply-To, unexpected invoice, request to bypass approval, and artificial urgency.
How should I verify a vendor’s new bank details?
Place the payment on hold and call a known vendor representative using independently stored contact information. Confirm the change itself and document the verification before updating your vendor master.
Why should I not call the number in the payment-change email?
Because the same party sending fraudulent instructions could also provide the phone number. Use a number from a previously verified vendor record, signed agreement, known contact, or official source obtained independently of the message.
What is a callback verification procedure?
A callback verification procedure is an out-of-band check in which the business contacts a known vendor representative through an independently trusted telephone number before accepting changed payment instructions.
Does a small business really need dual approval for payments?
Not every routine payment needs two people, but two-person approval is particularly useful for bank-account changes, new beneficiaries, new vendors, and higher-risk payments. Tiny companies can assign the bookkeeper to prepare a change and the owner to approve it.
What should I do immediately after sending money to a scammer?
Stop additional payments and contact the financial institution immediately. Explain the fraud and ask what recovery procedure applies to the payment method. Preserve the payment record and fraudulent communications, secure affected accounts, notify appropriate people, and report the incident where appropriate.
Can a bank reverse a fraudulent wire or ACH payment?
Do not assume it can. A bank may attempt recovery, but available procedures and outcomes depend on the payment rail and facts. Wire fraud may involve a recall request. ACH rules distinguish permissible reversals from other fraud-recovery mechanisms, so the originating bank should determine the appropriate approach.
Should I report business email compromise to the FBI?
Yes, FBI guidance directs BEC victims to report incidents through IC3. Contacting IC3 does not replace the urgent call to your bank after a fraudulent transfer.
Are PDF invoices less secure than billing-platform invoices?
A PDF is not inherently fraudulent or insecure. The weakness arises when an emailed document is allowed to change payment instructions without independent verification. A well-controlled billing portal may provide authenticated access, stored payment information, workflow controls, and audit history that reduce some substitution opportunities.
Can invoice portals still be spoofed or compromised?
Yes. A fraudulent message can point to an imitation login page, and genuine accounts can be compromised. Navigate through a known bookmark or independently entered portal address where possible and enable MFA when supported.
What controls can a one-person accounting team use?
Maintain a verified vendor master, independently call back bank changes, use beneficiary controls and alerts offered by the bank, maintain sensible transaction limits, enable strong MFA, and reconcile payments quickly.
Should every vendor payment change require independent verification?
As a strong small-business operating rule, every new payment destination or bank-account change should trigger independent verification. That keeps the control focused on the point at which legitimate vendor payments can be diverted.
Conclusion
The most effective invoice scams do not necessarily look suspicious. A fake invoice email scam may contain a polished document, familiar vendor name, realistic amount, convincing signature, or genuine email-thread history.
None of those things verifies where the money should go.
The strongest small-business rule is therefore straightforward: every changed bank account, beneficiary, or payment destination becomes a separate verification event. Stop the payment, use a trusted contact method that did not come from the change request, confirm the change itself, document the callback, obtain appropriate approval, and only then modify the vendor master.
A small company can apply that discipline without building an enterprise security department. An owner and bookkeeper can separate preparation from approval. A one-person business can use independent callbacks, bank controls, alerts, MFA, and prompt reconciliation.
If money is nevertheless sent to a fraudulent destination, contact the financial institution immediately, preserve the evidence, secure affected accounts, contact the genuine vendor, and report BEC through appropriate channels.
Billing portals and security tools can strengthen the process. They do not replace it.
The decisive control is a routine that employees actually follow whenever somebody asks the business to send money somewhere new.















