Invoice fraud is one of the few cyber crimes that doesn't need malware, a breached firewall, or a stolen password to succeed. It needs exactly one thing: someone in your accounts payable process who believes a payment request that looks routine. An attacker sends an invoice that appears to come from a vendor you actually use — or quietly asks you to "update" a real vendor's bank details — and your own team wires the money out.
Invoice fraud is a form of business email compromise (BEC), the category the FBI's Internet Crime Complaint Center (IC3) has ranked among the costliest cyber crimes for years, with reported losses running into the billions of dollars annually. And it disproportionately hits small businesses, because small firms process payments with fewer people, fewer approvals, and more trust.
How invoice fraud actually works
Nearly every invoice fraud we've seen or studied follows one of three patterns:
- The fake invoice. An attacker researches your business — your website, LinkedIn, public contracts — and sends an invoice from a supplier you plausibly use: office products, IT services, a trade subcontractor. The amount is deliberately unremarkable, sized to fall under whatever approval threshold a firm your size probably has.
- Vendor impersonation (the changed bank details). The attacker poses as a real vendor — often from a lookalike domain (yourvendor-inc.com instead of yourvendorinc.com) — and asks your bookkeeper to update payment details "for all future invoices." The next legitimate invoice you receive gets paid straight to the attacker's account.
- The compromised mailbox. The most dangerous version. The attacker phishes their way into a real email account — yours, or a vendor's — watches actual invoice conversations for weeks, then inserts a payment-redirect request into a genuine email thread. Every detail checks out, because it's a real thread with a real vendor about a real invoice.
Why small businesses: a 20-person firm rarely has segregation of duties in accounts payable. The person who receives the invoice often approves it and pays it. Attackers know this — it's why they impersonate vendors of small firms rather than attacking a bank's payment systems.
The 7 controls that stop it
1. Verify every bank-detail change by phone — using a number you already have
This single control defeats the majority of invoice fraud. Any request to change a vendor's payment details gets confirmed by calling the vendor at the phone number in your existing records — never a number in the email requesting the change (attackers helpfully include their own). Make it policy, in writing, with zero exceptions, including for requests that appear to come from your own executives.
2. Require two people for payments above a threshold
One person initiates, a different person approves. Set the threshold low enough to matter for your business — for many small firms that's $2,500 to $5,000. Fraudsters size their fake invoices to slip under approval limits, so a second set of eyes on anything unusual is the point, not bureaucracy.
3. Turn on multi-factor authentication for email — everyone, no exceptions
The compromised-mailbox variant starts with a stolen email password. Multi-factor authentication (MFA — a second confirmation step, like an authenticator app prompt) blocks the overwhelming majority of account-takeover attempts. If your firm runs Microsoft 365, this is a configuration task, not a purchase. We covered the broader account-takeover playbook in our guide to preventing business email compromise.
4. Set up email authentication (SPF, DKIM, DMARC) on your domain
These are DNS records that tell receiving mail systems which servers may legitimately send email as your domain. Configured correctly, they make it dramatically harder for an attacker to spoof you to your customers — and a DMARC policy set to quarantine or reject stops much of the lookalike traffic before a human ever sees it. Ask whoever manages your email to confirm all three are in place and enforcing.
5. Flag external email, and watch for lookalike domains
A simple "[External]" banner on mail from outside your organization gives staff a fighting chance against a spoofed internal request. Pair it with training that teaches the one-character-off domain trick — rn for m, added hyphens, .co for .com. Attackers register lookalike domains precisely because busy people read past them.
6. Train the people who touch money — specifically
Generic phishing training helps, but invoice fraud targets a small group: bookkeepers, office managers, controllers, and owners. Those people need scenario-specific training — fake invoices, bank-change requests, urgent wire requests from the "CEO" — plus explicit permission to slow down and verify, even when a request claims to be urgent. That urgency is the tell: pressure to pay today is how fraudsters beat verification. Our security awareness training builds these scenarios into simulations rather than slideware.
7. Reconcile fast, and know the recall window
Reconcile bank activity against approved invoices at least weekly — daily is better. Speed matters because recovery has a clock: wire transfers can sometimes be recalled if your bank and the FBI are notified within the first 24–72 hours, before the money is moved out of the receiving account. After that window, recovery rates fall off sharply.
If you've just been hit: call your bank immediately and request a recall/hold on the transfer, file a report at ic3.gov (the FBI's Internet Crime Complaint Center) the same day, preserve every email involved, and reset credentials + review mailbox rules for any account that touched the thread — attackers plant auto-forwarding rules to keep watching. Then call your insurance carrier; many cyber policies cover funds-transfer fraud, but notification deadlines are strict.
What this looks like with a managed IT partner
Every control above is either a policy decision or a configuration task in systems most small businesses already own — Microsoft 365, your DNS, your accounting workflow. None of it requires new software. What it does require is someone who owns the setup: enforcing MFA without breaking workflows, publishing DMARC without losing legitimate mail, wiring the external-sender banner, and running realistic training on a schedule.
That's the work a managed IT partner does as routine hygiene, and it's where our cybersecurity practice starts with new clients: close the doors invoice fraud walks through before spending a dollar on anything more exotic. Firms in regulated industries — from law firms handling client trust funds to medical practices and contractors — face the same three fraud patterns with higher stakes.