Invoice Fraud
What it is
A scam that inserts a fake or altered invoice into an organization's or individual's normal payment flow, so that a routine-looking bill diverts money to the fraudster.
How it works
Real-world examples
- •A long-standing supplier appears to email updated bank details before a scheduled payment; the details belong to the fraudster, and the next legitimate invoice pays them.
- •Small businesses receive official-looking "invoices" for directory listings or domain renewals that are actually solicitations, with the obligation implied rather than owed.
- •The Facebook and Google case saw more than 100 million dollars paid against forged invoices in the name of a real hardware supplier between 2013 and 2015.
- •A "toner pirate" phones an office, confirms the printer model, then sends an invoice for overpriced supplies that were never ordered, banking on the model detail to look genuine.
Ethical guidelines
- ●Submitting fake or altered invoices to obtain payment is fraud and forgery; there is no legitimate version.
- ●Disguising a solicitation as an invoice is deceptive even where a tiny-print disclaimer exists; the design intends the reader to mistake it for a bill.
- ●Organizations owe their suppliers and themselves verification controls proportionate to the payment, rather than paying on appearance to save time.
How to defend against it
- ►Confirm every change to a vendor's bank details by phone to a number you already hold, not one printed on the new invoice or in the email requesting the change.
- ►Match invoices to purchase orders and delivery records before paying, and require a second approver for new payees or changed banking details.
- ►Treat unexpected "renewal" or "listing" invoices as solicitations until proven otherwise; verify against your own records of what you actually ordered.
- ►Segregate duties so the person who approves a payment is not the person who can change payee details, forcing an attacker to defeat two people.
- ►If a fraudulent payment has gone out, contact your bank immediately to attempt a recall and report to the FBI at ic3.gov; wires reported quickly can sometimes be frozen.
From the Defense Playbook
Confirm any request that arrives through one channel (email, text, chat, a phone call) by reaching the supposed sender through a different channel you already trusted before the request existed.
When anyone contacts you claiming to be your bank, a government agency, a utility, or a company you deal with, hang up and call back on the number printed on your card, statement, or the organization's official website, never the number they gave you.
Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.
References
- Federal Bureau of Investigation, Internet Crime Complaint Center (2023). Business Email Compromise: The $50 Billion Scam (Public Service Announcement I-060923-PSA). FBI IC3 · linkAltered invoices and changed bank details as core mechanisms of business email compromise and its multibillion-dollar losses.
- Federal Trade Commission (2019). Fake invoices: A scam against your business. FTC Business Guidance · linkWarning about disguised-solicitation invoices and unordered-merchandise billing aimed at businesses.
Related Articles
Social Engineering: Why Smart People Fall for It
Social engineering does not target stupidity. It targets helpfulness, deference, and time pressure, which are the same habits that make people good at their jobs. Here is how the attacks are built and which procedures actually stop them.
The Disinformation Playbook: How Campaigns Are Built and Where They Break
Disinformation campaigns follow a recognizable sequence: seed, launder, amplify, and let real people carry it the rest of the way. A field guide to the stages, drawn from the research, with the defences that work at each one.