Skip to content
ScamiroScamiro
Fraud Prevention9 min read1,259 words

Checking an invoice before you pay it

It rides on a real transaction between two parties who genuinely owe each other money, with one field changed — which is why it survives the scrutiny that stops other frauds.

ScamiroScamiro
An invoicing dashboard producing documents with a consistent format month to month
An invoicing dashboard producing documents with a consistent format month to month

Short answer

Invoice fraud usually alters one field on a genuine invoice: the bank details. Verify any change of payment details by voice on a number you already held, before paying — never a number from the invoice or email. Then check the sender's domain character by character and match the invoice to an order rather than to your expectation.

On this page
  1. What does invoice fraud look like?
  2. What to check on any invoice
  3. The bank details rule
  4. Where does the compromise usually start?
  5. For a business, not just a person
  6. If a payment has gone
  7. The short version

The invoice is from a supplier you use. The amount matches roughly what you expected, the reference is right, the layout is theirs. One line differs from every previous invoice they have sent: the bank details.

Invoice fraud is the alteration or fabrication of a bill so that payment goes to an account the attacker controls, and it works because everything else about the document is correct. It does not rely on a fake company or an invented service — it usually rides on a real transaction, between two parties who genuinely owe each other money, with only the destination changed. That is why it survives scrutiny that stops other frauds.

What does invoice fraud look like?

The intercepted invoice. An attacker with access to one side's email — a compromised mailbox, or a forwarding rule nobody noticed — waits for a genuine invoice, alters the bank details, and forwards it on. The document is real. Only one field is not.

The impersonated supplier. An email from a lookalike domain announcing new banking details, often citing an audit, a merger or a fraud check. No invoice yet — the groundwork is laid so the next real one goes to the new account.

The invented service. A plausible invoice for something ordinary: a directory listing, a domain renewal, an office supply. Small enough to be approved without a query, and repeated across hundreds of businesses.

The clever part is not the document. It is that the money is genuinely owed, so every instinct about whether the transaction makes sense agrees that it does.

What to check on any invoice

Seven checks catch almost every form of invoice fraud, and the first is worth more than the other six.

  1. Bank details against a record you already hold. Not against the invoice, not against an email — against details you verified previously and stored. A change is the single highest-risk event in the entire process.
  2. The sender's domain, character by character. Lookalike domains use a swapped letter, an added hyphen, a different suffix. In a threaded conversation the display name is what you see and the address is what matters.
  3. Whether you ordered it. Match against a purchase order or a person who can confirm they requested it.
  4. The amount against the agreement, not against your expectation. Expectations drift; agreements do not.
  5. The invoice number. A supplier's numbering is sequential. One wildly out of sequence, or a repeat of a number you have already paid, is worth a question.
  6. The tax details. A registration number is verifiable in most countries, and a fabricated invoice frequently has one that does not check out.
  7. The due date and any urgency. Genuine terms are stated calmly. Pressure that a payment must go today is a technique, not a business practice.
SignalGenuineConcerning
Bank detailsMatch your recordChanged, with an explanation
DomainExact matchOne character different
UrgencyStated termsMust be paid today
Contact for queriesKnown numberNew number on the invoice
AmountMatches agreementSlightly higher, plausibly

The bank details rule

If one thing survives from this article, it should be this.

A change of bank details is verified by voice, on a number you already had, before any payment. Not the number on the invoice, not one in the email signature, not a number given in a reply — the number you have used before, from your own records.

Two supporting practices make it workable:

Confirm the change, not the invoice. Ask specifically: "Have your bank details changed?" A person who did not change them will say so immediately, and the conversation is thirty seconds.

Treat the first payment to new details as a test. A small amount, confirmed received by phone, before the full sum. It costs a day and it is the difference between a small loss and a total one.

Businesses issuing invoices can help their customers here: keeping details stable, stating on every document that details never change by email, and providing a known contact for verification. Invoicing tools such as Ordava produce consistent documents with a stable format, and consistency is itself a security property — a customer who receives the same layout every month notices the month it differs.

Where does the compromise usually start?

Understanding this changes what you protect.

Most invoice fraud begins with access to a mailbox — yours or your supplier's — rather than with a technical attack on payments. From there, the attacker reads the correspondence, learns the relationship, waits for the right moment, and intervenes with the tone and detail of someone who belongs.

Four consequences:

  • Email forwarding rules are the classic sign. An attacker sets one so replies are hidden from the real owner. Check yours periodically; they survive password changes.
  • The conversation may be entirely real up to a point. Earlier messages in the thread are genuine, which is why the fraudulent one reads correctly.
  • Both parties may be uncompromised in the lookalike-domain version, where no account was accessed at all — only a similar address registered.
  • Two-factor authentication on email is the highest-value control in this whole area, because it protects the channel the fraud runs through.

For a business, not just a person

Four controls reduce invoice fraud for an organisation, roughly in order of effect per unit of effort.

Two people for any change to payment details. The single most effective measure, because it does not depend on anyone spotting anything.

A supplier record that is the source of truth, maintained separately from correspondence, and consulted rather than the invoice.

A payment threshold requiring a second approval, set low enough to catch the amounts that actually get through.

Training that names the specific scenario. Not general awareness — the exact situation of an invoice arriving with changed details, and exactly what to do.

The first control is worth more than the others combined and it is a process change rather than a purchase.

If a payment has gone

If a payment has gone to invoice fraud, speed is everything, because the funds are moved on quickly.

  1. Call your bank immediately and ask them to attempt recall. Within hours there is a real chance; within days there is much less.
  2. Contact the real supplier on a known number, so they learn their correspondence may be compromised.
  3. Check your own mailbox for forwarding rules and unfamiliar sessions, and change the password with two-factor enabled.
  4. Report it to the national fraud service and, if a lookalike domain was used, to the registrar.
  5. Tell your finance team what happened. Repeat attempts follow, and the second one arrives knowing the first worked.

More on impersonation in impersonation, payment safety in online scams, and the selling side in shopping scams. Action Fraud covers reporting business fraud.

The short version

Invoice fraud rides on real transactions, which is why the document survives inspection. Almost always, only the bank details differ.

Verify any change of details by voice on a number you already had, before paying anything. Check the sender's domain character by character, match the invoice to an order rather than to your expectation, and require two people to approve a change of payment details — that last one is a process change and it catches what individual vigilance does not.

Frequently asked questions

What is the single most important check?
Bank details against a record you already hold, verified by voice on a number you had before. A change of payment details is the highest-risk event in the whole process, and it is the field that fraud almost always alters.
How does the attacker know about the transaction?
Usually through access to a mailbox — yours or the supplier's — where they read the correspondence and wait for the right moment. That is why earlier messages in the thread are genuine and the fraudulent one reads correctly.
What if the supplier says their details changed?
Confirm it by calling them on a number from your own records and asking specifically whether the details changed. Then send a small test payment and confirm receipt by phone before the full amount.
What control works best for a business?
Requiring two people to approve any change to payment details. It is a process change rather than a purchase, and it works without depending on anyone spotting anything unusual.

Sources

  1. Reporting fraud and cyber crimeAction Fraud
  2. Business email compromise: defending your organisationUK National Cyber Security Centre
  3. Ordava: Invoice & Order MakerTecno Blocks
Scamiro

Published by

Scamiro

Practical online safety guides covering scams, phishing, suspicious links, fraudulent websites, impersonation, social media scams, and digital fraud.

About the publication

Related reading

Keep going

Browse everything
A billing dashboard showing plans and charges clearly, the opposite of a hidden cancellation flow

Fraud Prevention9 min read

The subscription trap behind a free trial

Sign-up optimised to four taps, cancellation left deliberately tiring, every abandoned step measured. Where you actually cancel, and the order that works.

الاشتراكات / التجارب المجانية