Checking an invoice before you pay it
It rides on a real transaction between two parties who genuinely owe each other money, with one field changed — which is why it survives the scrutiny that stops other frauds.

Short answer
Invoice fraud usually alters one field on a genuine invoice: the bank details. Verify any change of payment details by voice on a number you already held, before paying — never a number from the invoice or email. Then check the sender's domain character by character and match the invoice to an order rather than to your expectation.
On this page
The invoice is from a supplier you use. The amount matches roughly what you expected, the reference is right, the layout is theirs. One line differs from every previous invoice they have sent: the bank details.
Invoice fraud is the alteration or fabrication of a bill so that payment goes to an account the attacker controls, and it works because everything else about the document is correct. It does not rely on a fake company or an invented service — it usually rides on a real transaction, between two parties who genuinely owe each other money, with only the destination changed. That is why it survives scrutiny that stops other frauds.
What does invoice fraud look like?
The intercepted invoice. An attacker with access to one side's email — a compromised mailbox, or a forwarding rule nobody noticed — waits for a genuine invoice, alters the bank details, and forwards it on. The document is real. Only one field is not.
The impersonated supplier. An email from a lookalike domain announcing new banking details, often citing an audit, a merger or a fraud check. No invoice yet — the groundwork is laid so the next real one goes to the new account.
The invented service. A plausible invoice for something ordinary: a directory listing, a domain renewal, an office supply. Small enough to be approved without a query, and repeated across hundreds of businesses.
The clever part is not the document. It is that the money is genuinely owed, so every instinct about whether the transaction makes sense agrees that it does.
What to check on any invoice
Seven checks catch almost every form of invoice fraud, and the first is worth more than the other six.
- Bank details against a record you already hold. Not against the invoice, not against an email — against details you verified previously and stored. A change is the single highest-risk event in the entire process.
- The sender's domain, character by character. Lookalike domains use a swapped letter, an added hyphen, a different suffix. In a threaded conversation the display name is what you see and the address is what matters.
- Whether you ordered it. Match against a purchase order or a person who can confirm they requested it.
- The amount against the agreement, not against your expectation. Expectations drift; agreements do not.
- The invoice number. A supplier's numbering is sequential. One wildly out of sequence, or a repeat of a number you have already paid, is worth a question.
- The tax details. A registration number is verifiable in most countries, and a fabricated invoice frequently has one that does not check out.
- The due date and any urgency. Genuine terms are stated calmly. Pressure that a payment must go today is a technique, not a business practice.
| Signal | Genuine | Concerning |
|---|---|---|
| Bank details | Match your record | Changed, with an explanation |
| Domain | Exact match | One character different |
| Urgency | Stated terms | Must be paid today |
| Contact for queries | Known number | New number on the invoice |
| Amount | Matches agreement | Slightly higher, plausibly |
The bank details rule
If one thing survives from this article, it should be this.
A change of bank details is verified by voice, on a number you already had, before any payment. Not the number on the invoice, not one in the email signature, not a number given in a reply — the number you have used before, from your own records.
Two supporting practices make it workable:
Confirm the change, not the invoice. Ask specifically: "Have your bank details changed?" A person who did not change them will say so immediately, and the conversation is thirty seconds.
Treat the first payment to new details as a test. A small amount, confirmed received by phone, before the full sum. It costs a day and it is the difference between a small loss and a total one.
Businesses issuing invoices can help their customers here: keeping details stable, stating on every document that details never change by email, and providing a known contact for verification. Invoicing tools such as Ordava produce consistent documents with a stable format, and consistency is itself a security property — a customer who receives the same layout every month notices the month it differs.
Where does the compromise usually start?
Understanding this changes what you protect.
Most invoice fraud begins with access to a mailbox — yours or your supplier's — rather than with a technical attack on payments. From there, the attacker reads the correspondence, learns the relationship, waits for the right moment, and intervenes with the tone and detail of someone who belongs.
Four consequences:
- Email forwarding rules are the classic sign. An attacker sets one so replies are hidden from the real owner. Check yours periodically; they survive password changes.
- The conversation may be entirely real up to a point. Earlier messages in the thread are genuine, which is why the fraudulent one reads correctly.
- Both parties may be uncompromised in the lookalike-domain version, where no account was accessed at all — only a similar address registered.
- Two-factor authentication on email is the highest-value control in this whole area, because it protects the channel the fraud runs through.
For a business, not just a person
Four controls reduce invoice fraud for an organisation, roughly in order of effect per unit of effort.
Two people for any change to payment details. The single most effective measure, because it does not depend on anyone spotting anything.
A supplier record that is the source of truth, maintained separately from correspondence, and consulted rather than the invoice.
A payment threshold requiring a second approval, set low enough to catch the amounts that actually get through.
Training that names the specific scenario. Not general awareness — the exact situation of an invoice arriving with changed details, and exactly what to do.
The first control is worth more than the others combined and it is a process change rather than a purchase.
If a payment has gone
If a payment has gone to invoice fraud, speed is everything, because the funds are moved on quickly.
- Call your bank immediately and ask them to attempt recall. Within hours there is a real chance; within days there is much less.
- Contact the real supplier on a known number, so they learn their correspondence may be compromised.
- Check your own mailbox for forwarding rules and unfamiliar sessions, and change the password with two-factor enabled.
- Report it to the national fraud service and, if a lookalike domain was used, to the registrar.
- Tell your finance team what happened. Repeat attempts follow, and the second one arrives knowing the first worked.
More on impersonation in impersonation, payment safety in online scams, and the selling side in shopping scams. Action Fraud covers reporting business fraud.
The short version
Invoice fraud rides on real transactions, which is why the document survives inspection. Almost always, only the bank details differ.
Verify any change of details by voice on a number you already had, before paying anything. Check the sender's domain character by character, match the invoice to an order rather than to your expectation, and require two people to approve a change of payment details — that last one is a process change and it catches what individual vigilance does not.
Frequently asked questions
- What is the single most important check?
- Bank details against a record you already hold, verified by voice on a number you had before. A change of payment details is the highest-risk event in the whole process, and it is the field that fraud almost always alters.
- How does the attacker know about the transaction?
- Usually through access to a mailbox — yours or the supplier's — where they read the correspondence and wait for the right moment. That is why earlier messages in the thread are genuine and the fraudulent one reads correctly.
- What if the supplier says their details changed?
- Confirm it by calling them on a number from your own records and asking specifically whether the details changed. Then send a small test payment and confirm receipt by phone before the full amount.
- What control works best for a business?
- Requiring two people to approve any change to payment details. It is a process change rather than a purchase, and it works without depending on anyone spotting anything unusual.
Sources
- Reporting fraud and cyber crime — Action Fraud
- Business email compromise: defending your organisation — UK National Cyber Security Centre
- Ordava: Invoice & Order Maker — Tecno Blocks
Scamiro
Practical online safety guides covering scams, phishing, suspicious links, fraudulent websites, impersonation, social media scams, and digital fraud.
About the publication