How do you detect a fraudulent invoice?

A fraudulent invoice is detected by its context, not its appearance: modern invoice fraud reuses genuine invoices with only the payment details altered. The reliable red flags are a bank-detail change accompanying the invoice, unusual urgency or confidentiality pressure, a subtly altered sender domain, a new contact person mid-relationship, and remittance details pointing to a bank or country that does not match the supplier’s history.

Also known as: fraudulent invoice detection · fake invoice scam · invoice verification · bank detail change request

The red flags, ranked

First and above all: any change to payment details. Legitimate suppliers change banks rarely; fraudsters change them always. Second: pressure — urgency, threats of supply disruption, or requests for confidentiality that discourage verification. Third: sender anomalies — look-alike domains (supplier-inc.com vs supplierinc.com), replies that drop or add recipients, or a new "accounts manager" you have never dealt with. Fourth: payment anomalies — a first-time bank, a personal-account format, a different country, or amounts just under an approval threshold. Any one flag warrants verification; two or more warrant stopping the payment run.

The verification protocol that works

Call the supplier on a number you already had — never one printed on the suspicious invoice or email — and confirm the change with a person you know. Require dual approval for any detail change, enforced in the ERP rather than by convention. Then automate the discipline: manual call-backs decay under AP workload, which is why platforms like Trustmi verify vendor identity and monitor detail changes continuously, flagging the anomalous payment before execution instead of relying on every clerk having a suspicious day.

Sources: FBI IC3 — 2025 Internet Crime Report

// In the Cyberdis portfolio

Trustmi verifies vendors and bank-detail changes continuously — distributed by Cyberdis.

// FAQ

Common questions.

What is the single biggest invoice fraud red flag?

A bank-detail change request, in any form. It is the mechanism of nearly all high-loss invoice fraud: the invoice is real, the debt is real, and only the destination account changed. Verify every change on a known channel before paying.

Can a fraudulent invoice look completely genuine?

Yes — in compromised-mailbox attacks it IS genuine, sent from the supplier’s real email inside a real thread, with only the remittance details altered. That is why visual inspection fails and verification of the change itself is the control that matters.

Should small businesses worry about invoice fraud?

Yes. Attackers target payment processes, not company size, and smaller finance teams have fewer verification layers. The FBI’s IC3 data averages roughly 123,000 dollars of loss per BEC incident — existential money for a small firm.

Related explainers: What is vendor impersonation fraud?What is payment fraud?Can you recover money after payment fraud?

Weighing approaches? Dedicated payment fraud prevention vs ERP controls and email security