Invoice fraud is the family of scams where organizations are tricked into paying fraudulent invoices or redirecting legitimate payments to attacker-controlled accounts, spanning everything from bluff invoices for services never ordered to sophisticated vendor email compromise.
Key facts
- Two main forms with very different sophistication: bluff invoices at one end, and payment diversion via compromised or impersonated vendors at the other.
- The payment-diversion form is a business email compromise technique and the hardest to detect because the invoice and email thread are often genuine.
- Losses to email-borne payment fraud are reported in billions internationally, according to the FBI IC3 annual reports.
Bluff invoices
Mass-scale fake invoices for services never ordered, betting on sloppy accounts-payable processes and the assumption that a small charge will be paid rather than investigated. Common across Europe, and mostly a process problem: strict AP procedures, dual approval, and matching every invoice to a purchase order resolves the majority of it.
Payment diversion and vendor email compromise
The real threat. An attacker either compromises a legitimate supplier''s mailbox or impersonates it convincingly, waits for a live invoice thread, and injects new bank details mid-conversation. Every technical signal passes: real domain, real thread, real invoice, real relationship history. Only the behavior is wrong. This overlaps closely with pretexting and is a core BEC play.
Warning signs
- New bank details announced without prior conversation or a change on a call.
- Sudden urgency or unusually formal tone in a familiar thread.
- Lookalike sender domains one character off from the supplier''s real domain.
- Pressure to skip the usual verification (year-end, executive travel, "confidential" note).
How to defend
Two layers, together: AP procedures that verify every payment-detail change via a known channel (not by replying to the same email thread), dual approval on high-value payments, and matching invoices to purchase orders; and behavioral email security that catches the thread-hijack humans miss, because bank details never before discussed in a two-year relationship changing on a Friday afternoon is a signal.
How Sentaro helps
Sentaro''s Behavioral Defense flags payment-detail changes that break the relationship''s history, tone shifts mid-thread and the executive-timing patterns that classic vendor fraud follows. Message Defense catches lookalike supplier domains at first contact. The invoice may look legitimate; the deviation is what shows.