Invoice Fraud

Invoice fraud is the family of scams where organizations are tricked into paying fraudulent invoices or redirecting legitimate payments to attacker-controlled accounts.

Invoice fraud is the family of scams where organizations are tricked into paying fraudulent invoices or redirecting legitimate payments to attacker-controlled accounts, spanning everything from bluff invoices for services never ordered to sophisticated vendor email compromise.

Key facts

Bluff invoices

Mass-scale fake invoices for services never ordered, betting on sloppy accounts-payable processes and the assumption that a small charge will be paid rather than investigated. Common across Europe, and mostly a process problem: strict AP procedures, dual approval, and matching every invoice to a purchase order resolves the majority of it.

Payment diversion and vendor email compromise

The real threat. An attacker either compromises a legitimate supplier''s mailbox or impersonates it convincingly, waits for a live invoice thread, and injects new bank details mid-conversation. Every technical signal passes: real domain, real thread, real invoice, real relationship history. Only the behavior is wrong. This overlaps closely with pretexting and is a core BEC play.

Warning signs

How to defend

Two layers, together: AP procedures that verify every payment-detail change via a known channel (not by replying to the same email thread), dual approval on high-value payments, and matching invoices to purchase orders; and behavioral email security that catches the thread-hijack humans miss, because bank details never before discussed in a two-year relationship changing on a Friday afternoon is a signal.

How Sentaro helps

Sentaro''s Behavioral Intelligence flags payment-detail changes that break the relationship''s history, tone shifts mid-thread and the executive-timing patterns that classic vendor fraud follows. Domain Intelligence catches lookalike supplier domains at first contact. The invoice may look legitimate; the deviation is what shows.

Frequently asked questions

What is the difference between a bluff invoice and invoice fraud via email compromise?

A bluff invoice is a mass-scale fake for a service never ordered, defeated by AP hygiene. Email-compromise invoice fraud is targeted, uses the real supplier relationship and thread, and requires behavioral detection to catch because everything except the account number is real.

How do attackers change vendor bank details?

By compromising the supplier''s mailbox or convincingly imitating it (lookalike domain, reply-to trick), then injecting new details in an active or newly initiated invoice thread. The attacker often reads existing history first, so wording and references feel natural.

What should we do if we already paid a fraudulent invoice?

Contact your bank immediately to attempt recall, report to police and (in the US) the FBI''s IC3, preserve the emails and any attachments as evidence, and check whether the supplier mailbox or your own is still compromised before further payments go out.

Can email security stop invoice fraud?

For the diversion form, yes: behavioral detection catches breaks in the relationship''s history that content filters cannot see. For bluff invoices, no directly; that is an AP process problem, and the fix lives in finance, not email.