Fake invoices: how small businesses actually get hit
Invoice fraud is not a technology problem, which is why it keeps working on businesses that have good technology. It is a problem of a document arriving through a channel that carries no proof of who sent it, into a process designed to pay things promptly, at a moment when the person approving it has forty other things to do.
Three variants account for most of what actually reaches a small business, and they need different defences.
1. The changed bank details
The most expensive one. A real supplier relationship exists, real invoices have been paid before, and one day an invoice arrives that looks exactly like the previous ones except for the account number. Sometimes it is preceded by an email announcing that the supplier has "changed banks".
It usually starts with a compromised mailbox — the supplier's, not yours — which is why the message thread looks genuine, quotes real project details, and comes from the address you have always used. The invoice itself is often the supplier's own PDF with one field edited, which is exactly the case where a forensic check earns its keep: an edited field in an otherwise untouched file leaves a save layer behind it.
The defence is procedural and it is not optional: any change to payment details gets confirmed by voice, on a number from your own records, with a named person, before the next payment. No exceptions for urgency — urgency is the mechanism.
2. The invoice for something you never ordered
Directory listings, domain renewals, trademark "publication fees", office supplies, safety inspections. These are sent in volume to businesses that will not check, and they are engineered to survive a glance: a plausible amount, an official-looking layout, a due date close enough to create pressure, and sometimes a reference to a real registration your business genuinely has.
They work because approval is delegated. Someone who was not in the room when the service was — or was not — ordered sees a modest invoice with a supplier name that sounds like an authority, and pays it. The defence is a purchase-order rule: nothing gets paid that cannot be matched to something someone here asked for.
3. The entirely fabricated supplier
A company that does not exist, sometimes registered recently to give it a paper trail, invoicing for consulting or services that leave no physical trace. This one is more common inside businesses than outside them — it is the shape internal fraud usually takes — and it is caught by supplier onboarding rather than by document inspection: registry lookup, verified bank details, an address that is not a mailbox, and separation between whoever approves a new supplier and whoever approves payments.
A check short enough to survive real life
Any control that adds ten minutes per invoice will be abandoned within a fortnight. This one fits in about ninety seconds and is worth applying to anything above whatever threshold matters to you, and to every payment-details change regardless of amount.
- Does this match something we ordered? A purchase order, a signed quote, an email agreeing the work.
- Have the bank details changed since last time? If yes, stop and phone. If this is a first payment, verify the details independently before sending anything.
- Does the arithmetic close — line items, tax, total? Fabricated invoices get tax rounding wrong more often than you would expect.
- Is the supplier findable in a public register, at the address on the invoice, with a registration date that predates the relationship?
- What does the file say about itself? A supplier's billing system produces PDFs with a consistent Producer field month after month. An invoice from the same supplier that suddenly names a different tool, or carries a modification timestamp well after its creation, is worth a call before it is worth an argument.
What to do when one gets through
Speed is the whole game. Contact your bank immediately and ask for a recall — funds sitting in the receiving account can sometimes be frozen within hours, and almost never after a few days. Tell the real supplier, because their mailbox may be the compromised one and you will not be the only victim. Report it to the relevant national fraud body. And keep the original file exactly as it arrived, with its headers, rather than a printout: the file is the evidence, and re-saving it damages the very traces that show what happened.