All posts

Invoice Fraud You're Missing: The Bank Detail Warning Signs

Most invoice fraud doesn't look like fraud. It looks like a routine email from a supplier saying their bank account changed. Here's how it actually happens and what catches it.

Google and Facebook once paid out over $100 million between them to a single fraudster. Not through a hack. Not through stolen credit cards. Through invoices.

A man named Evaldas Rimasauskas set up a fake company with a name almost identical to a hardware supplier both companies already worked with, then sent invoices that looked completely normal, from an email address that looked completely normal, requesting payment to a bank account that was not normal at all. Both companies paid. It took years before the fraud was uncovered.

That case is extreme in scale, but the method behind it is ordinary. It happens to small businesses every week, just with smaller numbers attached. According to the Association for Financial Professionals, 79% of organizations experienced payments fraud attacks or attempts in 2024, and vendor impersonation is now one of the most common forms it takes.

This kind of fraud is hard to catch precisely because it doesn’t look suspicious. The invoice has the right logo. The amount is reasonable. The email comes from someone you’ve corresponded with before. The only thing that’s actually wrong is a handful of digits in a bank account number, buried in a document your team is processing alongside forty others that day.

How This Fraud Actually Works

Most invoice fraud follows a pattern that’s simpler than people expect.

The setup. A fraudster identifies a real supplier your business already works with, often through a data breach, a compromised email account, or research on LinkedIn and your company website. They learn the supplier’s name, invoice format, and sometimes even the name of the person who normally sends invoices.

The request. At some point, an email arrives that looks like it’s from that supplier. It might say the company has switched banks. It might say the usual account is temporarily unavailable. It might just be a normal invoice, sent from a slightly altered email domain, with new payment details quietly included.

The payment. If nobody checks the new bank details against what the supplier used last time, the payment goes through. The money is gone within hours, often moved through several accounts before anyone notices.

The discovery. Weeks later, the real supplier follows up asking why they haven’t been paid. That’s usually the first moment anyone realizes something went wrong.

Research from Trustpair found that BEC attacks cost US businesses $2.77 billion in reported losses in 2024 alone, and the same source notes these attacks are increasingly built around detailed research into a target’s normal invoicing process, sometimes even spoofing a real vendor’s actual email format.

Why Smaller Businesses Are Not Safe From This

There’s a common assumption that this kind of fraud only targets large companies with big payments and big targets. The data doesn’t support that.

Smaller companies, those under 1,000 employees, face a 70% weekly probability of at least one BEC attack, and the average requested wire transfer in these attacks was $24,586 in early 2025. That's a meaningful amount of money for an SME, and it's a number specifically chosen to be large enough to matter but not so large that it triggers extra scrutiny.

Smaller finance teams are, if anything, more exposed. There’s often no dedicated fraud or security function. One person might handle supplier onboarding, invoice approval, and payment execution. A convincing email claiming urgency, “please process this today, our usual account is frozen”, can move straight through without a second check.

The Warning Signs That Actually Matter

Some red flags get repeated so often they’ve become background noise. It’s worth being specific about which ones actually predict fraud.

A request to change bank details, especially by email. This is the single most important thing to watch for. Legitimate suppliers do occasionally change banks, but a change arriving unprompted, via email, tied to an urgent payment, is the most common pattern behind large invoice fraud losses.

Slight variations in the sender’s email domain. supplier-invoices.com instead of supplierinvoices.com. An extra letter, a swapped domain extension, a lookalike character. These are easy to miss at a glance, especially on a phone screen.

Urgency language. “This needs to go out today.” “Our old account is closed as of this week.” Fraud attempts lean on urgency because it discourages the extra step of verifying the request through a separate channel.

A round number with no line item detail. Real invoices from an established supplier usually have consistent structure. An invoice that’s unusually vague, or a suspiciously round amount, is worth a second look.

An invoice number that’s out of sequence. If a supplier normally sends invoices numbered in a predictable pattern and one suddenly breaks that pattern, that’s a small but real signal.

None of these signs are proof on their own. Suppliers really do change banks sometimes. Invoices really are urgent occasionally. The problem is that fraud is built to look exactly like the ordinary version of these situations, which is why relying on a person to “notice something feels off” isn’t a reliable control.

Why Manual Verification Usually Fails

Most businesses already have some kind of policy that says bank detail changes need extra verification. In practice, that policy often exists on paper but doesn’t get followed consistently.

The reasons are predictable. The team is busy. The email looks legitimate. Calling the supplier to confirm feels excessive for a routine-seeming update. Abnormal Security, after studying vendor email compromise across more than 1,400 organizations, found that nearly half of all vendor scam emails triggered employee interaction, meaning employees opened, replied to, or forwarded the fraudulent message before anyone caught the issue.

This isn’t a training problem that can be solved by telling people to be more careful. It’s a structural problem. Manually cross-checking every bank detail change against historical records, for every supplier, every time, doesn’t happen consistently when someone is also processing forty other invoices that day.

What Actually Catches This

The businesses that avoid this kind of loss tend to have one thing in common: bank details are checked automatically, every time, against what that specific supplier used previously, without depending on someone remembering to do it.

This works differently than a manual policy. Instead of relying on a person to recall what a supplier’s account number was three months ago, or to notice a subtle change buried in a document, every incoming invoice gets checked against the supplier’s payment history automatically. If a supplier that has used the same bank account for two years suddenly shows a different one, that gets flagged before the invoice is approved, not after the money has already moved.

This doesn’t mean every bank change gets blocked. Suppliers legitimately switch banks sometimes, merge with other companies, or update account details for their own reasons. The point isn’t to stop every change. It’s to make sure a human actually looks at it and confirms it through a second channel, a phone call to a known number, not the one in the email, before a payment goes out.

What To Put in Place This Week

You don’t need a large fraud prevention program to meaningfully reduce this risk. A few specific practices go a long way:

Verify any bank detail change through a second channel. If an email says the account changed, call the supplier using a phone number you already have on file, not one provided in the email itself.

Flag first-time payments to a new account as high scrutiny, regardless of urgency. The urgency is often the point of the attack.

Keep a record of each supplier’s payment history. Even a simple log makes it possible to catch a change quickly, whether that’s done manually or automatically.

Don’t rely on one person’s memory as your control. If catching this depends on someone happening to remember what a bank account looked like months ago, it will eventually be missed.

Automate the check where you can. A system that compares every invoice’s bank details against the supplier’s own history removes the dependency on any one person noticing.

The Real Lesson From These Cases

What’s striking about most large invoice fraud cases, including the Google and Facebook incident, is how little sophistication was actually required. No hacking. No malware. Just a convincing invoice and a bank account that nobody double-checked.

That’s actually good news, in a way. This isn’t a threat that requires a large security budget or specialized expertise to defend against. It requires one consistent habit: never treat a bank detail change as routine, no matter how normal the email looks.

The invoices that cause the most damage are rarely the ones that look suspicious. They’re the ones that look exactly like every other invoice your team processes that day, except for a handful of digits nobody checked.