Business Operations

How to reduce the risk of invoice fraud

A stressed businessman reviews a fake invoice at a desk piled with overdue documents while a hooded figure rifles through files behind him

A convincing invoice does not prove that the payment details are genuine. Criminals can copy a supplier's layout, change the bank account and send the document at a time when staff expect a bill.

The invoice may arrive on paper, by email or through a compromised account. The safest response is a payment process that checks unusual requests before money leaves the business.

How criminals make an invoice look genuine

Old invoices, public websites, email signatures and stolen mailboxes can reveal supplier names, contact details and billing patterns. A criminal can use that information to create a fake invoice or alter a real one.

The most important warning is a change to bank details. The message may claim that the supplier has moved banks, opened a new account or needs an urgent payment. It may look exactly like previous correspondence.

Why busy periods increase the risk

Invoice fraud works when a familiar process becomes automatic. During month end, while staff are on leave, or during a busy project, the person entering a payment may not have time to question a small change.

Pressure can also come from inside the fake message. Requests for secrecy, an unusual deadline or instructions not to contact the supplier should trigger a pause.

Verify bank detail changes separately

Call the supplier using a phone number from a trusted record, such as the existing supplier file or an earlier verified contract. Do not use the phone number printed on the invoice or included in the message that requested the change.

Read the new account details back and record who confirmed them. For important suppliers, nominate the people who are allowed to request and approve changes.

Separate entry from approval

A second person should approve large or unusual payments and any change to supplier bank details. The approval should check the invoice, the supplier record and the separate confirmation.

Choose approval levels that suit the business. Make sure the process still works when an approver is away. Shared passwords or informal approval by text can undo the benefit of having two people involved.

Protect the information used to create fakes

Shred financial records before disposal and secure physical mail. Limit access to supplier files and accounting systems. Protect email and finance accounts with strong, unique passwords and a second sign-in check.

Remove access promptly when a staff member leaves. If criminals can read a real mailbox, they can learn the timing and wording of genuine invoices.

Use digital controls carefully

Accounting and payment systems can keep an audit trail, restrict who can change supplier records and require approval. Turn those controls on and review them.

A digital system is not safe merely because it is online. Compromised accounts, excessive permissions and shared logins can still allow fraud.

If a payment has already been sent

Contact the bank immediately and ask about its fraud and transfer recall process. Preserve the invoice, email, call details and payment records. Follow your insurer's instructions and report the incident through ReportCyber. Emergency response: call 000 if anyone is in immediate danger; otherwise follow current ReportCyber/police guidance. Tell your IT provider if an email account may be involved.

Fast action does not guarantee recovery, but delay can reduce the available options.

Put the checks beside the payment process

Download the JCPIT Invoice Fraud Checklist and keep it with the steps staff use to add suppliers and approve payments. It gives staff a short verification process and records who confirmed a change. For printing, download the complete two-page ink-light copy.

If you also need the email and account controls checked, contact JCPIT for a payment process security review. We will focus on the access that could be used to redirect an invoice.

Jake
Jake
JCPIT Support — Keeping IT Simple.
← Previous Article
Why your business Wi-Fi password is not enough
Next Article →
Five warning signs that deserve a security check