Invoice Fraud: The Scam That Targets Your Accounting Team (Not Your IT)
Invoice fraud is when a scammer tricks your business into paying a fake or altered invoice — usually by impersonating a real vendor and quietly changing the bank account the money goes to. It rarely involves “hacking” anything. It targets the person who approves payments, not your firewall, and for most small businesses that person sits in accounting.
We got a message recently from someone in an accounting role at a growing company with no dedicated IT team. They weren’t worried about dramatic, movie-style hackers. They were worried about something quieter and far more common: the invoice that looks completely legitimate. That instinct is exactly right — and this article is the plain-English version of the answer we gave them.
What invoice fraud actually looks like
The version that drains small-business bank accounts is a type of scam the FBI calls Business Email Compromise (BEC). Here’s the usual play:
- A scammer gets into — or convincingly imitates — an email conversation between you and a real vendor.
- They wait. Sometimes for weeks. They read how your vendor writes, when invoices normally arrive, and who signs off on payments.
- When a real invoice is due, they send a follow-up: “Quick heads-up — we’ve updated our banking details. Please send this month’s payment to the new account below.”
- Same logo. Same signature. Same friendly tone. The only thing that changed is the account number.
- You pay. The money is gone, often within hours, and it’s extremely hard to claw back.
No malware. No password stolen from you. Just a believable email and a moment of trust.
Why the target is almost always accounting
Attackers aren’t after your IT team — they’re after the people who can move money. In a small business, that’s accounts payable, a bookkeeper, an office manager, or the owner themselves. These are capable, busy people who process dozens of legitimate invoices a week. That’s the vulnerability the scam is built around: it hides in a routine that’s supposed to run smoothly.
And here’s the part that catches companies off guard — the strongest defense has almost nothing to do with technology. It has to do with the process around approving a payment. Most small businesses have never written that process down, so it lives entirely in one person’s judgment on a hectic afternoon.
Three habits that stop most invoice fraud — no IT department required
1. Verify banking changes by phone. Every time.
Any email that changes where money goes — new bank, new account, new wire instructions — gets a phone call before you act on it. Call a number you already had on file, not the number in the email (that number rings the scammer). This one habit stops the majority of these attacks cold.
2. Slow down anything marked “urgent.”
Urgency is the scam. Fraudsters manufacture pressure — “the account’s overdue,” “we need this today,” “please handle before your boss gets back” — because urgency is what shuts down the double-check. Real vendors can wait a day. Treat “urgent + payment + email” as a reason to slow down, not speed up.
3. Make it a rule, not a reflex.
When “we always verify account changes by phone” is written company policy, nobody has to feel awkward being the person who questions a payment. It stops being a personal judgment call and becomes just how you do things. Write it down. Tell every person who touches money. Revisit it once a year.
A few more layers, if you want to go further
- Turn on multi-factor login for every email account — especially anyone in finance. Most BEC starts with one compromised inbox.
- Set a two-person rule for payments over a threshold you choose. A second set of eyes catches what a busy afternoon misses.
- Watch for look-alike email domains — @yourvendor-inc.com instead of @yourvendor.com. A quick habit of checking the actual address, not just the display name, goes a long way.
- Give your team permission to pause. The most expensive mistakes happen when someone senses something’s off but doesn’t feel they can slow a payment down.
Where the FTC Safeguards Rule fits in
If you’re an accounting firm, tax preparer, or CPA, this isn’t just good hygiene — it overlaps with a federal rule. The FTC treats those businesses as “financial institutions” under the Safeguards Rule, which expects protections like multi-factor login, a written security plan, and a named person accountable for security. The specific requirements scale with your size — smaller firms are exempt from some of the formal paperwork — so the honest question isn’t whether you have a binder somewhere, but whether you could actually demonstrate these protections if someone asked.
If that applies to you, our CPA & tax-season IT page walks through what year-round protection looks like, and our free FTC Safeguards self-assessment shows you where your firm stands in a few minutes.
What to do if you think you’ve already paid a fraudulent invoice
- Call your bank immediately and ask about a wire recall or reversal. Speed is everything — the first few hours matter most.
- Contact the real vendor by phone to confirm what’s real and what isn’t.
- Report it to the FBI’s Internet Crime Complaint Center at ic3.gov. They have a recovery process specifically for these wire frauds.
- Check whether an email account was compromised — reset passwords, review inbox rules, and turn on multi-factor login everywhere.
Frequently asked questions
What is the difference between invoice fraud and phishing?
Phishing is a broad attempt to trick anyone into clicking a link or handing over a password. Invoice fraud (a form of business email compromise) is more targeted — it impersonates a real vendor or executive to redirect a specific, legitimate payment. Invoice fraud is often the result of an earlier phishing success.
How much does invoice fraud cost small businesses?
Business email compromise is one of the costliest categories of cybercrime, with individual losses to small businesses frequently landing in the tens of thousands of dollars per incident — money that is very difficult to recover once wired.
Can antivirus software stop invoice fraud?
Not on its own. These scams usually contain no malicious file to detect — just a convincing email. That’s why the defense is mostly process and verification, backed by basics like multi-factor login, rather than any single piece of software.
We’re a small team without IT staff. Where do we even start?
Start with the phone-verification habit for banking changes — it’s free and stops most attacks. Then turn on multi-factor login for email. Those two steps alone put you ahead of most small businesses. From there, a short conversation with an IT partner can close the rest of the gaps.
The bottom line
The person most likely to protect your company from a costly scam isn’t in IT — it’s whoever pauses over an invoice and thinks, “…is this real?” That instinct is worth building a process around.
If your team has ever had that moment, we’re happy to help you turn it into a simple, repeatable process — no jargon, no scare tactics. Grab 15 minutes with us and we’ll walk through where the real risk hides for a business your size.








