Every week, small business owners open their inboxes and find what looks like a routine invoice from a vendor they recognize. The logo looks right, the dollar amount is plausible, and the due date is close enough to create a quiet sense of urgency. A payment gets made, and the money disappears into an account the business owner has never heard of.
This is not a niche crime. It is one of the most financially damaging forms of fraud targeting businesses today, and the numbers behind it are sobering. Understanding how these scams work, what they look like, and why they keep succeeding is the first real step toward stopping them.
The Scale of the Problem Is Larger Than Most Realize

The FBI’s 2025 IC3 report logged 24,768 business email compromise complaints and $3.05 billion in reported losses, up from 21,442 complaints and $2.77 billion in 2024. These figures only capture reported incidents, and most fraud goes unreported due to embarrassment or uncertainty about where to turn.
Research from 2024 reveals that nearly half of all businesses have received fraudulent invoices, with an average of 13 attempts per year. Even more troubling, an average of nine of those attempts succeed, costing businesses approximately $133,000 each time.
Almost four in five companies dealt with attempted fraud in 2024, according to one report. For small businesses operating on tight margins, even a single successful fake invoice can be enough to destabilize payroll, delay supplier payments, or drain a month’s operating cash in minutes.
What a Fake Invoice Email Actually Looks Like

A criminal poses as a supplier the company already does business with, then sends an invoice or payment-update email that looks legitimate. The attack usually starts with a compromised email account or a domain that is one character off from the real one. Because the request appears to come from a known vendor, it bypasses the basic “is this someone we work with?” filter that catches most cold-pitch scams.
Sometimes the criminal gets into a real business email account and watches conversations before stepping in. Other times, they use a lookalike domain, a spoofed reply address, or a message that appears to come from someone your staff already knows.
Fraudulent invoices are sent to accounts payable departments for goods or services the business has not ordered. The amount is often set low enough that the accounts payable team may process the payment without verifying it. That deliberate calibration of the dollar amount is one of the most telling signs of a professional operation.
The Vendor Impersonation Technique

The fraudster typically requests a change to the vendor’s bank account details, routing payments to an account they control. This step is what makes vendor impersonation so effective: the victim is not being asked to do something unusual, just to update a bank account, which feels like routine admin.
FBI guidance notes that criminals may study compromised inboxes, create forwarding or deletion rules, and then impersonate the business, the vendor, or both in order to redirect payments. One common version starts with a message stating that a vendor has new banking instructions and wants the next payment sent to a different account.
In 2024, a construction company in Victoria, Australia, was defrauded of AU$900,000 after attackers compromised a supplier’s email account and inserted a fake invoice with altered bank details. The fraud was only discovered when the real supplier followed up about non-payment. That discovery lag is exactly what scammers count on.
The Shell Company Variant: Invoices from Nowhere

Rather than impersonating a real supplier, some schemes create an entirely fictitious company. The fraudster registers a shell company and submits invoices for goods never delivered or services never performed. This approach is common in industries where businesses deal with many vendors and payment workflows are decentralized.
Con artists send out fake invoices in hopes of tricking businesses into paying for services or products they never requested or received. Large corporations and small businesses alike lose billions each year to this scam. The Better Business Bureau’s Scam Tracker has received reports from business owners who got fake invoices for office supplies, domain hosting services, and web services.
The shell company approach relies on volume and invisibility. By targeting businesses with high invoice throughput, scammers bet that one fictitious bill will slip through a stack of legitimate ones without anyone checking the underlying purchase order.
Why Small Businesses Are Especially Vulnerable

These attacks don’t just impersonate brands, they often impersonate people inside an organization to redirect payments or steal sensitive data. While many believe that only big companies are targets, the truth is that small and mid-sized businesses are often the least protected and easiest to exploit.
According to a 2024 study by the Association of Certified Fraud Examiners (ACFE), businesses lose about 5% of their revenue to fraud each year. For very small businesses, this can be particularly devastating. A five percent revenue loss for a business pulling in $500,000 a year means $25,000 gone, with little realistic chance of recovery.
Small operations typically lack dedicated fraud teams, and their finance functions are often managed by one or two people. When the person who approves invoices is also the one receiving them, verification steps tend to collapse under the pressure of daily business.
How AI Is Making These Scams More Convincing

Fake invoice scams remain a pervasive threat, with researchers warning that threat actors are ramping up efforts and fine-tuning their techniques. HP Wolf Security’s threat insights report for Q1 2024 found email-based social engineering attacks are still getting past enterprise email security measures, with roughly one in eight email threats evading gateway security tools.
These attacks involve fraudsters impersonating trusted contacts, such as executives, suppliers, or internal staff, to trick employees into sending payments or confidential information. BEC scams have become increasingly sophisticated, often slipping past traditional email security filters and targeting finance and accounts payable teams.
Generative AI tools have made grammatically perfect fake invoices trivially easy to produce in any language. Scammers no longer need fluency in English, familiarity with business norms, or technical skills. The quality floor of a fake invoice email has risen sharply, and so has the difficulty of spotting one at a glance.
The Red Flags That Most People Miss

Key red flags include spoofed or lookalike sender domains, urgent or secretive language, unexpected payment requests, and newly changed bank account details that have not been verified through a separate channel. These are not dramatic warning signs. They tend to appear subtle and easy to rationalize when you’re busy.
Many invoice scams use social engineering to coax recipients into falling for schemes they might otherwise recognize. One widely used technique is to create a sense of urgency by pressuring the target to pay the invoice right away. A scammer might even threaten legal action if payment is not made immediately. If an invoice request demands payment on the spot, the likelihood of it being fraudulent is high.
Other indicators include misspellings or grammatical errors in the email or invoice text, the absence of a purchase order or corresponding documentation, and slight inconsistencies in vendor names, logos, or email domain addresses. Checking for these takes thirty seconds. Recovering from an overlooked red flag can take years.
What Happens After You Pay

Fourteen percent of BEC scam victims recover none of their financial losses. Funds transferred to fraudulent accounts move fast, often through multiple banks across different countries before anyone has a chance to flag the transaction.
If one of your employees accidentally pays a fraudulent invoice, your business may still be on the hook for the real invoice, effectively paying twice. Courts and insurers will determine whether your business exercised reasonable care in verifying payment instructions. If that standard wasn’t met, you are likely liable for every penny.
BEC-related fund transfers have been traced to financial institutions in over 140 countries. That global footprint is part of what makes recovery so difficult. By the time a fraud report is filed, the money has often crossed multiple jurisdictions and is effectively untraceable.
How Scammers Use Stolen Information to Compound the Damage

As the FTC reports, fake invoices can be a way of phishing for your business information in addition to tricking you out of money. The invoice itself is sometimes just a pretext. The real goal is to harvest credentials, bank details, or internal vendor data for a second, larger attack.
According to Hoxhunt’s threat analysts, it’s rarely about actually getting the invoice paid anymore. It’s more often about getting someone to click a link, call a scam number, or hand over credentials through a fake login page.
Scammers have been known to use a company’s own invoice documents, company logos, and non-public contact details to expand the fraud. The criminals then impersonate both the original target and their clients to reach other companies. One successful breach can seed a chain of related frauds affecting an entire supply network.
Practical Steps That Actually Reduce Your Risk

Developing strong internal controls is essential for detecting and preventing fake invoice scams. These controls include policies and procedures that govern how invoices are received, reviewed, and approved. Implementing a three-way matching system, comparing the invoice with the purchase order and the receiving report, can help identify discrepancies early.
One of the most effective defenses against invoice fraud is awareness. Employees across all departments, not just finance, should be educated about the risks and warning signs. Training should include how these scams work, what red flags to look for, and the proper channels for verifying payment requests.
Anyone dealing with invoices, payroll, vendor emails, or payment approvals should know that urgency, secrecy, and last-minute payment changes are warning signs. Give employees permission to pause and verify. Staff should never feel pressured to rush a payment or act on a request that feels off. A quick phone call can prevent a very expensive mistake.
The Takeaway

The FBI’s 2025 IC3 report logged 24,768 BEC complaints and $3.05 billion in reported losses, up from 21,442 complaints and $2.77 billion in 2024. Reported BEC complaints rose by roughly 16% year over year, while reported losses rose by about 10%. The trend is consistent and moving in one direction.
Fake invoice fraud works because it targets the most human part of running a business: trust. Trust in a vendor you’ve paid a dozen times before. Trust in an email that looks exactly like the last one. The scam doesn’t need to be sophisticated to succeed. It just needs to arrive at the right moment, when someone is busy and the process is loose.
The businesses that hold up best against this threat aren’t necessarily the most technologically advanced. They’re the ones that have built a habit of pausing to verify, no matter how familiar the invoice looks. That habit costs nothing and has saved more than a few businesses from a loss they would never have fully recovered from.
AI Disclaimer: This article was created with the assistance of AI tools and reviewed by a human editor.