Invoice Fraud
Pronunciation: IN-voys FRAWD
Definition
Invoice Fraud is the creation, alteration, substitution, or misuse of an invoice or payment instruction to obtain money, goods, credentials, or sensitive information through deception. It includes more than a false invoice because legitimate invoices can be redirected by changing bank, wallet, beneficiary, amount, tax, or contact details. Controls should authenticate changes through an independent channel, compare beneficiary history, separate approval duties, and preserve the original invoice and communication trail.
Overview
Invoice Fraud is the creation, alteration, substitution, or misuse of an invoice or payment instruction to obtain money, goods, credentials, or sensitive information through deception. The control exists to prevent deceptive or unauthorized transactions, reduce customer and merchant loss, and preserve evidence for recovery, dispute handling, and investigation. It includes more than a false invoice because legitimate invoices can be redirected by changing bank, wallet, beneficiary, amount, tax, or contact details. It should be interpreted alongside Beneficiary Name Check because the concepts can affect the same decision without representing the same control, event, or risk.
The workflow combines identity, device, behavior, communication, beneficiary, transaction, and historical signals before and after payment. High-risk changes or instructions should be verified through a trusted independent channel, and controls should not rely on information supplied inside the potentially compromised message or session. In this context, controls should authenticate changes through an independent channel, compare beneficiary history, separate approval duties, and preserve the original invoice and communication trail.
It should connect the term to Business Email Compromise (BEC) where that relationship changes access, transaction treatment, investigation, communication, or recovery.
Records should preserve the original request, account and device events, approvals, beneficiary changes, transaction identifiers, communications, authentication results, review notes, and recovery actions. Teams should connect related attempts without exposing unnecessary personal or credential data.
Useful measures include attempted and confirmed loss, prevented value, false-positive rate, review time, recovery rate, beneficiary-change exceptions, customer complaints, repeat attacks, and control-bypass findings.
The relationship with CEO Fraud should be documented where it affects residual risk or control ownership.
Operational review of Invoice Fraud should reconstruct the use of of an invoice or payment instruction to obtain money, goods, credentials, or sensitive information through deception using the identities, communications, devices, and transaction records available for the affected case. Investigators should separate confirmed facts from hypotheses about of an invoice, payment instruction to obtain money, and goods, preserve the original evidence, and document why the event was cleared, escalated, or treated as a loss. Containment, recovery, and customer communication for the Invoice fraud pattern should match the harm indicated by of an invoice, payment instruction to obtain money, and goods.
Key Takeaway
Controls should authenticate changes through an independent channel, compare beneficiary history, separate approval duties, and preserve the original invoice and communication trail.
Sources
- Business Email Compromise — FBI Internet Crime Complaint Center (2026-08-03)
- Recognize and Report Phishing — Cybersecurity and Infrastructure Security Agency (2026-08-03)
- Security and Privacy Controls for Information Systems and Organizations, SP 800-53 Rev. 5 — NIST (2026-08-03)