The Fake Invoice Scam That's Costing Businesses Thousands

Imagine: An invoice arrives from a vendor your company works with regularly. The company name is right, and the amount looks reasonable. The email may even reference a real project or an outstanding balance that your company may have. There is just one problem with it: your vendor didn't send it. A scammer did. 

Fake invoice scams and vendor impersonation schemes are designed to blend into normal business activity. Instead of sending an obviously suspicious email, criminals may impersonate a legitimate vendor, compromise a real email account, or send fraudulent instructions telling your accounting team that payment information has changed. Your next legitimate payment could go directly to the criminal's bank account. 

For businesses that regularly pay contractors, suppliers, professional service providers, and other vendors, understanding this risk is becoming an important part of both cybersecurity and insurance planning.

What Does a Fake Invoice Scam Look Like?

Fake invoice fraud can take several forms. In a basic version, a criminal sends an invoice that appears to come from a legitimate company and hopes someone pays it without verifying the charge. However, more sophisticated attacks can be much harder to recognize.

A criminal might impersonate one of your existing vendors and send updated ACH or wire instructions. In other cases, an actual vendor's email account may be compromised, allowing the attacker to monitor conversations and learn how the two companies normally communicate.

The criminal can then wait for the right moment to intervene.

Your employee may receive an email that appears to continue an existing conversation:

"We've recently changed banks. Please use the attached payment instructions for all future invoices." The invoice itself may be completely legitimate. The only fraudulent part is where you're being told to send the money.

Why Vendor Impersonation Can Be So Convincing

Vendor relationships run on speed and trust. Once a business has worked with the same supplier, contractor, or service provider for months or years, invoices and payment requests become routine. Employees recognize the vendor's name, know what they typically purchase, and expect invoices to move through accounts payable without unnecessary delays. Scammers exploit that familiarity.

Rather than relying on an obviously suspicious email, sophisticated scams can use information gathered from company websites, employee profiles, social media, previous communications, or even a compromised email account to make a request look like part of an established vendor relationship. In some cases, the deception may extend beyond email, using phone calls, text messages, or other communication channels to reinforce the request.

The objective is usually to move the employee from a familiar interaction to a high-impact action. That might mean changing ACH information, approving an invoice, sending an urgent wire transfer, entering credentials into a fraudulent login page, or redirecting future payments to a new account.

A request to "update our banking information" can be especially effective because nothing about the underlying business relationship has changed. The vendor may be real. The invoice may be real. The amount may be exactly what your company expected to pay. The attacker only needs to change where the money goes.

That is what makes vendor impersonation particularly difficult to catch. The scam is designed to look less like an attack and more like another routine task that needs to be completed before the end of the day.

How Common Are Fake Invoice Scams?

Email scams are not isolated incidents. In August 2026, Microsoft researchers identified a campaign involving more than one million fraudulent emails designed to impersonate company executives and trick accounts payable departments into sending payments of nearly $50,000. About 88% of the campaign's targets were in the United States.

What made the campaign especially concerning was how much effort went into making the messages look legitimate. Attackers combined executive impersonation, vendor branding, fabricated invoices, and fake email conversations into a single, believable story. Microsoft researchers also found signs consistent with AI-assisted template development, which can make these scams easier to personalize and distribute at scale.

For businesses, the takeaway is that fake invoice fraud is no longer limited to poorly written emails asking for an obvious wire transfer. Attackers are building increasingly realistic payment requests that fit into normal vendor workflows, making strong verification procedures and appropriate insurance coverage more important than ever.

The Payment Goes Through. What Happens Next?

These incidents can move quickly. Your accounting department receives the payment request, processes it, and moves on. Days or even weeks later, the legitimate vendor contacts your company because its invoice is still outstanding. That's when everyone realizes what happened.

The business may have already paid thousands of dollars to a criminal, but it can still owe the legitimate vendor the original amount. Recovering transferred funds can also be difficult. Businesses should contact their financial institution immediately after discovering fraudulent payment instructions because the ability to stop or recover a transfer can depend heavily on how quickly the fraud is identified.

The next call should be to your insurance agent or carrier to determine whether the incident may be covered and what documentation is required.

Doesn't General Liability Insurance Cover Fraud?

This is where businesses can encounter an unpleasant surprise. A Commercial General Liability policy is primarily designed to address risks such as bodily injury, property damage, and certain personal and advertising injuries. It generally isn't the policy intended to reimburse a company for money voluntarily transferred because an employee was deceived by a fraudulent email.

Coverage for a fake invoice or fraudulent wire transfer may instead depend on specialized cyber or crime coverage.

Depending on the policy, relevant protections may include Social Engineering Fraud, Funds Transfer Fraud, or other crime and cyber provisions. The terminology, limits, exclusions, and requirements can vary considerably between policies. Simply having cyber insurance doesn't guarantee that every type of payment fraud is covered. Coverage for fake invoices, vendor impersonation, social engineering, and fraudulent funds transfers can vary by policy, which is why it's important to understand exactly what your coverage includes.

Social Engineering Fraud vs. Funds Transfer Fraud

These terms can sound similar, but the distinction matters. Social engineering fraud generally involves someone manipulating an employee into voluntarily sending money or property. Vendor impersonation is a common example. Your employee believes the request is legitimate and authorizes the transfer.

Funds transfer fraud may apply to different circumstances involving unauthorized or fraudulent transfers, depending on how the policy defines the coverage. That distinction is important because a business can have protection for one type of event without necessarily having equivalent protection for another. It is also why reviewing the actual policy language matters more than simply checking whether your company has "cyber" or "crime" insurance.

How Businesses Can Reduce the Risk

Technology can help identify suspicious messages, but fake invoice fraud is also a process problem. One of the strongest defenses is making sure a single email cannot change where your company sends money.

Establish a verification procedure for new payment instructions, especially when a vendor requests a change to its bank account, ACH information, or wire instructions. Employees should verify the request using contact information already on file rather than a phone number supplied in the email requesting the change.

Businesses can also consider requiring approval from more than one person for significant transfers or changes to vendor payment information. Employees responsible for accounts payable should be trained to recognize unexpected changes in payment instructions, unusual urgency, slightly altered email addresses, and requests that deviate from normal procedures.

The goal is simple: make it difficult for one convincing email to become an expensive mistake.

Your Insurance Should Be Part of the Fraud Prevention Conversation

Good internal controls can reduce the likelihood of a successful scam, but no procedure eliminates the risk entirely. That's where understanding your insurance becomes important.

Rather than waiting until money has disappeared to find out how your policy responds, review your cyber and crime coverage ahead of time. Ask specifically how your policy addresses vendor impersonation, social engineering, fraudulent payment instructions, and funds transfers.

Pay particular attention to coverage limits and sublimits. A policy may provide significant overall cyber coverage while offering a much smaller amount for a specific type of social engineering loss.

Know Your Coverage Before You Hit Send

Fake invoice scams work because they imitate something businesses do every day: pay people they owe. An email doesn't need to look suspicious if it arrives at the right time, uses familiar language, and appears to come from a company your team already trusts. Your internal procedures are the first line of defense. Your insurance coverage should provide another layer of protection when those procedures fail.

Does Your Policy Cover a Fake Invoice Scam?

Don't wait until a fraudulent payment is already gone to start reading your policy. Contact Navisure Insurance Group for a review of your business insurance coverage. We can help you understand how your current policies address social engineering and funds transfer fraud, identify potential gaps, and discuss coverage options that better reflect the cyber risks businesses face today.

Troy Vandermeer

TROY VANDERMEER | VICE PRESIDENT

Troy attended Aquinas College in Grand Rapids, MI, and obtained a degree in Business and Technology. After graduating, he began his career as an insurance adjuster for a large-scale carrier. This included almost 10 years of experience, with roles such as property catastrophe, marine, and recreational vehicle claim handling. Troy learned the ins and outs of how insurance companies operate while also perfecting the technical aspects of the industry. This gives him an edge when working with clients regarding what coverage best fits their needs. As a proponent of leveraging technology, his goal is to simplify the process of getting insured without clients having to sacrifice their time.

In his spare time, Troy coaches high school soccer, enjoys golfing, fly fishing, and spending time with his family and friends.

Frequently Asked Questions about Fake Invoice Fraud

Q: What is a fake invoice scam?

A fake invoice scam occurs when a criminal attempts to convince a business to pay a fraudulent invoice or redirect a legitimate payment. The attacker may impersonate a vendor, compromise an email account, or provide fraudulent banking instructions.

Q: What is vendor impersonation fraud?

Vendor impersonation occurs when a criminal pretends to be a company your business already works with. The criminal may send fake invoices or request that legitimate payments be redirected to a different bank account.

Q: Does General Liability insurance cover fake invoice fraud?

Commercial General Liability insurance is generally not designed to cover money a business voluntarily transfers because of a fraudulent payment request. Depending on the circumstances and policy language, coverage may instead be available through cyber insurance, crime insurance, or specific social engineering or funds transfer fraud coverage.

Q: Will cyber insurance cover a fraudulent wire transfer?

It depends on the policy and the circumstances of the loss. Cyber policies can vary substantially, and social engineering or funds transfer coverage may have separate limits, exclusions, or conditions.

Q: How can businesses verify a vendor's new banking information?

Use a known, previously verified method of contacting the vendor rather than replying to the email or using contact information provided in the payment-change request. Confirm the new banking instructions directly before changing payment information.

Q: What should a business do after discovering a fraudulent payment?

Contact your bank or financial institution immediately to determine whether the transaction can be stopped or recovered. You should also notify your insurance agent or carrier promptly and follow any reporting requirements contained in your policy.