Anatomy of invoice fraud: how supplier payments get stolen, step by step
This is an analysis of a fraud pattern documented across public research — Palo Alto Networks Unit 42's SilverTerrier series, Group-IB's BEC casework, INTERPOL's African Cyberthreat Assessment (2024) and the Verizon Data Breach Investigations Report (2024). It describes the pattern, not any specific victim.
The pattern
Invoice fraud — sometimes called supplier fraud or payment-diversion fraud — is the business end of business email compromise. The attacker does not ask for money; they redirect money that was already going to be paid. A legitimate invoice, a legitimate supplier relationship, a legitimate approval chain — with one fraudulent change: the bank account. Because every other element is genuine, this is the BEC subtype that consistently produces the largest per-incident losses in published reporting, and the DBIR's pretexting data shows how routinely it works. African supply chains, with their mix of cross-border suppliers, currency intermediaries and relationship-driven procurement, offer ideal cover.
How it plays out
The documented anatomy has five stages:
1. Compromise a mailbox on either side. A credential-phishing email or commodity information stealer gives the attacker a foothold — in your accounts-payable inbox, or just as often in your supplier's sales inbox. The weaker party's security protects both parties, which is why attackers hunt the smaller firm.
2. Watch the billing cycle. The intruder reads quietly: which invoices are due, in what format, referencing which purchase orders, approved by whom. Auto-forwarding rules keep copies flowing even after passwords change.
3. Intervene at the payment moment. Just before a real invoice is due, the attacker strikes — from the genuine supplier mailbox, or from a lookalike domain one character off. The message is mundane by design: "Please note our updated banking details for this and future invoices." Sometimes a genuine invoice PDF is reissued with only the account number altered.
4. Collect and disperse. The payment lands in a mule account, often in the same country as the victim so nothing looks foreign, and fragments onward within hours through further accounts, mobile wallets or currency conversion.
5. The long silence. The fraud surfaces only when the real supplier chases the unpaid invoice — typically weeks later, when recovery odds have collapsed.
Who it targets
Accounts-payable teams, procurement officers, project managers who approve contractor payments, and the finance functions of any organisation with recurring supplier relationships — construction, logistics, agriculture, manufacturing, NGOs and public procurement included. Suppliers themselves are targeted as the point of compromise, making your security partly a function of your smallest vendor's habits.
Breaking the pattern
- Verify every bank-detail change out-of-band — a call to a number from your master records, never from the email signature. This single control defeats the entire pattern.
- Freeze supplier bank details in a master file with dual-control changes, so an email alone can never alter where money goes.
- Train AP and procurement on the exact lure: calm, well-written, mid-thread "updated details" messages — not just crude phishing.
- Alert on lookalike domains of your organisation and key suppliers, and on new mailbox forwarding rules.
- Reconcile supplier statements promptly so a diverted payment surfaces in days, not months, while funds may still be freezable.
Sources
- Palo Alto Networks Unit 42, SilverTerrier research series (2014–2022)
- Group-IB, business email compromise research and Operation Falcon casework (2020)
- INTERPOL, African Cyberthreat Assessment Report (2024)
- Verizon, Data Breach Investigations Report (2024)
One verified phone call breaks this entire fraud — whether your team would make it is measurable, and our free Human Risk Maturity Assessment is where to start.