SardineCon SF/2026

Learn More
Fraud types4 min de lectura

¿Qué es Invoice fraud?

SUBSCRIBE

Invoice fraud is submitting false, inflated, duplicate, or altered invoices to get paid improperly. The payments look routine, so the theft can run for a long time through a fake vendor or a manipulated real one before anyone notices.

What is invoice fraud, in plain English?

Invoice fraud is getting a company to pay money it does not owe by feeding false paperwork into accounts payable. The invoice might be entirely fake, from a vendor that does not really exist, or a manipulation of a real one: inflated amounts, a duplicate of a genuine bill, or altered payment details. Either way, the payment leaves through a process built to pay invoices, so it looks completely normal.

That normality is the whole point. AP teams process high volumes, and a well-formed invoice for a plausible amount rarely gets a second look. So the fraud can run quietly for months or years, especially when it hides among legitimate spend, sits just under approval thresholds, or exploits weak controls around who can add vendors and approve payments.

It can be an outside scheme, a fake supplier billing the company, or an inside job, an employee routing payments to themselves or an accomplice, and it frequently involves collusion. Invoice fraud is closely tied to vendor fraud, procurement fraud, and invoice redirection, and the standard defenses are three-way matching, duplicate-payment detection, vendor bank verification, and segregation of duties.

Common invoice fraud patterns

Pattern

How it works

Fake vendor

A shell or nonexistent supplier is set up and billed against for goods or services never delivered.

Inflated invoice

A real vendor's bill is padded with extra quantities, higher rates, or phantom line items.

Duplicate billing

The same invoice, or a lightly changed copy, is submitted twice to get paid more than once.

Altered details

Amounts or bank details on a genuine invoice are changed so payment goes to the fraudster.

Threshold splitting

Charges are broken into pieces just under approval limits to avoid extra scrutiny.

What it looks like in practice

In practice

A mid-size company pays a "facilities maintenance" vendor a few thousand dollars each month. The invoices are clean, the amounts are modest, and they always land just under the level that would require a second approver. The vendor was added to the system by an employee in AP, and its bank account details quietly match that employee's own.

Nothing looks wrong on any single payment, so it runs for over a year. It surfaces when a duplicate-payment check flags two invoices with the same number a month apart, and a vendor bank review shows the account shared with an employee. The routine, low-value invoices were the disguise; the shared bank details and duplicate number gave it away.

Why it matters to operators

Invoice fraud is a slow leak rather than a sudden hit, which is exactly what makes it costly. Because each payment looks like ordinary spend, the loss accumulates unnoticed and the total can be large by the time anyone catches it. When an insider is involved, they can also cover their tracks by approving their own entries, so weak segregation of duties turns a small gap into a durable scheme.

The controls that work are procedural and data-driven. Three-way matching of purchase order, goods received, and invoice stops payment for things that were never ordered or delivered. Duplicate-payment detection catches repeated invoice numbers and amounts. Verifying vendor bank accounts exposes suppliers that share details with employees or that change banks suspiciously. And separating the people who create vendors, approve invoices, and release payments removes the single point of control fraudsters exploit.

What to watch in the data

  • Just-under-limit invoices. Charges consistently priced a little below an approval threshold to dodge a second reviewer.
  • Duplicate numbers or amounts. The same invoice number, or identical amounts, appearing more than once across a period.
  • Shared bank details. A vendor account that matches an employee's, or several "vendors" sharing one account.
  • Sudden detail changes. A vendor's bank or contact information changing right before a payment run.
  • Thin vendor footprint. Suppliers with no address, no web presence, round-number invoices, and only one internal contact.

Quick questions

How is invoice fraud different from invoice redirection?

Invoice redirection specifically changes the payment details on a real invoice, usually after compromising a vendor's email. Invoice fraud is the broader category that also includes fake vendors, inflated bills, and duplicates.

Is invoice fraud usually an inside job?

It can be either. Outsiders bill with fake or manipulated invoices, and insiders route payments to themselves or an accomplice. Many cases involve collusion between an employee and an outside party.

What is three-way matching?

Matching the purchase order, the goods-received record, and the invoice before paying. If there is no order or no delivery, the invoice does not get paid, which blocks fake and inflated bills.

Why is threshold splitting a red flag?

Approval limits usually require an extra reviewer above a certain amount. Charges repeatedly sized just under that limit suggest someone is deliberately avoiding scrutiny, a classic invoice fraud tell.

How does verifying vendor bank accounts help?

It catches vendors whose bank details match an employee's, multiple vendors sharing one account, or suspicious changes of bank right before payment, all common signals of fake vendors and redirection.

Go deeper

  • FTC Consumer Advice: Scams ↗ — US consumer guidance on current scams and fraud, and how to report them.
  • FBI IC3 ↗ — The FBI Internet Crime Complaint Center. Fraud reporting and annual trend reports.

Qué saber junto con Invoice fraud