SardineCon SF/2026

Learn More
Fraud types4 min read

What is Vendor fraud?

SUBSCRIBE

Vendor fraud is theft that flows through a company's supplier payments, using fake or shell vendors, inflated or duplicate invoices, or collusion between a supplier and an insider. Because vendor payments are routine and trusted, the money leaves through the front door and blends into ordinary spending.

What is vendor fraud, in plain English?

Vendor fraud is any scheme that pulls improper payments out of a business through its accounts payable process. Instead of breaking in, the fraudster works the plumbing that companies already use to pay suppliers: purchase orders, invoices, and the vendor master file. Because paying vendors is normal, an extra invoice or a slightly inflated one does not look out of place.

The scheme takes a few common forms. A shell or fictitious vendor is a supplier that exists only on paper, set up to receive payments for goods or services never delivered. Invoice manipulation covers duplicate billing, inflated amounts, and charges for phantom work. Collusion is when an insider and a real supplier work together, approving overbilling or kickbacks in exchange for a cut.

In the fraud and financial-crime world, vendor fraud overlaps heavily with invoice fraud, procurement fraud, and invoice redirection. What ties them together is the trusted channel: the payment is authorized inside the company's own controls, so the loss looks like a legitimate business expense until someone reconciles the details.

The main flavors of vendor fraud

Type

How it works

Tell to look for

Shell vendor

A fake supplier is added to the master file and paid for nothing.

No web presence, PO-box address, banking that matches an employee.

Duplicate invoice

The same invoice is submitted and paid more than once.

Same amount and reference paid twice, close in time.

Inflated invoice

A real vendor bills for more than was delivered.

Amounts creeping above quote or contract, round numbers.

Collusion and kickback

An insider approves overbilling for a share of the proceeds.

One approver, one favored vendor, weak documentation.

Who is involved?

Who

Their role

The insider

An employee in procurement, AP, or finance who creates or approves the improper payment.

The vendor

Either fictitious and controlled by the fraudster, or a real supplier colluding on overbilling.

Accounts payable

Processes the payment in good faith. Often the team that later spots the duplicate or mismatch.

The bank

Sees vendor payouts landing in accounts that trace back to employees or throwaway entities.

What it looks like in practice

In practice

A procurement manager adds a new supplier to the vendor master for consulting services. The vendor has a generic name, a PO-box address, and a bank account that, unknown to the reviewers, matches the manager's own. Small invoices for advisory work start arriving monthly, each just under the amount that would require a second approval.

For a year the payments clear without question because they look like ordinary consulting spend. The scheme surfaces only when an auditor cross-references vendor bank details against payroll records and finds the account numbers match. By then the total loss runs well into six figures across dozens of invoices.

Why it matters to operators

Vendor fraud is dangerous precisely because it hides inside legitimate, recurring spend. There is no stolen card and no chargeback to raise the alarm. The payments are authorized, documented, and posted to the general ledger, so they pass every downstream control until someone reconciles the underlying data. Losses accumulate slowly and can run for years.

For teams, that means detection depends on data hygiene and linkage rather than real-time decisioning. Validating the vendor master, running duplicate-payment and threshold analysis, and linking supplier bank details and addresses back to employees are the workhorse controls. It also has a fraud-and-AML overlap: shell-vendor payouts can be a vehicle for embezzlement and for moving illicit funds under the cover of trade.

What to watch in the data

  • No verifiable footprint. Vendors with no website, no phone, no registration, and only a PO-box address.
  • Banking overlaps. Supplier account or routing details that match an employee, or several vendors sharing one bank account.
  • Just-under thresholds. Invoices repeatedly priced just below the amount that would trigger a second approval.
  • Duplicate references. The same invoice number or amount paid more than once within a short window.
  • Single approver. One employee who onboards, approves, and reconciles the same favored vendor with thin documentation.

Quick questions

How is vendor fraud different from invoice fraud?

They overlap heavily. Invoice fraud focuses on the fake or altered invoice itself, while vendor fraud is the broader category covering fake suppliers, duplicate and inflated billing, and insider collusion across the whole procure-to-pay cycle.

Is vendor fraud usually an inside job?

Often, yes. Setting up a shell vendor or approving overbilling generally requires someone with access to the vendor master or the approval workflow. External-only schemes exist too, but the highest-loss cases usually involve an insider.

What is the single best control?

Segregation of duties combined with vendor-master validation. No one person should onboard, approve, and pay the same vendor, and new bank details should be verified through a callback to a known contact before any payment.

Why do the payments go undetected so long?

They look like normal business expenses posted to the general ledger. Without cross-referencing vendor data against payroll and running duplicate and threshold analysis, nothing flags them, so losses build quietly over months or years.

Does this connect to money laundering?

It can. Shell vendors and inflated invoices are also a way to move illicit funds under the appearance of legitimate trade, which is why trade-based and procurement schemes often draw both fraud and AML attention.

Go deeper

  • FTC Consumer Advice: Scams ↗ — US consumer guidance on current scams and fraud, and how to report them.
  • FBI IC3 ↗ — The FBI Internet Crime Complaint Center. Fraud reporting and annual trend reports.

What to know alongside Vendor fraud