Invoice & Payment Fraud
A clean invoice, the usual format, the attacker's bank details.
What Is Invoice & Payment Fraud?
An attacker registers a one-character lookalike of a real supplier domain and sends your accounts payable team an invoice in that supplier's usual format. There is no malware and no urgent story, just a clean PDF with the attacker's bank details printed on it. The control that stops it is the three-way match: purchase order, goods receipt, verified vendor record. You'll run that match, find the missing PO and the wrong remit-to bank, confirm by callback, reject the invoice, and file a fraud report.
What You'll Learn in Invoice & Payment Fraud
- Run the 3-way match (purchase order, goods receipt, invoice) on every vendor invoice and refuse to advance any invoice with a failed leg
- Recognize that bank details printed on an invoice are not authoritative and must always be reconciled against the vendor master under Procurement's change control
- Spot lookalike sender domains, missing or placeholder PO references, and unusually short payment terms as red flags of vendor invoice fraud
- Reject contact information supplied inside a suspicious invoice or its accompanying email - the phone number and reply-to are part of the attack
- Use the verified phone number from the vendor master to place an out-of-band callback that confirms the invoice is genuine before any payment moves
- Reject confirmed-fraud invoices in the AP system with a structured reason code that produces an audit trail and a SOC notification
- File a structured fraud report capturing the lookalike domain, spoofed phone, fraudulent bank account, and 3-way match output so the SOC can hunt for parallel campaign attempts
Invoice & Payment Fraud — Training Steps
-
Monday Morning Invoice Queue
It is Monday morning at Westmark Industrial. You're Alice, an Accounts Payable Specialist, and the end-of-month invoice queue is sitting at twenty-three open items. Wednesday's payment run is the deadline. Most of the queue is routine. Each invoice gets matched against its purchase order and goods receipt in InvoiceFlow before payment is queued - the 3-way match is the only thing standing between a fraudulent invoice and the wire room.
-
An Invoice From Apex Steel
A new email lands in your inbox from Apex Steel & Fabrication, one of your standing suppliers. The subject line references invoice INV-AS-2025-1147 and a PDF is attached.
-
A Closer Look at the Email
Apex sends invoices like this every month, so on a quick read nothing about the message rings an immediate alarm. Slow down anyway. Two details in the email should make you stop before you process the PDF.
-
Download the Invoice PDF
Even with the lookalike domain, the only way to know if this invoice is real is to inspect it the same way you inspect every other invoice. Pull the attached PDF down to your Downloads folder so you can open it.
-
Open the Downloaded PDF
The PDF is now in your Downloads folder. Open it from the file manager so you can see the line items, payment terms, and the remit-to bank details printed on the invoice.
-
What the Invoice Claims
The PDF is well-formatted - vendor letterhead, line items, payment terms. The two parts that matter most to fraud detection are the purchase order reference and the banking details . Look at both.
-
Run the 3-Way Match
An eyeballed PDF is not the control. The control is the 3-way match in InvoiceFlow: invoice line items must match an open purchase order, the goods receipt must confirm those items were actually delivered, and the vendor banking details must match the vendor master. If any of those three legs fail, the invoice does not move to the payment run.
-
Sign In to InvoiceFlow
InvoiceFlow uses Westmark SSO - the same account that gates every internal portal. Use the saved credentials in your password manager.
-
Upload the Invoice for Matching
InvoiceFlow opens to your AP workbench. The email arrived in your personal inbox, not the AP intake mailbox - so InvoiceFlow does not yet have the invoice. Click the upload button, choose the PDF you just downloaded, and let the system parse it and run the 3-way match.
-
The Match Results
InvoiceFlow runs the match in seconds. Three of the four checks fail - and the system has not auto-blocked the invoice, only flagged it. Whether to escalate or pay is your decision.
Security Framework Coverage
MITRE ATT&CK
- T1656 Impersonation
CIS Controls
- CIS 14.2 Train Workforce Members to Recognize Social Engineering Attacks
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind