Agentic AI expense audit and AP automation | AppZen

Invoice fraud detection: Eight schemes and the control for each

Written by AppZen | Sep 14, 2026, 3:49:27 AM

Invoice fraud detection is the set of controls that stop a payment going to the wrong party or for the wrong reason. Eight schemes account for most enterprise exposure, and each has a signal that exposes it, a control that catches it, and a false positive that control creates. Sort every control by who owns the data it reads.

Key takeaways

  • Independence is what makes a control worth its cost. Where the fraudster controls the document or the email thread, a control reading either verifies nothing.
  • Callback verification has failed twice over. The number on the invoice was always the attacker's choice, and an attacker with synthetic speech now clears the implicit recognition test inside a phone call.
  • Every control needs a hit rate and a false positive rate. A rule flagging 400 invoices a month to catch two gets switched off by March.
  • An invoice is a document a stranger sends you, and once a model reads it, the document becomes an attack surface. Treat extracted values as claims.

A supplier emails new bank details on their usual letterhead, and the attached invoice matches an open purchase order (PO) line for line. The person answering your callback confirms it in a voice your accounts payable (AP) clerk knows. Three weeks later the real supplier asks where the money went.

What the current numbers actually say

The FBI's Internet Crime Complaint Center recorded 24,768 business email compromise (BEC) complaints in its 2025 Internet Crime Report, published in 2026, totaling $3,046,598,558 in reported losses. That ranked BEC second among crime types by loss, behind investment fraud. BEC losses rose about 10 percent year over year, from $2.770 billion in 2024, against total reported losses of $20.877 billion.

Exposure at the individual firm is another matter. The Association for Financial Professionals surveyed 465 treasury practitioners in January 2026 for its 2026 payments fraud survey. It found 76 percent of US organizations hit by attempted or actual payments fraud in 2025, with 74 percent affected by BEC. Just 17 percent use AI to combat it.

Then there is the clock. The Association of Certified Fraud Examiners studied 2,402 cases for Occupational Fraud 2026 and found a median loss of $104,000. The median scheme lasted 12 months before detection. Cases caught inside six months cost a median of $40,000, while those that lasted past five years cost more than $1.1 million. Billing schemes are a form of asset misappropriation, which appeared in 90 percent of cases. Time is the expensive variable.

A lens for sorting invoice fraud detection controls

Sort every candidate control by one question. Who controls the data it reads?

Where the fraudster controls the document, a control reading only the document checks internal consistency, and a well-made fake is internally consistent by design. Where the fraudster controls the email thread, verifying through that thread verifies nothing. Independence is what makes a control worth its cost, meaning the verifying data came from a source the fraudster could not alter.

The second question is when the control fires. Once the money leaves the bank you recover it slowly and partially, so spend your friction budget before the payment file is cut.

The third question is whether the control survives contact with your team. Every control has a hit rate and a false positive rate, and the binding constraint in AP is reviewer attention. Ask for both, because a catch rate alone is half a specification.

Eight invoice fraud schemes and what actually catches each

1. Fictitious or ghost vendor

A ghost vendor is a master record with no operating business behind it, billing modest amounts for services that leave no receiving trail. The signal is a vendor sharing a bank account or address with an employee record. The control is screening at vendor creation plus cross-matching against payroll. The false positive is a real one-person consultancy at a home address.

2. Bank account change fraud

An attacker sends a request to redirect payment for a real supplier, often attached to an authentic invoice. The signal is a request that arrives with an urgency cue, near a payment run, or from a domain that differs from the display name. The control is a mandatory hold plus verification against independently sourced contacts. The false positive is the supplier who genuinely changed banks last week.

3. Duplicate submission across channels

The same invoice arrives by email, through a portal, and on a statement, and two copies get paid. The signal is a near match on amount and date with a mutated reference, an added prefix or a stripped leading zero. The control is fuzzy duplicate detection across every intake channel. The false positive is recurring billing, meaning identical rent every month.

4. Altered or inflated invoice

An attacker intercepts a genuine invoice and edits it before it reaches AP, usually the total or the remit-to block. The signal is a total that does not equal the sum of its own lines. The control is arithmetic validation on every document plus three-way matching where a PO and receipt exist. The false positive is a supplier reissuing from a new billing system.

5. Business email compromise impersonating an executive or a supplier

An attacker compromises a real mailbox or registers a lookalike domain, then requests a payment or a detail change. Supplier impersonation includes real thread history, because the attacker has read the mailbox for weeks. The signal is a domain differing by one character, or a reply-to that diverges from the sender. The control is a rule that no payment instruction is actioned from email alone. The false positive is the urgent settlement that now waits.

6. Overbilling and bill padding inside tolerance

A supplier bills 3 percent over contract and every invoice clears, because it is under your matching tolerance. No single invoice is the signal. The signal is a supplier whose variance is consistently positive and never negative. The control is trend analysis on price and quantity variance, alerting on directional bias rather than a threshold breach. The false positive is genuine input inflation.

7. Insider collusion with a supplier

An employee with approval authority passes inflated invoices for a share, and the documentation is complete because the insider knows what complete looks like. The signal is relational, meaning an approver who signs off on a disproportionate share of one supplier's invoices. The control is segregation of duties enforced in the system plus approver concentration analysis. The false positive is the specialist who legitimately owns one relationship.

8. Advance-fee and shell-company schemes

An invoice arrives for something never ordered, a directory listing or a toner shipment, priced low enough to clear. The signal is an invoice with no PO, no internal requester, and a supplier appearing for the first time. The control is a hard block on payment without a named internal owner confirming receipt of value. The false positive is the small purchase made outside procurement.

Callback verification was already weak, and voice cloning finished it

Every fraud guide of the last decade recommends one control for bank detail changes. Call the vendor and confirm the change.

Callback to a number printed on the invoice was never a control. Where the attacker produced the document, the attacker chose the number, and you verified the fraud against itself. Most practitioners know this and call the number held in the vendor master instead.

That version is failing too, for two reasons that compound. The vendor master is itself a target. An attacker sitting in a compromised supplier mailbox for six weeks has often already submitted a contact update, so the number on file is theirs. An attacker using speech synthesized from a short sample then clears the implicit recognition test inside a phone call, which was never authentication. Your clerk was confirming that a voice sounded right, and an attacker now passes that test.

What substitutes is a set of partial measures. Verify out of band against independently sourced details, meaning a signed contract or a corporate registry filing, and treat anything that arrived by email as unverified. Impose a mandatory hold on bank changes, commonly five business days, because time is the one input an attacker cannot fake. Require dual authorization on vendor master changes, recorded against the field that changed. Confirm the new account by micro-deposit or an authenticated portal session.

None of these is complete. A hold delays a real supplier. Micro-deposits fail where a bank aggregates incoming credits. Portal confirmation works only when the portal is not itself compromised. Out-of-band verification depends on a contact record nobody has edited, which is the confidence you were trying to establish in the first place.

The next two problems, synthetic vendors and adversarial documents

A fabricated supplier is no longer a bare name in the master file. It arrives as a packet, with a website of plausible depth and tax documentation that passes format validation. A manufactured invoice history establishes a pattern before the first large claim. Screening built for a lazy ghost vendor misses a funded one. Proof of delivered value catches it.

Adversarial documents are the second pattern. Once an extraction model reads your invoices, the document becomes an attack surface. Text rendered invisibly to a human reader can push a wrong total or remit-to into the record while the visible page looks correct. Treat extracted values as claims, and keep a human decision point on any field that changes where money goes.

What invoice fraud detection does not catch

Detection does not catch the invoice that is legitimate on its face and wrong only in the world, meaning the consulting engagement billed and never performed, or the licenses nobody uses. Only receipt confirmation from someone accountable for the spend resolves that. Detection also misses whatever your tolerances are set to pass, which is a settings decision rather than a capability gap.

The larger failure is operational. Rules-based screening generates volume, and volume produces alert fatigue, the quiet reason most fraud programs underperform their design. A team reviewing 300 flags a month to find two real cases learns that flags are noise. Measure any control you keep on how often it was right, not how often it fired.

That gap is the honest state of the field. AFP found 17 percent of organizations using AI against payments fraud in 2026, while 76 percent were hit by it. ACFE found in 2026 that organizations training both staff-level employees and management reported a median loss of $84,000 per case, against $150,000 where neither group was trained.

How we approach invoice fraud detection

Our platform screens where the fraud starts, which for most enterprises is an email inbox rather than the enterprise resource planning (ERP) system. Bank change requests and invoices reach AP mailboxes days before anything is keyed.

Inside the AP Inbox Service Center, our Bank Change Verification Guardian Agent treats remit-to changes as a governed workflow rather than an email exchange. It holds the change, checks it against independent evidence, and routes it for dual approval. Our Duplicate Invoice Gatekeeper Agent matches submissions across every intake channel, so an invoice arriving by email and again on a statement is caught before either copy reaches the payment file. Both leave a full audit trail, because a control you cannot evidence is a control you cannot defend.

TruGreen reached 60 percent autonomous processing with our platform and identified $870,000 in duplicates through cross-channel matching.

The bottom line

Rebuild the control that fails most expensively in your shop, usually the bank detail change, around independence and a hold period instead of a phone call. Then measure it on precision. Our fraud and risk detection page shows how pre-payment screening fits an existing approval flow, and the upstream discipline is covered in vendor invoice management.

Frequently asked questions

What is the most common type of invoice fraud?

Bank account change fraud and business email compromise dominate reported losses. The FBI's Internet Crime Complaint Center logged 24,768 BEC complaints and $3,046,598,558 in losses in its 2025 report, published in 2026, an increase of roughly 10 percent on the prior year.

Does callback verification still work for bank detail changes?

It does not work on its own. A callback to a number on the invoice verifies the fraud against itself, and the number on file fails once the attacker has updated that record. Use independently sourced details, a hold, and dual authorization.

How long does invoice fraud last before someone catches it?

The Association of Certified Fraud Examiners reported a median scheme duration of 12 months across 2,402 cases in 2026. Schemes caught inside six months had a median loss of $40,000. Those that lasted past five years exceeded $1.1 million.

What is a fake invoice red flag I can check today?

Check whether the document total equals the sum of its own line items. Validating arithmetic costs nothing, catches altered documents, and produces few false positives.