ShieldNet 360

Oct 1, 2026

Blog

I paid a fake invoice. What should my business do?

I paid a fake invoice. What should my business do?

Your Finance team receives an invoice from a familiar supplier.

The supplier name is correct. The amount looks normal. The email appears legitimate.

The invoice says:

“Please note that our bank account has changed. Use the new account details for this payment.”

The payment is approved and sent.

A few days later, the real supplier contacts you:

“We still haven't received your payment.”

You check the bank details again.

The money went to the wrong account.

Your business has paid a fake invoice. What should you do now?

The most important thing is to act quickly.

Do not wait for the supplier to investigate. Do not continue communicating with the suspicious sender. And do not assume the money is automatically lost.

Immediately involve your bank or payment provider, Finance team, management, and IT/security team.

Your first priorities are:

Stop further payments → Contact the bank → Preserve evidence → Secure affected accounts → Investigate what happened

Quick Answer: What should a business do after paying a fake invoice?

If your business has transferred money because of a fraudulent invoice:

  1. Contact your bank or payment provider immediately. 

  2. Ask whether the payment can be stopped, recalled, frozen, or investigated. 

  3. Stop any additional payments related to the suspicious request. 

  4. Notify Finance, management, and IT/security. 

  5. Contact the real supplier using previously trusted contact information. 

  6. Preserve the fraudulent invoice, emails, payment records, and related evidence. 

  7. Determine whether any business or supplier email account was compromised. 

  8. Check for other fraudulent invoices or payment changes. 

  9. Change or secure affected credentials if necessary. 

  10. Follow applicable internal, legal, insurance, and law-enforcement reporting procedures. 

The faster your business acts, the better the opportunity to contain the incident and potentially recover funds.

Step 1: Contact Your Bank Immediately

This should be one of the first actions.

Tell the bank or payment provider that your business believes it has made a payment as the result of fraud.

Provide information such as:

  • Transaction amount 

  • Date and time 

  • Recipient account 

  • Transaction reference 

  • Beneficiary name 

  • Invoice information 

  • When the fraud was discovered 

Ask what options are available for the specific transaction.

Depending on the payment method, timing, jurisdictions, and status of the funds, the bank may be able to attempt a recall, contact the receiving institution, freeze funds where possible, or begin a fraud investigation.

There is no guarantee that money can be recovered.

But waiting reduces your options.

Step 2: Stop Any Additional Payments

Invoice fraud may involve more than one payment.

Once one fraudulent transaction succeeds, the attacker may try again.

Immediately check for:

  • Other invoices from the same sender 

  • Pending payments to the new bank account 

  • Recently changed supplier bank details 

  • Similar payment requests 

  • Other unusual transactions 

If additional suspicious payments are waiting for approval, stop them until they have been independently verified.

Also alert employees responsible for Accounts Payable or payment approvals.

Step 3: Contact the Real Supplier

Contact the supplier using information your business already trusted before the suspicious invoice arrived.

For example, use:

  • A phone number in your existing supplier records 

  • A known account manager 

  • A previously verified communication channel 

Do not simply call the phone number printed on the suspicious invoice or provided in the suspicious email.

Ask the supplier to confirm:

  • Whether they sent the invoice 

  • Whether their bank account actually changed 

  • Whether they sent the email requesting the change 

  • Whether they have noticed suspicious activity in their email account 

This helps determine whether the attacker:

Impersonated the supplier or Compromised the supplier's real email account.

Step 4: Preserve the Evidence

Do not delete the fraudulent email or invoice.

Keep:

  • Original emails 

  • Full sender addresses 

  • Invoice files 

  • Bank account information 

  • Payment confirmations 

  • Transaction references 

  • Email attachments 

  • Relevant chat messages 

  • Internal approval records 

  • Dates and times 

  • Previous legitimate invoices from the supplier 

Your bank, security team, insurer, legal advisers, or authorities may need this information.

Preserving evidence also helps your business understand exactly how the fraud succeeded.

Step 5: Find Out How the Fake Invoice Reached Your Business

Paying the fake invoice is the visible outcome.

But the business also needs to understand how the attacker made the request believable.

Several scenarios are possible.

Scenario 1: The Attacker Impersonated the Supplier

The attacker created a lookalike email address.

For example:

Real: [email protected]

Fake: [email protected]

The difference may be only one character.

Scenario 2: The Supplier's Email Was Compromised

The attacker accessed the supplier's real mailbox.

They could read previous conversations, identify upcoming invoices, and send modified payment instructions at exactly the right moment.

In this situation, the fraudulent request may come from a real email address.

Scenario 3: Your Employee's Email Was Compromised

The attacker may have access to an employee's mailbox and be monitoring communications with suppliers.

They can learn:

  • Who approves payments 

  • Which invoices are expected 

  • How much the company normally pays 

  • When payments are made 

  • How employees communicate 

Scenario 4: A Real Invoice Was Modified

The attacker obtained a legitimate invoice and changed only the payment details.

Everything else may be correct:

Supplier. Amount. Invoice number. Services.

Only the bank account is different.

Identifying the scenario matters because recovering from the payment alone is not enough if an email account is still compromised.

Step 6: Check Business Email Accounts

If email compromise may be involved, IT/security should investigate relevant accounts.

Depending on the environment, this can include reviewing:

  • Recent logins 

  • Unknown devices 

  • Suspicious sessions 

  • Password changes 

  • MFA changes 

  • Email forwarding rules 

  • Inbox rules 

  • Deleted or hidden messages 

  • Connected applications 

Attackers who gain access to business email sometimes try to remain unnoticed.

For example, they may create rules that hide replies from a real supplier so the victim continues communicating with the attacker.

If an account is compromised, securing it quickly is critical.

Step 7: Check Whether Credentials Were Also Stolen

Invoice fraud may be part of a larger phishing attack.

An employee may previously have entered their password into a fake Microsoft 365, Google, or other login page.

Ask employees involved in the transaction:

Did you recently click an unusual login link?

Did you enter your password after following an email?

Did you approve an unexpected MFA request?

Did you download anything unusual?

If credentials may have been exposed, the organization should secure those accounts according to its incident-response process.

Step 8: Look for Other Fraudulent Activity

Do not assume the fake invoice was the attacker's only action.

If attackers had access to an email account, they may have targeted multiple transactions.

Check for:

  • Other bank account changes 

  • New suppliers 

  • Unusual payment requests 

  • Duplicate invoices 

  • Changes to invoice amounts 

  • Suspicious emails sent from internal accounts 

  • Deleted messages 

  • New forwarding rules 

  • Requests for confidential information 

The objective is to understand the full scope of the incident, not just the payment that was discovered first.

Step 9: Notify the Right People Inside the Business

A fake invoice payment can involve more than Finance.

Depending on the incident, notify the appropriate:

  • Finance team 

  • Management 

  • IT/security team 

  • Legal or compliance team 

  • Risk team 

  • Privacy team 

  • Insurance contact 

Keep a clear record of what happened and what actions have been taken.

For example:

09:15 – Finance discovered supplier had not received payment.

09:25 – Bank contacted and fraud case opened.

09:35 – IT began reviewing employee email account.

10:00 – Real supplier confirmed bank details had never changed.

A simple timeline can become extremely useful during the investigation.

Step 10: Consider Reporting and Legal Requirements

Depending on the country, transaction, information exposed, contracts, and circumstances, the business may need to report the incident to relevant authorities or other parties.

If personal or confidential information was also exposed, additional privacy or data-protection obligations may apply.

Your legal, compliance, security, banking, or insurance advisers can help determine the appropriate reporting requirements for the specific incident.

Do not assume that invoice fraud is only a financial problem.

It may also involve:

  • Account compromise 

  • Personal data exposure 

  • Contractual obligations 

  • Cyber insurance requirements 

  • Criminal fraud 

Can a Business Recover Money From a Fake Invoice?

Sometimes recovery may be possible, but it depends on the circumstances.

Important factors can include:

  • How quickly the fraud was discovered 

  • How quickly the bank was contacted 

  • Whether the transfer has completed 

  • Whether the money remains in the recipient account 

  • Which banks and countries are involved 

  • The payment method 

This is why the first few minutes or hours can matter.

Do not spend hours investigating internally before contacting the bank.

Financial recovery and cybersecurity investigation can happen in parallel.

Should We Contact the Attacker?

Generally, once fraud is suspected, avoid continuing the conversation without guidance from the appropriate internal or external response teams.

Do not tell the suspicious sender:

“We know you're a scammer. Return our money.”

Doing so may alert them that the fraud has been discovered and potentially encourage them to move funds or destroy evidence.

Preserve the communication and let the bank, security team, legal advisers, or authorities guide further contact where appropriate.

How Can Businesses Prevent Fake Invoice Payments?

After the immediate incident is under control, review the process that allowed the payment to happen.

The goal should not simply be:

“Employees need to be more careful.”

Good financial controls can stop invoice fraud even when an email looks convincing.

1. Independently Verify Bank Account Changes

Any request to change supplier bank information should be confirmed through a previously trusted channel.

For example:

Email requests bank change → Finance calls verified supplier contact → Supplier confirms → Change is approved

Never verify a bank account change using only the contact information included in the request itself.

2. Require Additional Approval for Important Payments

High-value payments or bank-detail changes can require approval from more than one person.

This reduces the chance that one convincing email leads directly to a transfer.

3. Compare With Previous Supplier Records

Before changing payment details, compare:

  • Bank account 

  • Supplier contact 

  • Invoice format 

  • Payment history 

  • Contract information 

Unexpected differences deserve verification.

4. Protect Employee Email Accounts

Strong authentication, email security, account monitoring, and employee awareness can reduce the chance of attackers gaining access to business conversations.

5. Train Employees Around the Request, Not Just the Email

Employees should not only ask:

“Does this email look fake?”

They should also ask:

“Is this request unusual?”

A perfectly written email from a real compromised account can still contain fraudulent payment instructions.

A Simple Rule for Supplier Bank Changes

Businesses can make invoice fraud much harder with one simple policy:

No supplier bank account change is approved based only on an email request.

Instead:

Receive request → Verify through trusted contact → Record confirmation → Approve change → Process payment

This process remains useful even if an attacker has compromised the supplier's real email account.

Fake Invoice Incident Checklist

If your business has already paid:

Bank  – Contact the bank/payment provider immediately.

Payment  – Stop related pending transactions.

Supplier  – Verify with the real supplier through a trusted channel.

Evidence  – Preserve emails, invoices, and transaction records.

Accounts  – Check whether employee or supplier email was compromised.

Credentials  – Secure potentially exposed accounts.

Scope  – Search for other suspicious payments or messages.

Internal response  – Notify Finance, management, IT/security, and other relevant teams.

Reporting  – Assess legal, insurance, contractual, and law-enforcement requirements.

Prevention  – Fix the process that allowed the fraudulent payment.

Key Takeaways

If your business pays a fake invoice, speed matters.

Do not spend the first several hours trying to determine who made the mistake.

Focus on limiting the damage.

Start with:

Contact the bank → Stop additional payments → Verify with the supplier → Preserve evidence → Investigate email compromise

Then determine how the attacker succeeded and strengthen the payment process.

The most important preventive lesson is simple:

A change in payment details should never be trusted based on email alone.

Verify the change independently before the money moves.

Frequently Asked Questions

What should I do immediately after paying a fake invoice?

Contact your bank or payment provider immediately, stop related pending payments, notify internal Finance and security teams, preserve the evidence, and verify the situation with the real supplier.

Can a bank reverse a payment made to a scammer?

It may sometimes be possible to stop, recall, freeze, or recover funds, depending on the payment method, timing, banks involved, and whether the funds are still available. Contact the bank immediately rather than assuming the payment cannot be recovered.

Should I contact the supplier after discovering invoice fraud?

Yes. Use previously trusted contact information rather than details from the suspicious invoice or email. Confirm whether the supplier actually requested the payment change.

Can a fake invoice come from a supplier's real email address?

Yes. If a supplier's mailbox has been compromised, attackers may send fraudulent payment instructions from the legitimate account.

Should we change employee passwords after invoice fraud?

If there is evidence or suspicion that employee credentials were compromised, the affected accounts should be secured according to your incident-response process. Invoice fraud does not automatically mean every employee password needs changing.

How can businesses prevent invoice fraud?

Independently verify bank-detail changes, require appropriate payment approvals, compare new invoices with existing supplier records, protect business email accounts, and train employees to question unusual payment requests.

ShieldNet 360 in Action

Protect your business with ShieldNet 360

Get started and learn how ShieldNet 360 can support your business.