ScamWatch

If you feel you're being scammed in United States: Contact the Federal Trade Commission (FTC) at 1-877-382-4357 or report online at reportfraud.ftc.gov

Vendor‑Fraud Automation: How Scammers Clone Supplier Emails & Fake Invoices — A Two‑Person Approval Playbook

A woman in a red shirt smiles while using her smartphone in a studio setting, offering modern lifestyle vibes.

Introduction — Why vendor‑invoice fraud is now automated

Small businesses are facing a faster, more convincing wave of vendor‑invoice fraud: attackers now combine account takeover and email‑spoofing tricks with generative AI to clone supplier emails, recreate letterhead and write plausible invoice notes that pressure staff to pay quickly. These are part of the Business Email Compromise (BEC) family of scams, which continue to cause large losses reported to the FBI’s Internet Crime Complaint Center (IC3).

This article explains how the scams work, technical and human red flags to watch for, and a compact, practical two‑person approval playbook that small businesses can adopt immediately to stop mistaken payments — without slowing routine operations.

How modern vendor‑fraud attacks operate (step‑by‑step)

Understanding the attack chain makes it easier to interrupt it. Common stages include:

  • Reconnaissance: attackers collect public invoices, vendor templates, email threads and contact names from prior messages or public records.
  • Access or spoof: they either take over a supplier’s email account or spoof a very similar domain / reply‑to address so messages appear to come from a trusted vendor. Threat actors will insert themselves into an existing thread (thread‑hijack) so the new message appears to continue a legitimate conversation.
  • Invoice manipulation: the attacker sends an updated invoice or ‘reminder’ that changes banking or payment instructions and adds urgency ("pay now or service will stop").
  • AI polish: generative tools help clone writing style, build convincing PDFs and mimic letterhead so the fake invoice passes casual inspection. Academic research shows AI can produce more convincing phishing content and increase attackers’ scale.
  • Cash out: money is routed to mule accounts, crypto rails or quickly withdrawn, reducing recovery odds.

Because the email often appears within an existing thread and uses real invoice numbers, recipients can be persuaded that the change is legitimate — which is why process controls are essential.

A practical two‑person approval playbook for small businesses

This playbook is designed for organizations that cannot afford expensive ERP controls. It balances speed and safety using policy, verification, and a simple dual‑control workflow.

Policy essentials (implement immediately)

  1. Require dual approval for any vendor payment that includes a change to payment instructions (bank account, ACH routing, new crypto address, or changes to payee name). The dual‑approval check must be independent: the second approver cannot be the person who received the invoice or who initiated the vendor change.
  2. Set dollar thresholds that automatically trigger additional checks (for example: any >$2,500 payment or any change to vendor banking details requires two approving signatures/approvals).
  3. Verify vendor changes out of band: always confirm changes using a trusted channel already on file (call the vendor’s published number, check a vendor portal, or use an email address you already store in your vendor master). Do not reply to the message that requested the change. The FBI recommends out‑of‑band verification for vendor requests.
  4. Document and log: require a short justification and the verifying phone number or portal proof to be attached to the payment record so auditors can trace the decision.

Two‑person workflow (template)

RoleActionWhat to attach/record
Initiator (AP clerk)Uploads invoice & flags changed payment details to systemInvoice image, original thread, note: "changed banking details"
Verifier (second AP staff / manager)Performs out‑of‑band vendor confirmationVendor call log or portal screenshot, contact name & timestamp
Approver (finance manager)Final approval to pay after reviewing verificationSigned approval, payment method, and retained verification evidence

Simple verification checklist (use during the verifier step)

  • Is the email domain identical to the one on record? (look closely for character substitutions).
  • Is the vendor‑profile phone number the same as our vendor master? Call that number (do not use numbers supplied in the suspicious email).
  • Does the invoice number match prior invoices? If not, ask for an explanation and confirm by phone.
  • Ask the vendor: “Did you send an invoice updating bank details via email today?” Require confirmation from a named person at the supplier on record.
  • For ACH/ wire changes, use a micro‑deposit validation or a bank letter on vendor letterhead before making large transfers.

Embed this workflow into your everyday AP routine and train staff with 2–3 live practice scenarios per year.

Technical controls, email red flags and incident steps

Key technical mitigations

  • Email authentication: enable SPF, DKIM and enforce DMARC policy so spoofed domains are more likely to be blocked or quarantined. Monitoring these records helps spot lookalike domains and replay attacks.
  • Vendor master hygiene: keep one canonical contact record per vendor, purge stale details and require periodic re‑verification for high‑risk vendors.
  • Invoice scanning & detection: use automated tools or rules to flag invoices that change bank details, use new email addresses, or include attachments with embedded links.

Practical red flags (quick checklist)

  • Unexpected request to change bank details or payment method.
  • Pressure language or an urgent due date with a threat of service interruption.
  • New email address that is similar but not identical to the vendor domain (character swaps, extra hyphens, different TLDs).
  • Invoices sent outside the vendor’s normal billing cadence or with new invoice numbering.
  • Requests to pay via unfamiliar rails (gift cards, cryptocurrency, non‑standard P2P apps).

If you suspect fraud — an immediate checklist

  1. Stop payment if possible; contact your bank immediately and ask for a hold or reversal.
  2. Preserve evidence: save the original email (full headers), attachments and any call logs used for verification.
  3. Report the incident to law enforcement/IC3 and your bank; follow your local regulator’s guidance. The FBI and IC3 provide reporting channels for BEC incidents.
  4. Perform a post‑incident review and update vendor verification and approval thresholds.

Combining technical controls with the two‑person approval policy forms a robust, low‑cost defense that blocks the most common automated vendor fraud attempts while keeping normal payments flowing.