Invoice Fraud in 2026: Anatomy of a Fake Invoice, and How AI Is Scaling the Threat
A real invoice fraud attempt hit Keepnet's inbox: a clean PDF, no link, no malware, and every authentication check passing. Here is the anatomy of the attack, why AI is scaling it, and how to stop it.
Ozan Ucar, Founder and CEO of Keepnet
What is invoice fraud?
Invoice fraud is a scam in which a criminal sends a business a fake or altered invoice, or a request to change payment details, to trick the finance team into paying money into an account the attacker controls. It is one of the most common forms of business email compromise (BEC). The invoice usually looks completely legitimate. No dodgy link, no malware, just a convincing document and a bit of urgency. That is exactly what makes it so hard to catch.
Key takeaways
- Modern invoice fraud carries no link and no malware; it targets a human decision, not your software.
- The attack we received passed authentication (SPF, DKIM and DMARC) and still tried to move nearly £10,000.
- AI has collapsed the cost of producing convincing, company-specific fake invoices at scale.
- The controls that actually work are human: out-of-band verification (confirming through a separate, known channel such as a phone call, never a reply), dual approval on any bank-detail change, and one-click reporting.
It landed in our own inbox
A few days ago, an invoice fraud attempt landed in an inbox here at Keepnet. We build human risk technology for a living, so it was a healthy reminder that nobody gets a free pass, not even the people who make the tools. (It is not the first time we have taken a live attack in our own inbox apart.)
The email was short and polite: “Please arrange payment for the attached invoice today.” It carried my name. Attached was a clean, one-page PDF invoice from “Woburn Consulting Group Ltd” for professional services, executive coaching and strategic research, for £9,974.84. There was no link to click. There was no attachment to detonate. Nothing for a scanner to flag.
That is the point, and it is worth sitting with for a second. The most effective invoice fraud in 2026 does not break into anything. It borrows your trust, leans on your routine, adds a little urgency, and asks a real person to move real money. So we did what we tell every customer to do. We did not pay. We pulled the message apart instead.

How does invoice fraud work? What the headers gave away
On the surface, the message looked like it came from inside the company. Underneath, four different identities were fighting each other.
The four-identity mismatch. The visible sender read as an internal address. The Reply-To pointed somewhere else entirely, a personal ProtonMail account. The true originating system was a third, unrelated domain that sent the message through Amazon's cloud email service, the kind of legitimate sending platform anyone can rent on demand. And the “forwarded” invoice thread quoted a fourth party, the supposed consulting firm. One message, four addresses that should never appear together on a genuine invoice.

The automated checks all passed, and here is why that matters. SPF, DKIM and DMARC are the automated checks that confirm an email really came from where it claims. In this case, all three returned “pass,” and that is exactly what fooled the eye. Here is the mechanism. The message genuinely came from outside, an unrelated domain sending through Amazon's service. But it was routed through an internal group address, which then re-sent it to members from trusted internal infrastructure. At that moment the checks aligned to our own domain, so they passed. An outside email had been laundered into an internally authenticated one. The checks were telling the truth about the delivery path and nothing at all about the invoice. Authentication verifies the envelope, not the truth inside it.


The reply trap. If anyone had hit “Reply,” their message would not have gone to a colleague. It would have gone straight to the attacker's personal mailbox, where the criminal would happily supply “the correct bank details”. This is the norm, not the exception: the Anti-Phishing Working Group found that 69% of BEC messages in the fourth quarter of 2025 used free webmail accounts, often in the sender or the reply address, precisely because the attacker wants replies flowing to a mailbox they control (Anti-Phishing Working Group, Phishing Activity Trends Report, Q4 2025, pp. 11-12).
The number was chosen carefully. £9,974.84 is not random. It sits just below the £10,000 line that triggers extra scrutiny in many finance functions. VAT was listed at 0% to keep the total clean and unremarkable. And a line on the invoice instructed that “payment is remitted directly to the consultant responsible for the engagement”, which is textbook payment-redirection language.

The PDF was mass-produced by software. When we inspected the document, its metadata showed it had been rendered programmatically by a browser engine, consistent with automated, templated production rather than a one-off document typed by a person. On its own that is a weak signal, since plenty of legitimate billing systems render PDFs the same way; it is the company it keeps that matters. We cannot prove a language model wrote the wording, and that is not the point. Structurally the file was inert: no active code, no auto-open behaviour, nothing hidden inside. It was built to pass every “is this file dangerous?” test while carrying a dangerous request. In security terms the attachment is a lure, not a weapon; the objective was never to infect a machine, it was financial theft.
Put those findings together and you have the modern shape of invoice fraud: authentic-looking, technically clean, socially engineered, and aimed squarely at a busy person in finance. One more free check worth building into the routine: a quick domain-age lookup often shows that a “long-standing supplier” domain was in fact registered only weeks ago.
What are the red flags of a fake invoice?
Most invoice fraud shares the same handful of tells. Put this list in front of anyone who touches payments.
- A new or changed bank account, or a request to update remittance details.
- An amount set just below your approval threshold (ours was priced at £9,974.84 for a reason).
- Pressure to pay quickly: “today,” “urgent,” “before end of day.”
- A Reply-To address that differs from the display name, often a free webmail account.
- A first-time, vaguely described charge such as “consulting” or “executive coaching.”
- Instructions to pay a person directly rather than a company account.
- A supplier domain that does not quite match, or was registered very recently.
Why this kind of attack works
Traditional defences were built to catch bad links and bad files. This attack has neither, and that is the whole trick. It plays on the shortcuts we all use. A familiar name and a routine ask, so it feels ordinary. A touch of urgency, so it feels time-sensitive but not alarming. Clean technical checks, so the tools wave it through. And a hidden reply address, so a quick glance at the sender reassures you instead of warning you.
People are the last line of processing for this message, and the whole attack is engineered around that fact. The human element now appears in 62% of breaches, up from 60% the year before, according to the Verizon 2026 Data Breach Investigations Report (Verizon, 2026 Data Breach Investigations Report, p. 12, p. 19). Invoice fraud is not an edge case; it is the mainstream.
Invoice fraud in 2026: the numbers
The single attempt we received is a drop from a very large tap.
The FBI's Internet Crime Complaint Center recorded $3.05 billion in reported BEC losses across 24,768 complaints in its 2025 annual report, up from $2.77 billion the year before (FBI IC3, 2025 Internet Crime Report). Phishing and spoofing were the single most reported crime type, with 191,561 complaints, a pattern borne out by the wider phishing statistics. Across all internet crime, reported losses reached $20.877 billion, a 26% increase on the previous year (FBI IC3, 2025 Internet Crime Report).
The requests are also getting bigger. The Anti-Phishing Working Group reported that the average wire-transfer amount requested in BEC attacks reached $50,297 in the fourth quarter of 2025, and that the volume of wire-transfer BEC attacks rose 136% over the previous quarter (Anti-Phishing Working Group, Phishing Activity Trends Report, Q4 2025, pp. 11-12). A single BEC attack can now carry a five-figure loss.
For readers in the UK, the pattern holds close to home: phishing hit 38% of all UK businesses in the past year, the most common and most disruptive attack type (UK Department for Science, Innovation and Technology, Cyber Security Breaches Survey 2025/26).


When the impersonated party is a supplier rather than an executive, this same tactic is often called vendor email compromise (VEC); when it is a boss demanding an urgent transfer, CEO fraud. They are branches of the same tree, and invoice fraud is the most common form of payment fraud aimed at accounts-payable teams.

The AI accelerant: one attacker, thousands of tailored invoices
Here is what has actually changed since 2019. This is AI phishing pointed straight at the finance team, and it quietly rewrites the economics of the whole attack.
Producing a convincing, company-specific invoice used to take effort. A criminal had to research the target, mimic a real vendor, get the branding roughly right, write clean business English, and generate a professional-looking PDF. That friction limited how many high-quality lures one person could send.
Generative AI has removed almost all of that friction. The same tooling that helps legitimate teams draft documents can, in the wrong hands, scrape a target's public vendor relationships, write flawless and context-aware copy, and generate a polished invoice PDF on demand. Our invoice was produced by software in seconds. Producing a thousand more, each personalised to a different company, a different “vendor,” a different amount tuned just under that company's approval line, is now trivial and cheap.
The effectiveness is climbing too. Microsoft's threat researchers found that AI-generated phishing achieved a 54% click-through rate versus 12% for traditional phishing, roughly four and a half times more effective (Microsoft Digital Defense Report 2025; figures from Microsoft's incident-response and Defender dataset, not a global breach census). Gartner reports that 84% of security leaders have observed more advanced, AI-assisted phishing in their organisations (Gartner, “Cybersecurity Trend: GenAI Breaks Traditional Cybersecurity Awareness Tactics,” G00840678, January 2026; 2025 Gartner Cybersecurity Innovations in AI Risk Management Survey, n=302).
The uncomfortable summary: the cost of producing a believable fake invoice has collapsed, and its effectiveness has risen. Volume and quality used to be a trade-off for attackers. AI removed the trade-off.

This is already happening to real companies
Invoice and payment fraud has hit organisations of every size, and the named cases make the pattern concrete.
And it is not just the tech giants. A US parish lost around $1.75 million during a church restoration when someone posing as the builder emailed over "new" bank details; the FBI confirmed the case, and the amount comes from later reporting. In June 2023 an attacker compromised a furniture supplier’s email system and changed the payment details Children’s Healthcare of Atlanta held on file, and the hospital wired $5.3 million to an account the attacker controlled; both parties spotted it within days and roughly $4 million was recovered. A school district in North Dakota was hit too, and there the FBI and prosecutors seized $4.86 million, with forfeiture proceedings under way to return it to the district. Different worlds, same move.
Google and Facebook, more than 100 million dollars. Between 2013 and 2015, a Lithuanian operator impersonated a real hardware supplier and sent a stream of fake invoices to two of the most sophisticated technology companies on earth. Both paid. The US Department of Justice put the theft at over $120 million and did not name the companies; those names come from later reporting. Evaldas Rimasauskas was sentenced to five years in prison and ordered to forfeit $49.7 million. If it can happen to them, the "we would obviously notice" assumption deserves a hard look.
Arup, about $25.6 million in a single day. In early 2024, an employee at the engineering firm Arup was convinced to authorise 15 transfers after joining a video call populated by deepfake versions of the company's CFO and colleagues. It began, as these so often do, with a message about a confidential financial matter (Hong Kong Police, reported via CNN, February 2024). And it did not stop with Arup. In March 2025 a finance director at a firm in Singapore approved a $499,000 transfer after a video call with his “leadership”; every face on that call was a deepfake too. He grew suspicious when a second, larger demand arrived, and Singapore and Hong Kong police traced and blocked the funds two days later (Singapore Police Force, April 2025).
The “fake executive coaching invoice” wave. Through 2024 and 2025, the Anti-Phishing Working Group tracked a sustained BEC campaign aimed at accounts-payable teams using fabricated invoices for executive coaching and consulting services (Anti-Phishing Working Group, Phishing Activity Trends Report, Q4 2025, pp. 11-12). The invoice we received, for “executive coaching, leadership development and strategic research,” fits that template precisely.
And the flip side: reporting works. In one FBI-documented case, a business email compromise diverted a $956,342 wire, but fast reporting let the FBI's Recovery Asset Team freeze $955,060 of it (FBI IC3 2024 Internet Crime Report). The difference between a catastrophe and a near-miss was speed.

Very different organisations, one common thread: a person was asked to move money based on a message that looked completely normal.
And here is what the case studies always leave out. The wins are quiet. Nobody writes a press release about the accounts-payable clerk who felt a bit awkward, picked up the phone anyway, and stopped a transfer before it left the building. Those saves happen every day. They just never trend.
Why email security alone is not enough
If your whole plan for invoice fraud is “our email filter will catch it,” then this attack was built with you in mind.
Gateways and filters are essential, and they stop enormous volumes of junk. But the message we received passed authentication, carried no malicious payload, and used clean, professional language. To a machine looking for links and malware, there was nothing to see. The maliciousness lived entirely in the request, not in the code.
You cannot patch judgment. When an attack is engineered to look legitimate and to slip past technical controls, the deciding factor becomes whether the person on the other end pauses, recognises the pattern, and verifies before acting. That is a human capability, and like any capability it has to be built and maintained.
The human layer: turn your finance and executive teams into sensors
Here is the good news, and it tends to surprise people. The same folks the attackers target are also your best detection system, once they are ready for it. Two habits do most of the work.

First, verification as a reflex. Any change to payment details, and any unexpected “pay this today” request, gets confirmed through a known, independent channel. The number you call must come from your own vendor master record, set up at onboarding, never the contact details on the invoice or in the email, because those can be part of the fraud. Give the caller a simple script: “I am calling to confirm a change to the bank account we hold for you; can you read back the account already on file with us?” For a brand-new supplier with nothing yet on file, source the number from a signed onboarding form or the vendor's official published details, never from the invoice that introduced them. This one habit neutralises most invoice fraud, because the whole scheme depends on the victim never making that call.
Second, reporting as a habit. When someone spots something odd, they need a one-click way to report it, and they need to trust that reporting is welcomed rather than punished. A single reported invoice can protect the entire finance team, because the same lure is rarely sent to just one person. A strong reporting culture turns one alert employee into an early-warning system for everyone.
These are not posters on a wall. They are trained behaviours, reinforced at the moment they matter, and measured over time.
Preventing recurrence: build Secure Behavior Management
Stopping this attack once is luck. Stopping it every time is a system. Awareness campaigns that end in a completion certificate do not change what a busy person does at 4pm on a Friday; Gartner notes that 84% of leaders track training completion as a top metric even though the human element still appears in 62% of breaches (Gartner, “6 Ways to Transform Your Cybersecurity Awareness Program,” G00840741, March 2026; 2025 Secure Behavior Strategies Survey, n=65). Completion is not behaviour. The durable fix is what Gartner now calls Secure Behavior Management: help people build better security habits, and keep the flywheel turning.
A quick word on language, because it matters more than it looks. The old line that people are the “weakest link” has not aged well. Give them the right tools and a moment to think, and the very same people become one of your strongest defences. That is the whole idea here: not catching people out, but helping them get good at spotting this, and making it easy to do the right thing.

This is the problem we built Keepnet to solve. Our Extended Human Risk Management Platform and Secure Behavior Management (xHRM) is built to help your people pick up secure habits, so the human layer becomes one of your strongest defences. Invoice fraud is a case it handles directly.
Simulations that mirror the real thing. Keepnet's Phishing Simulator generates realistic, localised invoice-fraud and BEC scenarios at scale rather than recycling a handful of generic templates. You can run the exact pattern described in this article, a clean PDF invoice, a plausible vendor, an amount tuned just under an approval threshold, a payment-redirection line, against the people who would actually receive it, and see who pays, who pauses, and who reports.
Role-based scenarios for finance and executives. The employees who authorise payments face different attacks than the rest of the workforce, so they should train against different scenarios. Keepnet targets accounts-payable, finance and executive teams with invoice-fraud, vendor-impersonation and CEO-fraud simulations built for their real workflows.
Microlearning at the teachable moment. When someone engages with a simulated invoice-fraud email, they get short, focused security awareness training then and there, while the lesson is concrete. Brief, timely and specific beats long and annual.
A reporting habit that scales. The Keepnet Phishing Reporter gives every employee a one-click way to flag a suspicious message and routes it to the Incident Responder for fast triage and response. Over time you are not just training people, you are building a workforce that feeds your security team real signals about live threats.
We hold ourselves to the same standard we set for customers. We run personalised phishing simulations and training for our own team, and we give everyone one-click reporting so they can flag anything that feels wrong. Against the attacks that hit finance hardest, invoice fraud and CEO fraud, we run the same controls we recommend to customers, including dual approval before any payment or change of bank details. Practice plus a hard process is what turns a lucky catch into a reliable one.
Ozan Ucar, Founder and CEO, Keepnet
We are deliberately not going to tell you that Keepnet makes invoice fraud impossible. Nothing does. What a well-run secure-behaviour programme does is move the numbers in the right direction: more people spot the lure, more people report it, and they do both faster. Against an attack that comes down to a single human decision, that is the whole game.
Invoice fraud prevention: a practical playbook
You can start most of this tomorrow, with or without new technology.
- Verify out of band. Confirm every new or changed payment instruction by calling a known contact on a number from your vendor master record, not from the message. Use a fixed script and log the call.
- Zero-threshold dual approval on bank-detail changes. Any change to a supplier's bank account requires two people, at any amount. Keep payment approval limits confidential, because the attacker will happily price the invoice just below a limit they can guess (as ours was). The second approver's job is not to re-read the email; it is to confirm that the out-of-band check actually happened.
- Slow the “urgent” ones down. Treat urgency as a reason to check, not a reason to rush. Legitimate suppliers understand a verification call.
- Check the reply address, not just the display name. Teach finance staff to expand the real Reply-To, where these attacks hide, and to glance at the supplier's domain.
- Make reporting effortless. Give everyone a one-click reporting button and thank the people who use it, even when they are wrong.
- Train the people who are actually targeted. Run realistic, role-based invoice-fraud and BEC simulations for finance and executives, and reinforce with microlearning when someone slips.

If you have already been hit: an incident-response playbook
If a payment has gone out, or you suspect one is about to, speed is everything. The chance of clawing the money back falls sharply after the first day, so treat the next few hours as an incident, not an email.

- Call your bank in the first hour. Ask the fraud team to recall the payment and to issue any indemnity the receiving bank needs. Do this before anything else; a recall attempted within hours can still catch the funds before they are withdrawn.
- Report it and trigger a freeze. In the US, file at ic3.gov and ask that it be flagged for the FBI's Recovery Asset Team; the Financial Fraud Kill Chain can freeze domestic wires of $50,000 or more when they are reported within roughly 72 hours (FBI IC3). Consider notifying the US Secret Service too. In the UK, tell your bank and report to Action Fraud.
- Preserve everything, and do not reply. Keep the email, its headers and the invoice; delete nothing, and do not respond to the sender. Save the transaction references and write a short timeline of who did what and when. That is what lets your bank and investigators act quickly.
- Work out whether it was a spoof or a break-in. The attack we received was an external spoof, but many invoice frauds ride on a genuinely compromised mailbox, yours or a supplier's. Check for mail rules or auto-forwarding you did not create, unfamiliar sign-ins, and items in Sent or Deleted that you did not send. Hidden forwarding rules are the most common way an attacker keeps reading your mail after a password change.
- If an account is compromised, contain it. Reset the password, revoke all active sessions and tokens, remove any rogue rules and connected-app grants, and enforce multi-factor authentication. Scope which accounts and data were exposed, review the sign-in and mail-flow logs, and bring in your incident-response or forensics team if the picture is not clear.
- Notify the people who need to know. Tell your cyber or crime insurer promptly, because policies carry strict notification conditions; warn any supplier or customer caught up in the thread; and check your breach-notification duties, since a personal-data breach in the UK or EU may need to reach the regulator within 72 hours. Then alert your own staff, because the same lure is rarely sent to a single inbox.
On getting the money back. Treat recovery as a bonus, not a plan. In the UK, mandatory reimbursement for authorised push-payment fraud came into force on 7 October 2024, shared between the sending and receiving banks up to a limit of £85,000; note that it covers consumers, micro-enterprises and charities, so larger businesses should not assume they are protected (UK Payment Systems Regulator). In most other places reimbursement is discretionary. Prevention and speed matter far more than any claim.
Ozan Ucar is the Founder and CEO of Keepnet. Keepnet's Extended Human Risk Management Platform and Secure Behavior Management (xHRM) helps organisations simulate real attacks, train people at the moment it matters, and turn everyday employees into a reporting network that protects the business.