---
title: "Vendor fraud: types, examples and how to prevent it"
description: "What vendor fraud is, the most common schemes (vendor impersonation, fake bank changes, fake invoices) and the controls that stop them."
url: https://realpayee.com/vendor-fraud
canonical: https://realpayee.com/vendor-fraud
date_published: 2026-10-05
date_modified: 2026-10-05
updated: 2026-10-05
author: "RealPayee"
site: RealPayee
---

# Vendor fraud: types, examples and how to prevent it

> **Vendor fraud** is any scheme that steals money through a company's supplier payments. It comes from outsiders impersonating a real vendor - fake bank-change requests and fake invoices sent from compromised or lookalike email accounts - and from insiders who create fictitious vendors or inflate bills. The most effective prevention is out-of-band verification of every bank-detail change plus separation of vendor-master and payment duties.

_Updated 2026-10-05 · 9 min read_

## Key takeaways

- There are two families of vendor fraud: **external impersonation** (someone pretending to be your supplier) and **internal schemes** (fake vendors, kickbacks, duplicate billing).
- **Vendor impersonation fraud** is one of the most common schemes today: in the AFP's 2025 survey, 45% of organizations reported vendor imposter fraud, up 11 points.
- Accounts payable fraud detection relies on a few high-signal reports: vendor master changes, bank accounts shared between vendors or with employees, and first payments to new details.
- Prevention is mostly process: verify changes with a known contact, separate duties, hold first payments, and keep evidence.

## What is vendor fraud?

Vendor fraud - also called supplier fraud or, when it runs through AP, accounts payable fraud - is any scheme in which money intended for, or appearing to be owed to, a supplier ends up with someone who is not entitled to it. The supplier may be real and impersonated, real and complicit, or entirely invented.

It matters because supplier payments are high-volume, routine and trusted. The AFP's 2026 Payments Fraud and Control Survey found that **76% of organizations** experienced attempted or actual payments fraud in 2025, and **74%** were targeted by business email compromise - up from 63% the year before. The FBI's IC3 logged roughly $3.0 billion in BEC losses in 2025.

## Types of vendor fraud

| Scheme | Who does it | How it works | Key control |
| --- | --- | --- | --- |
| Vendor impersonation / bank-change fraud | External | Fraudster poses as a real supplier and asks AP to change its bank details | Out-of-band callback to a known contact; hold first payment |
| Fake or altered invoices | External | A real-looking invoice for a real vendor, with new payment instructions or inflated amounts | Three-way match; pay only to verified details in the vendor master |
| Compromised vendor email (supplier account takeover) | External | Attacker controls the vendor's real mailbox and replies on genuine threads | Treat in-thread changes like any other - verify by phone from your records |
| Fictitious or shell vendor | Internal (sometimes with outsiders) | An employee creates a vendor that does not exist and approves its invoices | Segregation of duties; TIN match; compare vendor and employee bank accounts and addresses |
| Duplicate billing | Either | The same invoice is paid twice, sometimes with a slightly altered number | Duplicate-invoice detection in the ERP or AP platform |
| Overbilling and kickbacks | Internal + real vendor | Inflated prices or phantom quantities, with a share returned to the employee | Contract price checks, receiving controls, rotation of buyer relationships |

Internal schemes are serious, but the fastest-growing losses come from impersonation, because the attacker does not need anyone inside your company - just one change request that slips through.

## Vendor impersonation fraud: how an attack unfolds

The following is an illustrative composite of a typical vendor impersonation attack, not a specific case:

1. **Reconnaissance.** The attacker phishes an employee at one of your suppliers, or registers a domain one character away from theirs. Public info - press releases, LinkedIn, procurement portals - tells them who your AP contacts are.
2. **Observation.** With mailbox access, they read past invoice threads to learn amounts, timing, invoice formats and who signs off.
3. **The ask.** Shortly before a payment run, a message arrives on a familiar thread: “We've changed banks - please use the attached details for all future payments.” A professional-looking letter is attached.
4. **Pressure.** If AP hesitates, a follow-up arrives: the old account is closed, invoices are overdue, the account manager is travelling and can only email.
5. **The payment.** AP updates the vendor master. Legitimate invoices are paid - to the wrong account. Money is moved on quickly.
6. **Discovery.** The real vendor chases payment. By then recovery depends on how quickly the bank can act.

Generative AI makes each step cheaper: emails in perfect tone, convincing letterheads, even cloned voices if the target asks for a call. The IC3 noted that more than $30 million of 2025 BEC losses had a confirmed AI nexus. That is why verification has to rely on **who** you reach and **how**, not on how convincing a message looks.

## Warning signs of vendor fraud

- A bank-detail change arrives by email, especially combined with urgency or an overdue-invoice reminder.
- Sender domain, reply-to address or display name differs subtly from earlier messages.
- The new account holder name does not match the vendor's legal name, or the bank is in a new country.
- A vendor contact you have spoken to for years suddenly “can only email”.
- A new vendor receives a large payment soon after creation, or its address is a PO box or matches an employee's.
- Invoices with round numbers, sequential invoice numbers from a supposedly busy vendor, or amounts just below an approval threshold.
- The same bank account appears on more than one vendor record.

## Accounts payable fraud detection: the reports that matter

Detection will never replace verification before payment, but a handful of reports run weekly catch most schemes that slipped through - and give you evidence your controls work.

| Report | What it catches | Frequency |
| --- | --- | --- |
| Vendor master change log (bank, address, contacts) | Unverified or unauthorized bank changes; changes reverted after a payment | Weekly, and before each payment run |
| First payment to new bank details | Impersonation payouts before they repeat | Every payment run |
| Shared bank accounts across vendors or with employee payroll | Fictitious vendors, conflicts of interest | Monthly |
| Duplicate invoice numbers and amounts | Double payments, altered invoice numbers | Every payment run |
| Invoices just under approval limits | Split invoices to avoid approval | Monthly |
| New vendors paid within days of creation | Shell vendors, rushed onboarding | Monthly |
| Dormant vendors reactivated | Takeover of old vendor records | Monthly |

> [!TIP]
> **Make the change log someone's job**
> Assign a named reviewer - not the person who makes vendor changes - to sign off the vendor master change report every week. It is one of the cheapest controls you can run.

## How to prevent vendor fraud: a control matrix

| Control | Stops | Owner |
| --- | --- | --- |
| Out-of-band callback to a known contact for every bank change | Impersonation, compromised vendor email | AP |
| Bank account ownership validation | Mule accounts in mismatched names; typos | AP / AP platform |
| Segregation of duties: vendor setup ≠ invoice approval ≠ payment release | Fictitious vendors, self-approval | Controller |
| Dual approval for vendor master changes | Single-person errors and insider changes | Controller |
| Hold or cap the first payment to new bank details | Large losses from a single missed check | Treasury / AP |
| Three-way match (PO, receipt, invoice) | Fake and inflated invoices | AP / Procurement |
| Email warning banners for external senders and lookalike domains | Some impersonation emails | IT |
| Training with real examples and a no-blame escalation path | Pressure tactics and urgency | Finance leadership |
| Documented audit trail of each verification | Disputes with insurers and auditors | AP |

For a ready-to-use procedure, start with the [vendor bank-change policy template](https://realpayee.com/templates/vendor-bank-change-policy), and see our [vendor verification guide](https://realpayee.com/vendor-verification) for the step-by-step callback.

## What to do if you've paid a fraudster

1. **Call your bank immediately** and ask it to recall the payment and contact the receiving bank. Minutes and hours matter.
2. **File a complaint with the FBI's IC3** at ic3.gov and include transaction details.
3. **Preserve evidence**: emails with full headers, attachments, call logs and the vendor master change history.
4. **Contact the real vendor** through known details, and warn them their mailbox may be compromised.
5. **Notify your insurer** promptly; social engineering coverage often has notice requirements.
6. **Review and fix** the gap: which control was skipped, and why.

## Where RealPayee fits

[RealPayee](https://realpayee.com) focuses on the impersonation side of vendor fraud. When a vendor bank detail changes in your ERP or AP platform, the change is held until the vendor's known contact verifies out-of-band - a phone-bound approval or ID plus live selfie - and the result is written to an audit record. It works alongside account-validation tools rather than replacing them.

## Frequently asked questions

### What is vendor fraud?

Vendor fraud is any scheme that steals money through supplier payments, either by impersonating a real vendor (for example, a fake bank-change request) or by insiders creating fake vendors, inflating invoices or billing twice.

### What is vendor impersonation fraud?

Vendor impersonation fraud is when a criminal poses as one of your real suppliers - usually by email from a compromised or lookalike account - and asks you to pay its invoices into a new bank account the criminal controls.

### What is accounts payable fraud?

Accounts payable fraud is fraud that exploits the AP process: fake or altered invoices, fictitious vendors, duplicate payments, unauthorized vendor master changes and impersonation of suppliers.

### How do you detect accounts payable fraud?

Review the vendor master change log, first payments to new bank details, bank accounts shared between vendors or with employees, duplicate invoices and invoices just under approval limits. Then confirm anything unusual with the vendor through known contact details.

### Does insurance cover vendor impersonation losses?

Sometimes. Standard crime policies may exclude voluntarily authorized transfers; social engineering fraud coverage is often a separate endorsement with sub-limits and verification conditions. Check your policy wording with your broker.

## Sources

- [AFP - Over 75 percent of U.S. firms experienced payments fraud in 2025 (2026 Payments Fraud and Control Survey)](https://www.financialprofessionals.org/about/learn-more/press-releases/Details/over-75-percent-of-us-firms-experienced-payments-fraud-in-2025-while-ai-adoption-for-fraud-mitigation-lags)
- [AFP - Survey: 79 percent of organizations were victims of attempted or actual payments fraud in 2024](https://www.financialprofessionals.org/about/learn-more/press-releases/Details/survey-79-percent-of-organizations-were-victims-of-attempted-or-actual-payments-fraud-activity-in-2024)
- [McDonald Hopkins - The sobering truth of the FBI's 2025 Internet Crime Complaint Center report](https://www.mcdonaldhopkins.com/insights/news/the-sobering-truth-of-the-fbis-2025-internet-crime-complaint-center-report)

## Related

- [Vendor verification: how to verify vendor bank details before you pay](https://realpayee.com/vendor-verification) - A practical guide to vendor verification for finance teams: how to confirm vendor bank-detail changes, run callbacks, and prevent vendor impersonation fraud. (markdown: https://realpayee.com/vendor-verification.md)
- [Free vendor bank-change verification policy template](https://realpayee.com/templates/vendor-bank-change-policy) - A free, copy-ready vendor bank-detail change and callback verification policy template plus checklist for AP teams. (markdown: https://realpayee.com/templates/vendor-bank-change-policy.md)
- [Wire fraud prevention: how to stop bank wire fraud](https://realpayee.com/wire-fraud-prevention) - Controls that prevent business wire fraud: out-of-band verification, payment thresholds, dual approval and audit trails. (markdown: https://realpayee.com/wire-fraud-prevention.md)
- [CEO fraud and deepfake executive calls: how finance teams stop them](https://realpayee.com/ceo-fraud) - How CEO fraud works - from spoofed emails to deepfake video calls - and the verification steps that stop fake payment requests. (markdown: https://realpayee.com/ceo-fraud.md)

---

**Further reading**
- [Vendor verification guide](https://realpayee.com/vendor-verification.md)
- [Free vendor bank-change policy template](https://realpayee.com/templates/vendor-bank-change-policy.md)
- [Compare: callbacks vs bank-account validation vs RealPayee](https://realpayee.com/compare.md)
- [Pricing](https://realpayee.com/pricing.md)

Canonical HTML: https://realpayee.com/vendor-fraud · Site index for AI agents: https://realpayee.com/llms.txt?src=md-footer · Pricing: https://realpayee.com/pricing.md · Book a demo: https://realpayee.com/demo
