Invoice & Vendor Fraud: How to Protect Your Business

Reviewed by IT Cares certified technicians · Updated August 2026

Accounts payable employee reviewing a suspicious vendor invoice on screen before processing a wire transfer
The "banking details changed" email can look exactly like your vendor's real invoices. The phone call that verifies it is what actually stops the fraud.
🧾
Does your accounts payable team have a vendor verification protocol? Our certified technicians can review your AP process and vendor-file security.
Get a Free Assessment →

Invoice and vendor fraud is a specific, narrow scam: an attacker impersonates a real supplier your business already pays — not a fake new vendor, not your own CEO — and sends a routine-looking notice claiming their banking details changed, timed to land right around a real invoice you were already expecting to pay. It's a distinct and particularly dangerous subset of the broader Business Email Compromise (BEC) category, which also covers CEO/executive fraud, payroll diversion, and legal/real estate transaction fraud. Our broader BEC guide covers all of those scenarios; this guide goes deep specifically on the vendor-impersonation, banking-detail-change scam, because it targets one department — accounts payable — through a mechanism that's meaningfully different from an urgent request supposedly from a company executive.

This guide covers exactly how the scam works step by step, the warning signs specific to a fake vendor banking-detail change, a verification protocol built specifically for this scenario, real Canadian case studies with dollar amounts, honest CAD cost ranges, and Canadian reporting resources.

Who wrote this guide

This guide was written and reviewed by IT Cares certified technicians based on helping Canadian SMBs review and harden accounts payable processes against vendor impersonation fraud specifically. The verification protocol described here requires no specialized software and can be adopted by a business of any size starting today.

What Invoice & Vendor Fraud Actually Is

Vendor fraud targets accounts payable with one specific goal: get the banking details on file for an already-known supplier changed, so the next payment — and often several payments after it — is deposited into an account the attacker controls instead of the real vendor's account. Unlike CEO fraud, which relies on the perceived authority of an executive and the urgency of a one-time request, vendor fraud relies on familiarity. The vendor's name, invoice format, and sometimes even the tone of their emails are already well known to the person processing the request, which naturally lowers their guard compared to a request from an unfamiliar sender.

The trigger is almost always framed as a routine administrative update — "we've switched banks," "our accounting department has updated our records" — often accompanied by an invoice that looks exactly like the vendor's usual ones, sometimes even carrying a correct business number since that information is frequently public or already visible on old, legitimate invoices. The request is nearly always timed to land around a real, expected payment, which makes it feel like a natural part of the normal billing cycle rather than an isolated, suspicious ask.

The "trusted vendor" trap

Much of what makes this fraud effective is that it specifically targets long-established vendor relationships, not new ones. Staff naturally process a request from a supplier the business has worked with for years with far less scrutiny than a request from a new contact, precisely because the relationship already feels "proven." Attackers know this and deliberately target established relationships rather than recent vendors, where verification would feel more natural and less like an inconvenience.

How the Scam Actually Unfolds, Step by Step

Understanding the exact mechanics helps accounts payable staff recognize the pattern rather than searching only for spelling mistakes or obvious red flags — both frequently absent from the cases that succeed.

Step one: identifying a vendor relationship worth targeting

The attacker first identifies an active, sufficiently valuable vendor relationship to target. This information sometimes comes from public sources — public tenders, project announcements, invoices or purchase orders accidentally posted online — or from quietly monitoring email threads if an account has already been compromised on either side of the relationship. In documented cases, it's often the vendor itself that was compromised weeks earlier without even realizing it, giving the attacker direct, extended access to real conversations with several of that vendor's clients at once.

Step two: two distinct technical vectors

Two main methods let the attacker send a convincing email. The first, a genuinely compromised vendor email account, is the more dangerous: the email literally comes from the real address, sometimes inserted directly into an existing thread, and can even intercept a real invoice to swap in new banking details before forwarding it along. The second, a lookalike domain, involves registering a domain nearly identical to the vendor's — a swapped letter, an added hyphen, a different top-level domain — close enough to fool a quick glance, especially on a mobile device.

Step three: timing chosen to maximize plausibility

The banking-detail-change request rarely arrives at random. It's most often timed to coincide with a real, already-issued invoice or a known payment deadline, which gives accounts payable staff the impression that the change fits naturally into the normal billing cycle rather than appearing as an isolated, suspicious request.

Step four: a request dressed as routine paperwork

The email itself almost always adopts a neutral, bureaucratic tone — "following a change of financial institution," "for internal accounting update purposes" — rather than an urgent or dramatic one. It's frequently accompanied by a new void cheque, banking form, or vendor-change document that gives an impression of documentary legitimacy. In more sophisticated cases, a "confirmation" phone call follows the email, but from an unlisted number that only reinforces the request's apparent credibility rather than providing any real independent verification.

Step five: the transfer and the delayed discovery

Once the new details are applied to the vendor file, every subsequent payment is automatically redirected to the fraudulent account, often across several billing cycles before anyone notices. The fraud is almost always discovered the same way: the real vendor reaches out about a late payment, revealing that the funds sent never reached their actual account.

Want your AP process reviewed before it's tested for real?

Our certified technicians can review your vendor verification procedures and accounting-system alerts — from $119.99.

Warning Signs Specific to Vendor Banking-Detail Fraud

Warning Sign Why It's Deceptive Recommended Action
Banking-detail change reported by email only Framed as a routine, unremarkable administrative update Always confirm by phone using a number already on file
New void cheque or banking form attached Creates a sense of documentary legitimacy Compare against the existing vendor file, then verify verbally
Tone or signature subtly different from the usual contact Easy to miss when the display name and format look identical Train AP staff on the vendor contact's normal writing style
Request timed to a real invoice already due Creates apparent legitimate urgency that lowers scrutiny Verify even when the amount and due date match perfectly
Sender domain slightly different from usual Nearly invisible to the eye, especially on mobile Anti-spoofing filters plus manual check of the full domain
"Confirmation" call from an unlisted number Artificially reinforces the original email's credibility Only call back the number already on file, never the one provided

Verification Protocol Before Changing Any Vendor Banking Detail

Unlike a one-time wire supposedly requested by an "executive," a vendor banking-detail change has a lasting effect: once applied to the file, it silently redirects every future payment until someone notices. That's exactly why this specific type of change deserves a more rigorous verification protocol than confirming a single isolated transfer.

1

Freeze any payment tied to the change

No payment should go to the new account until verification is fully complete, even if the invoice due date has already passed by a few days.

2

Call the vendor's known contact

Use only the phone number already on file in your vendor record or on a prior confirmed invoice — never one supplied in the change-request email, and never one provided in a follow-up "confirmation" call.

3

Require written confirmation on letterhead

Ask for official confirmation on the vendor's usual letterhead, ideally signed by a contact your business already knows, in addition to — not instead of — the phone verification.

4

Confirm the vendor's legal registration

Verify that the legal business name and registered business number still match your existing vendor file, which helps catch a broader impersonation of the company itself rather than just its banking details.

5

Apply a grace period and a test payment

For significant amounts, send a small test payment to the new account first and confirm receipt before releasing the full balance, with a minimum 24-48 hour hold between the change request and the first full payment.

Vendor Fraud Prevention Checklist

Real Canadian Vendor Fraud Case Studies

The following are composite scenarios based on patterns IT Cares technicians have encountered and reviewed with Canadian business clients, anonymized and combined rather than describing any single identifiable client.

Case study 1: The packaging supplier "bank switch" (Hamilton, ON)

An accounts payable clerk at a mid-sized food distribution company received an email appearing to come from a packaging supplier's accounts receivable contact, stating the supplier had "switched banks" and providing new wire instructions for an upcoming payment of $61,200 CAD already due that week. The request arrived from a domain one character different from the vendor's real one. Because company policy required a phone call to a previously verified vendor contact before any banking change was applied, the clerk called the real supplier directly and learned no such change had ever been requested. The fraudulent request was blocked before any funds moved.

Case study 2: The compromised construction supplier (Kelowna, BC)

A residential construction company received, from the real and authentic email address of its main building-materials supplier — whose account had been compromised without their knowledge — a banking-detail change notice inserted directly into an existing thread about an active order. No phone verification was performed, since the company had no formal protocol at the time for vendor banking-detail changes specifically. A payment of $112,400 CAD was sent to the new account. The fraud was only discovered three weeks later when the real supplier followed up about an overdue payment. Despite a prompt report to the bank, only a limited portion of the funds was recovered. The company has since adopted a dual-channel verification protocol and a mandatory hold period for any vendor banking-detail change.

Case study 3: The recurring small-invoice fraud (Sherbrooke, QC)

An office administrator at a small dental clinic received, over two consecutive billing cycles, an email appearing to come from the clinic's regular dental-supply vendor, announcing a banking-detail change for small recurring invoices. Both payments, totaling $7,800 CAD, were sent to the new account without direct verification. The fraud was caught when the bookkeeper, preparing the monthly bank reconciliation, noticed the payee name on file no longer exactly matched the vendor's usual legal name — a detail a verification call would have caught on the very first payment. The clinic now applies a simple rule: no vendor banking-detail change, regardless of amount, is processed without a confirmation call to the number already on file.

Cost Reality Check for Canadian SMBs

Unlike a single CEO-fraud wire transfer, undetected vendor fraud can repeat across multiple billing cycles before discovery, which meaningfully increases the total loss compared to a one-time incident. Amounts seen in Canadian SMBs range from a few thousand dollars for a minor vendor relationship to well over $150,000 CAD when the targeted relationship involves large, recurring orders — such as with a construction materials supplier or a strategic logistics partner.

Weighed against a potential loss that can run well past $100,000 CAD for a single strategic vendor relationship, as the case studies above illustrate, the cost of these supporting layers is modest — and the core defense, a verification phone call before any banking-detail change, is entirely free to implement. Our broader BEC guide and cybersecurity budget guide cover how this fits into a wider security budget.

Canadian Reporting and Government Resources

If your business suspects or confirms a vendor fraud incident, or wants to verify a supplier before a payment change, the following Canadian resources are directly relevant:

Speed matters more than almost anything else if a fraudulent transfer has already occurred: contacting your bank immediately to attempt a wire recall gives the best remaining chance of recovering funds, since the window for a successful recall typically closes within hours.

What to Do If a Payment Was Already Sent to the Wrong Account

1

Contact your bank immediately

Call your bank's fraud team without delay to request a wire recall. The odds of recovering funds drop sharply with every hour that passes after the transfer clears.

2

Report the incident to the Canadian Anti-Fraud Centre

A prompt report supports your own case with your bank and contributes to the data used to warn other businesses targeted by the same fraud network.

3

Preserve everything without deleting anything

Keep the fraudulent email in full, including complete technical headers, along with every related communication. These are essential for your bank's investigation and any police report.

4

Notify the real vendor

Contact your actual vendor right away to inform them of the incident, since it's common in this specific fraud type for the vendor's own email account to have been compromised without their knowledge — information they need to secure their own systems and warn their other clients.

Want help closing your vendor fraud exposure?

IT Cares' cybersecurity services include accounting-system alert configuration, vendor verification policy design, and staff training your AP team will actually follow. Our security audits can also assess your current exposure to vendor impersonation fraud specifically.

Frequently Asked Questions

What is invoice and vendor fraud?
Invoice and vendor fraud (also called vendor banking-detail fraud) is a scam where an attacker impersonates a real, existing supplier your business already works with and sends a fake notice claiming their banking details have changed, in order to redirect an upcoming legitimate payment to an account the attacker controls.
How is vendor fraud different from broader Business Email Compromise (BEC)?
Business Email Compromise is a broad category that includes CEO/executive fraud, payroll diversion, legal/real estate transaction fraud, and vendor fraud. Vendor fraud is a specific, narrower subset: it targets accounts payable specifically, relies on an already-existing business relationship rather than impersonated authority, and is almost always timed around a real, expected invoice — which is exactly what makes it harder to catch than other BEC scenarios.
What are the warning signs of a fake vendor banking-detail-change email?
The most reliable signs are a banking-detail change communicated by email alone with no other confirmation, a request timed to coincide with a real invoice already due, a sender domain that's slightly different from the vendor's usual one, a tone or signature that differs subtly from the regular contact, and sometimes a "confirmation" call from an unlisted number designed to reinforce the email's credibility rather than provide real independent verification.
How do you verify a vendor's banking-detail change before paying?
Freeze any payment as soon as a banking-detail change is reported, then call the vendor's regular contact using a phone number already on file — never one supplied in the email. Require written confirmation on letterhead, confirm the vendor's legal registration still matches your file, and apply a grace period plus a small test payment before sending the full amount to the new account.
What should we do if a payment was already sent to the wrong account?
Contact your bank immediately to attempt a wire recall, since the odds of recovery drop sharply with every hour that passes. Report the incident to the Canadian Anti-Fraud Centre, preserve all related emails and communication without deleting anything, and notify the real vendor, since it's common in this type of fraud for the vendor's own email account to have been compromised without their knowledge.
How much do Canadian businesses actually lose to vendor fraud?
Amounts vary with the size of the vendor relationship targeted, ranging from a few thousand dollars for a minor supplier to well over $150,000 CAD for a strategic vendor tied to large recurring orders. Unlike a single CEO-fraud wire transfer, undetected vendor fraud can repeat across several billing cycles before discovery, which significantly increases the total loss.
Can email authentication (SPF/DKIM/DMARC) alone stop vendor fraud?
No. Email authentication reduces the risk of a domain being directly spoofed, but it does nothing if the vendor's own real email account has been compromised, which is a common vector in this specific fraud type — the email genuinely comes from the vendor's authentic, authenticated address. A verification procedure independent of email, like a phone call to a known number, is required regardless of how strong your email authentication setup is.
Is a small business with only a few vendors really at risk?
Yes, often more so, since small businesses typically maintain long-standing relationships with a limited number of vendors, creating an established trust that fraudsters specifically exploit — a banking-detail change feels routine rather than suspicious precisely because the relationship already seems proven. Small businesses also frequently lack a formal verification policy for this specific scenario, which increases the risk further.

Want an Honest Read on Your Vendor Fraud Exposure?

IT Cares reviews your accounts payable process and vendor verification procedures, then helps you build a real, low-friction defense your team will actually follow.

Comments (3)

DM
Derek M., Hamilton
August 6, 2026

Had almost this exact "bank switch" email from a packaging supplier we've used for years. The callback took two minutes and saved us over $60K. Our supplier had no idea their email had been compromised.

AT
Amara T., Kelowna
August 4, 2026

We only had verification rules for large one-off wires, not vendor banking-detail changes specifically. That gap cost us. Fixed now with a mandatory callback policy for any banking change, no exceptions.

JL
Jonathan L., Sherbrooke
August 2, 2026

Small clinic, we figured we weren't an interesting target for this kind of thing. Two small diverted payments later, we learned size doesn't matter. Verified vendor banking registry is mandatory here now.

Leave a Comment

Protect My Business