Invoice and vendor fraud is a specific, narrow scam: an attacker impersonates a real supplier your business already pays — not a fake new vendor, not your own CEO — and sends a routine-looking notice claiming their banking details changed, timed to land right around a real invoice you were already expecting to pay. It's a distinct and particularly dangerous subset of the broader Business Email Compromise (BEC) category, which also covers CEO/executive fraud, payroll diversion, and legal/real estate transaction fraud. Our broader BEC guide covers all of those scenarios; this guide goes deep specifically on the vendor-impersonation, banking-detail-change scam, because it targets one department — accounts payable — through a mechanism that's meaningfully different from an urgent request supposedly from a company executive.
This guide covers exactly how the scam works step by step, the warning signs specific to a fake vendor banking-detail change, a verification protocol built specifically for this scenario, real Canadian case studies with dollar amounts, honest CAD cost ranges, and Canadian reporting resources.
Who wrote this guide
This guide was written and reviewed by IT Cares certified technicians based on helping Canadian SMBs review and harden accounts payable processes against vendor impersonation fraud specifically. The verification protocol described here requires no specialized software and can be adopted by a business of any size starting today.
What Invoice & Vendor Fraud Actually Is
Vendor fraud targets accounts payable with one specific goal: get the banking details on file for an already-known supplier changed, so the next payment — and often several payments after it — is deposited into an account the attacker controls instead of the real vendor's account. Unlike CEO fraud, which relies on the perceived authority of an executive and the urgency of a one-time request, vendor fraud relies on familiarity. The vendor's name, invoice format, and sometimes even the tone of their emails are already well known to the person processing the request, which naturally lowers their guard compared to a request from an unfamiliar sender.
The trigger is almost always framed as a routine administrative update — "we've switched banks," "our accounting department has updated our records" — often accompanied by an invoice that looks exactly like the vendor's usual ones, sometimes even carrying a correct business number since that information is frequently public or already visible on old, legitimate invoices. The request is nearly always timed to land around a real, expected payment, which makes it feel like a natural part of the normal billing cycle rather than an isolated, suspicious ask.
The "trusted vendor" trap
Much of what makes this fraud effective is that it specifically targets long-established vendor relationships, not new ones. Staff naturally process a request from a supplier the business has worked with for years with far less scrutiny than a request from a new contact, precisely because the relationship already feels "proven." Attackers know this and deliberately target established relationships rather than recent vendors, where verification would feel more natural and less like an inconvenience.
How the Scam Actually Unfolds, Step by Step
Understanding the exact mechanics helps accounts payable staff recognize the pattern rather than searching only for spelling mistakes or obvious red flags — both frequently absent from the cases that succeed.
Step one: identifying a vendor relationship worth targeting
The attacker first identifies an active, sufficiently valuable vendor relationship to target. This information sometimes comes from public sources — public tenders, project announcements, invoices or purchase orders accidentally posted online — or from quietly monitoring email threads if an account has already been compromised on either side of the relationship. In documented cases, it's often the vendor itself that was compromised weeks earlier without even realizing it, giving the attacker direct, extended access to real conversations with several of that vendor's clients at once.
Step two: two distinct technical vectors
Two main methods let the attacker send a convincing email. The first, a genuinely compromised vendor email account, is the more dangerous: the email literally comes from the real address, sometimes inserted directly into an existing thread, and can even intercept a real invoice to swap in new banking details before forwarding it along. The second, a lookalike domain, involves registering a domain nearly identical to the vendor's — a swapped letter, an added hyphen, a different top-level domain — close enough to fool a quick glance, especially on a mobile device.
Step three: timing chosen to maximize plausibility
The banking-detail-change request rarely arrives at random. It's most often timed to coincide with a real, already-issued invoice or a known payment deadline, which gives accounts payable staff the impression that the change fits naturally into the normal billing cycle rather than appearing as an isolated, suspicious request.
Step four: a request dressed as routine paperwork
The email itself almost always adopts a neutral, bureaucratic tone — "following a change of financial institution," "for internal accounting update purposes" — rather than an urgent or dramatic one. It's frequently accompanied by a new void cheque, banking form, or vendor-change document that gives an impression of documentary legitimacy. In more sophisticated cases, a "confirmation" phone call follows the email, but from an unlisted number that only reinforces the request's apparent credibility rather than providing any real independent verification.
Step five: the transfer and the delayed discovery
Once the new details are applied to the vendor file, every subsequent payment is automatically redirected to the fraudulent account, often across several billing cycles before anyone notices. The fraud is almost always discovered the same way: the real vendor reaches out about a late payment, revealing that the funds sent never reached their actual account.
Want your AP process reviewed before it's tested for real?
Our certified technicians can review your vendor verification procedures and accounting-system alerts — from $119.99.
Warning Signs Specific to Vendor Banking-Detail Fraud
| Warning Sign | Why It's Deceptive | Recommended Action |
|---|---|---|
| Banking-detail change reported by email only | Framed as a routine, unremarkable administrative update | Always confirm by phone using a number already on file |
| New void cheque or banking form attached | Creates a sense of documentary legitimacy | Compare against the existing vendor file, then verify verbally |
| Tone or signature subtly different from the usual contact | Easy to miss when the display name and format look identical | Train AP staff on the vendor contact's normal writing style |
| Request timed to a real invoice already due | Creates apparent legitimate urgency that lowers scrutiny | Verify even when the amount and due date match perfectly |
| Sender domain slightly different from usual | Nearly invisible to the eye, especially on mobile | Anti-spoofing filters plus manual check of the full domain |
| "Confirmation" call from an unlisted number | Artificially reinforces the original email's credibility | Only call back the number already on file, never the one provided |
Verification Protocol Before Changing Any Vendor Banking Detail
Unlike a one-time wire supposedly requested by an "executive," a vendor banking-detail change has a lasting effect: once applied to the file, it silently redirects every future payment until someone notices. That's exactly why this specific type of change deserves a more rigorous verification protocol than confirming a single isolated transfer.
Freeze any payment tied to the change
No payment should go to the new account until verification is fully complete, even if the invoice due date has already passed by a few days.
Call the vendor's known contact
Use only the phone number already on file in your vendor record or on a prior confirmed invoice — never one supplied in the change-request email, and never one provided in a follow-up "confirmation" call.
Require written confirmation on letterhead
Ask for official confirmation on the vendor's usual letterhead, ideally signed by a contact your business already knows, in addition to — not instead of — the phone verification.
Confirm the vendor's legal registration
Verify that the legal business name and registered business number still match your existing vendor file, which helps catch a broader impersonation of the company itself rather than just its banking details.
Apply a grace period and a test payment
For significant amounts, send a small test payment to the new account first and confirm receipt before releasing the full balance, with a minimum 24-48 hour hold between the change request and the first full payment.
Vendor Fraud Prevention Checklist
- ☐ Any vendor banking-detail change automatically freezes related payments until verification is complete
- ☐ Verification requires a phone call to a number already on file — never one supplied in the email or a follow-up call
- ☐ Written confirmation on the vendor's letterhead is required in addition to the phone call
- ☐ The vendor's legal name and business registration number are checked against our existing file before major changes
- ☐ A minimum 24-48 hour hold applies between a banking-detail change request and the first full payment
- ☐ A small test payment is sent before releasing large amounts to newly changed banking details
- ☐ We maintain an internal, verified vendor banking-detail registry, kept independent of incoming email
- ☐ Any vendor banking-detail change in our accounting system requires dual approval from two separate people
- ☐ Our accounting software or ERP flags every vendor banking-detail modification automatically
- ☐ AP staff receive annual training specifically on vendor impersonation and banking-detail-change fraud
- ☐ Staff are explicitly told they will never be penalized for pausing a payment to verify it, even after the fact
Real Canadian Vendor Fraud Case Studies
The following are composite scenarios based on patterns IT Cares technicians have encountered and reviewed with Canadian business clients, anonymized and combined rather than describing any single identifiable client.
Case study 1: The packaging supplier "bank switch" (Hamilton, ON)
An accounts payable clerk at a mid-sized food distribution company received an email appearing to come from a packaging supplier's accounts receivable contact, stating the supplier had "switched banks" and providing new wire instructions for an upcoming payment of $61,200 CAD already due that week. The request arrived from a domain one character different from the vendor's real one. Because company policy required a phone call to a previously verified vendor contact before any banking change was applied, the clerk called the real supplier directly and learned no such change had ever been requested. The fraudulent request was blocked before any funds moved.
Case study 2: The compromised construction supplier (Kelowna, BC)
A residential construction company received, from the real and authentic email address of its main building-materials supplier — whose account had been compromised without their knowledge — a banking-detail change notice inserted directly into an existing thread about an active order. No phone verification was performed, since the company had no formal protocol at the time for vendor banking-detail changes specifically. A payment of $112,400 CAD was sent to the new account. The fraud was only discovered three weeks later when the real supplier followed up about an overdue payment. Despite a prompt report to the bank, only a limited portion of the funds was recovered. The company has since adopted a dual-channel verification protocol and a mandatory hold period for any vendor banking-detail change.
Case study 3: The recurring small-invoice fraud (Sherbrooke, QC)
An office administrator at a small dental clinic received, over two consecutive billing cycles, an email appearing to come from the clinic's regular dental-supply vendor, announcing a banking-detail change for small recurring invoices. Both payments, totaling $7,800 CAD, were sent to the new account without direct verification. The fraud was caught when the bookkeeper, preparing the monthly bank reconciliation, noticed the payee name on file no longer exactly matched the vendor's usual legal name — a detail a verification call would have caught on the very first payment. The clinic now applies a simple rule: no vendor banking-detail change, regardless of amount, is processed without a confirmation call to the number already on file.
Cost Reality Check for Canadian SMBs
Unlike a single CEO-fraud wire transfer, undetected vendor fraud can repeat across multiple billing cycles before discovery, which meaningfully increases the total loss compared to a one-time incident. Amounts seen in Canadian SMBs range from a few thousand dollars for a minor vendor relationship to well over $150,000 CAD when the targeted relationship involves large, recurring orders — such as with a construction materials supplier or a strategic logistics partner.
- Very small business (1–10 employees): Vendor verification policy: $0 (procedural, not a purchased tool). Business registry lookups to confirm a vendor's legal name and registration number: typically free and take a few minutes through provincial or federal corporate registries.
- Small business (10–30 employees): Accounting/ERP configuration to flag vendor banking-detail changes automatically: usually a one-time $150–$500 CAD setup if not already available in your existing platform. Targeted AP staff training on vendor fraud specifically: $20–$60 CAD/employee/year.
- Growing SMB (30–75 employees): A vendor management module with dual-approval workflows and audit trails: often $8–$20 CAD/user/month depending on your accounting platform, alongside more formal, recurring AP training programs.
Weighed against a potential loss that can run well past $100,000 CAD for a single strategic vendor relationship, as the case studies above illustrate, the cost of these supporting layers is modest — and the core defense, a verification phone call before any banking-detail change, is entirely free to implement. Our broader BEC guide and cybersecurity budget guide cover how this fits into a wider security budget.
Canadian Reporting and Government Resources
If your business suspects or confirms a vendor fraud incident, or wants to verify a supplier before a payment change, the following Canadian resources are directly relevant:
- Canadian Anti-Fraud Centre (antifraudcentre-centreantifraude.ca): Canada's central body for reporting fraud, including invoice and vendor fraud. Reporting an incident helps law enforcement track patterns and can support recovery efforts in some cases.
- Corporations Canada / provincial business registries (ised-isde.canada.ca): Let you verify a vendor's legal name and registration status quickly and free of charge before applying a significant banking-detail change.
- BDC (Business Development Bank of Canada, bdc.ca): Publishes small business fraud prevention and financial risk management resources relevant to protecting vendor payment processes.
Speed matters more than almost anything else if a fraudulent transfer has already occurred: contacting your bank immediately to attempt a wire recall gives the best remaining chance of recovering funds, since the window for a successful recall typically closes within hours.
What to Do If a Payment Was Already Sent to the Wrong Account
Contact your bank immediately
Call your bank's fraud team without delay to request a wire recall. The odds of recovering funds drop sharply with every hour that passes after the transfer clears.
Report the incident to the Canadian Anti-Fraud Centre
A prompt report supports your own case with your bank and contributes to the data used to warn other businesses targeted by the same fraud network.
Preserve everything without deleting anything
Keep the fraudulent email in full, including complete technical headers, along with every related communication. These are essential for your bank's investigation and any police report.
Notify the real vendor
Contact your actual vendor right away to inform them of the incident, since it's common in this specific fraud type for the vendor's own email account to have been compromised without their knowledge — information they need to secure their own systems and warn their other clients.
Want help closing your vendor fraud exposure?
IT Cares' cybersecurity services include accounting-system alert configuration, vendor verification policy design, and staff training your AP team will actually follow. Our security audits can also assess your current exposure to vendor impersonation fraud specifically.
Frequently Asked Questions
Want an Honest Read on Your Vendor Fraud Exposure?
IT Cares reviews your accounts payable process and vendor verification procedures, then helps you build a real, low-friction defense your team will actually follow.
Comments (3)
Had almost this exact "bank switch" email from a packaging supplier we've used for years. The callback took two minutes and saved us over $60K. Our supplier had no idea their email had been compromised.
We only had verification rules for large one-off wires, not vendor banking-detail changes specifically. That gap cost us. Fixed now with a mandatory callback policy for any banking change, no exceptions.
Small clinic, we figured we weren't an interesting target for this kind of thing. Two small diverted payments later, we learned size doesn't matter. Verified vendor banking registry is mandatory here now.
Leave a Comment