What is vendor impersonation fraud?

Vendor impersonation fraud (also called invoice fraud or supplier fraud) is a scheme in which an attacker poses as a legitimate supplier to redirect payments the business genuinely owes. The classic move is a bank-detail change request — sent from a compromised or look-alike vendor mailbox, attached to a real invoice — so the victim pays a real debt into a criminal’s account.

Also known as: invoice fraud · supplier fraud · accounts payable fraud · payment diversion · bank detail change fraud

Why approval chains do not catch it

ERP and accounts-payable controls verify that the invoice is expected, matched and approved — and in this fraud, it is. The goods were delivered; the amount is right; the approver approves. The only falsified element is the destination account, which sits in the vendor master record that was updated last week by a convincing email. Segregation of duties never sees it.

Closing the gap

Manual call-back verification of every bank-detail change works when it actually happens — practice decays under AP workload. Continuous vendor verification automates it: Trustmi validates vendor identity and monitors detail changes across the payment flow, correlating them with email and behavioral signals, so a redirected payment is stopped before execution rather than discovered at reconciliation.

// In the Cyberdis portfolio

Trustmi continuously verifies vendors and bank-detail changes — distributed by Cyberdis.

// FAQ

Common questions.

How common is invoice fraud?

It is consistently among the highest-loss categories of business fraud reported to agencies like the FBI’s IC3, because single incidents routinely reach six or seven figures — one redirected payment is all it takes.

What is the single most effective control?

Verified-channel confirmation of every bank-detail change — done every time, not just when someone is suspicious. Automating that verification is exactly what dedicated payment-security platforms exist for.

Can we recover a redirected payment?

Sometimes, if caught within hours — banks can attempt recalls, and law enforcement kill-chains exist. But recovery rates fall fast with time, which is why prevention before execution is the economically rational control.

Related explainers: What is business email compromise (BEC)?

Weighing approaches? Dedicated payment fraud prevention vs ERP controls and email security