invoice fraud

Fraud at this scale doesn’t announce itself. It doesn’t come with flashing red lights or an obvious break in the numbers. It hides inside ordinary transactions, processed by trusted people, approved through normal channels, filed and forgotten.

What breaks it open is almost always small. In this case, it was a date.

One invoice. One date that didn’t match the sequence it was supposed to fit into. A discrepancy so minor that any reasonable reviewer would have explained it away as a typo, a formatting error, an oversight. Except that it wasn’t. That single detail a service date that preceded the contract that authorized it was the thread that unraveled $40 million in fraudulent billing over multiple years.

This is the full story of how that investigation unfolded, what we found, and more importantly what any organization can learn from it about how invoice fraud hides in plain sight and how to find it before the losses compound. If you’d prefer to hear this story in my own words, the full walkthrough is on our YouTube podcast.

The Call That Started It All

The engagement began with a phone call from a compliance officer at a mid sized construction company. Their external auditors had flagged a variance in a subcontractor account not a huge number on its own, just an account that kept coming up when looking at quarter end adjustments. The auditors thought it was probably a timing difference. The compliance officer wasn’t sure.

We were brought in to take a look.

The first thing any fraud investigation starts with is document preservation. Before we touched a single record, we ensured that the accounting system, email archives, and vendor files were locked against modification. What evidence fraud investigators actually look for begins with making sure the evidence still exists and hasn’t been altered. Once we had that confirmed, we pulled the full transaction history for the subcontractor account in question every invoice, every payment, every contract amendment going back five years.

The Wrong Date: What It Was and Why It Mattered

The invoice was for construction management services. Significant amount. Properly formatted, professional looking, signed by the right people. But the service date on the invoice the period during which the work was allegedly performed fell three weeks before the contract that authorized those services had been executed.

A company was billing for work done under a contract that, according to the signature date on the agreement, didn’t yet exist when the work was supposedly performed.

There are innocent explanations for this. Contracts get backdated by agreement. Services sometimes begin before paperwork catches up. The company’s own lawyers advised us that this alone wasn’t proof of anything. But it was a signal the kind of anomaly that tells an experienced investigator to keep pulling.

So we did.

Invoice fraud rarely exists in isolation. The ACFE’s 2024 data shows that fraudsters who use billing schemes typically repeat the same method multiple times the pattern is the evidence. We ran a full duplicate analysis across five years of vendor payments, looking for the same subcontractor appearing in other accounts, other project codes, other payment periods. We found it dozens of times, across 14 different project accounts.

How the Scheme Actually Worked

What we uncovered was a structured invoice fraud operation that had been running for at least four years. The mechanics were not complicated. What made it effective was control.

A senior project manager someone who had been with the company for eleven years and was trusted with both vendor selection and invoice approval had established a relationship with a subcontractor whose principals he knew personally. Over time, that subcontractor began submitting invoices for work that was either never performed, performed by different parties, or deliberately inflated beyond the contracted scope.

The project manager approved each invoice. Because his approval authority was sufficient for the dollar amounts involved, no second review was required. The invoices passed through accounts payable without additional scrutiny. The subcontractor received payment. A portion of those payments we ultimately traced it through forensic bank analysis was routed back to an account connected to the project manager through a third party holding entity.

This is what vendor fraud through fake invoices looks like when it’s fully operational: a trusted insider with approval authority, a cooperative external party, and an approval process that never required a second set of eyes.

By the time we had mapped the full scheme, the losses exceeded $40 million. The date discrepancy on that first invoice had been there for years. Nobody had flagged it.

What Made This Fraud Almost Impossible to Catch Without Knowing What to Look For

The scheme survived for four years for reasons that are instructive for any organization with a vendor payment process.

The perpetrator controlled both sides of the transaction. He selected the subcontractor, approved the invoices, and had no requirement to explain his approval decisions to anyone above him for transactions under his authority threshold. This is the structural failure at the core of most invoice fraud cases: a single person controlling vendor relationships and payment approvals simultaneously. Dual control policies exist precisely to break this chain but they hadn’t been implemented here.

The invoices looked legitimate. Professional formatting, correct contract references, appropriate service descriptions. The subcontractor was real, had a website, had completed genuine work for the company on smaller projects early in the relationship. The fraudulent invoices were embedded in a history of legitimate ones which is why selective invoice review missed them.

The amounts were calibrated. Nothing stood out as obviously disproportionate on a per invoice basis. The scheme worked by volume many mid sized fraudulent payments rather than a few enormous ones specifically to stay below the threshold that would have triggered additional review. This is a pattern forensic investigators call “threshold manipulation,” and it appears in a significant percentage of documented billing scheme cases.

No one was looking at the date sequence. The wrong date that broke the case open had been on invoices going back years. It wasn’t hidden it was just never checked against the contract execution timeline. This is the detail that distinguishes a routine payment review from a fraud aware review: knowing what questions to ask of the data in front of you.

The Five Invoice Details That Fraudsters Hope You Never Check

Every invoice fraud investigation I’ve conducted has taught me that the details fraudsters count on going unverified are consistent. If your accounts payable team isn’t checking these five things on every vendor invoice particularly for large or recurring payments you’re leaving the door open:

1. Service dates versus contract dates. Does the service period on the invoice fall within an active, executed contract? If services are billed for a period before the contract was signed, or after it expired, that’s a material discrepancy requiring explanation not automatic processing.

2. Vendor bank account consistency. Has the bank account number on this invoice changed since the last payment to this vendor? A change in payment destination is one of the most reliable indicators of either vendor fraud or business email compromise targeting your AP process. Deepfake invoice fraud targeting accounts payable now uses AI generated vendor communications to make these changes appear legitimate.

3. Invoice number sequence. Do invoice numbers from this vendor follow a logical sequential pattern? Gaps, duplicates, or numbering that doesn’t match the vendor’s apparent volume are red flags. A vendor who bills you invoice #1047 and then #1049 the next month has either a gap or is selectively numbering invoices for different clients both worth verifying.

4. Approval authority versus relationship. Who approved this invoice, and do they have a pre existing relationship with this vendor that wasn’t disclosed? Single person approval authority for a vendor with whom that person has a personal or financial relationship is a conflict of interest that most invoice fraud schemes depend on.

5. Deliverable documentation. For service invoices especially: what documentation exists that the described service was actually performed? A signed delivery receipt for goods is standard. For consulting or project management services, equivalent documentation meeting notes, progress reports, deliverable sign offs should exist and be verifiable.

These five checks don’t require sophisticated software. They require a review process where someone is asking the right questions rather than processing invoices as efficiently as possible.

What Happened After Discovery

Once we had documented the scheme transaction by transaction, with forensic bank records tracing the kickback flow the company’s legal counsel was brought in to manage the criminal referral and civil recovery process. Law enforcement executed search warrants. The project manager was indicted.

The civil recovery process is ongoing, but the forensic work established the evidentiary foundation that made both criminal prosecution and civil judgment viable. How to document financial fraud so it holds up in court is the discipline that made that possible the chain of custody, the contemporaneous documentation, the forensic bank analysis conducted before records could be altered.

The company also undertook a significant internal controls review. The specific changes implemented mandatory dual approval for all vendor payments above $10,000, a vendor relationship disclosure policy for approving managers, and quarterly invoice audits for high spend subcontractors addressed directly the gaps that allowed the scheme to run.

Had any one of these controls been in place four years earlier, the loss would have been a fraction of what it became.

Conclusion: The Details Are the Defense

Invoice fraud increased by 71% year over year between 2023 and 2024, according to AFP data from affecting 14% of organizations to 24%. The methods aren’t becoming more sophisticated. The opportunity is becoming more abundant because organizations continue to process invoices for efficiency rather than for integrity.

The lesson from the $40 million case is not that sophisticated fraud requires sophisticated detection. It’s that obvious anomalies dates that don’t match contracts, bank accounts that change between payments, invoice sequences that don’t add up go unchallenged because no one’s process required them to be challenged.

The most powerful fraud detection tool in any AP department isn’t software. It’s a reviewer who knows what questions to ask and asks them, every time, without exception.

If something in your invoice records already looks off, don’t process it and move on. Pull the contract. Check the dates. Verify the bank account. Those thirty seconds of scrutiny are worth more than the most expensive fraud prevention platform on the market.

And if what you find goes beyond an anomaly into evidence of a real scheme, secure your records, engage legal counsel, and bring in a forensic accountant before anything else. The sequence matters. The evidence matters. The first forty eight hours of a fraud response determine what recovery is possible.

Frequently Asked Questions

1. How common is invoice fraud in 2025 and 2026? Very common and growing. According to the AFP’s 2024 Payments Fraud and Control Survey, incidents of attempted or actual invoice fraud increased by 71% year over year from affecting 14% of organizations in 2023 to 24% in 2024. Business email compromise targeting AP departments is now the leading external vector, while internal billing schemes remain the most costly form on a per incident basis.

2. What’s the most reliable red flag for invoice fraud? Date inconsistencies specifically, service dates on invoices that fall outside the period of an active contract are among the most consistently documented early indicators in billing scheme investigations. Other high reliability indicators include changes to vendor bank account details, invoice numbers that don’t follow sequential patterns, and single person approval authority for vendors with whom the approver has an undisclosed relationship.

3. How do forensic investigators trace kickbacks from invoice fraud? Forensic bank analysis compares payments made to vendor accounts against subsequent transfers out of those accounts looking for patterns that suggest funds are being routed to individuals connected to the approving party. Corporate structure searches reveal ownership of vendor entities. Email analysis identifies communications that establish the relationship between the insider and the vendor. Together, these create a financial map that shows where the money actually went. See our step by step forensic accounting investigation guide.

4. Can invoice fraud happen even with an AP system or automated processing? Yes frequently. Automated AP systems process invoices efficiently but are not designed for fraud detection unless specifically configured with anomaly detection rules. An insider who understands the system’s thresholds and approval workflows can route fraudulent invoices through automated processing by calibrating amounts and formatting to match legitimate invoices. Automated systems reduce processing errors; they don’t replace judgment based fraud review.

5. How much do companies typically recover from invoice fraud schemes? Recovery depends on several factors: how quickly the scheme is discovered, whether assets can be traced and frozen, the financial position of the perpetrators, and whether insurance coverage (fidelity bond or commercial crime policy) applies. In cases with strong forensic documentation, civil judgments can be obtained, but collection depends on the defendant’s assets. Criminal restitution orders are available but frequently uncollectible if the funds were spent. Immediate forensic action after discovery is the most important factor in maximizing recovery.

6. What’s the first thing to do if an invoice looks suspicious? Do not pay it. Do not confront the employee who submitted or approved it. Preserve the invoice and all related documentation exactly as found including email communications, contract files, and accounting system records. Consult legal counsel and, if the concern goes beyond a single invoice, engage a forensic investigator to assess the scope before any employment action is taken. Our guide on what to do when you suspect employee theft covers the full first response sequence.

References

  1. Association for Financial Professionals (AFP). (2024). AFP Payments Fraud and Control Survey. https://www.afponline.org/publications data tools/reports/survey research economic data/Details/payments fraud
  2. Association of Certified Fraud Examiners (ACFE). (2024). Occupational Fraud 2024: A Report to the Nations. https://www.acfe.com/ /media/files/acfe/pdfs/rttn/2024/2024 report to the nations.pdf
  3. Ramp. (2025). Invoice Fraud Detection: What It Is and 5 Ways to Prevent It. https://ramp.com/blog/accounts payable/invoice fraud
  4. Hoxhunt. (2025). Invoice Fraud: How to Identify Fake Invoices. https://hoxhunt.com/blog/invoice fraud
  5. Steph’s Books. (2026). Forensic Accounting and Fraud Detection: 8 Red Flags to Spot Early. https://stephsbooks.com/blog/forensic accounting fraud detection
  6. Invensis. (2025). Invoice Fraud Detection: How to Identify Fake Invoices. https://www.invensis.net/blog/invoice fraud detection
  7. Medius. (2024). Invoice Anomaly Detection and Fraud Risk Software. https://www.medius.com/solutions/fraud risk detection/
  8. GRF CPAs & Advisors. (2024). ACFE Study Finds Median Losses from Occupational Fraud Increasing. https://www.grfcpa.com/resource/acfe study occupational fraud/
  9. Clark Schaefer Hackett. (2024). Breaking Down the ACFE’s Latest Fraud Report. https://www.cshco.com/insights/breaking down the acfes latest fraud report
  10. Federal Bureau of Investigation (FBI). (2024). Business Email Compromise and Invoice Fraud. https://www.fbi.gov/investigate/white collar crime/fraud/internet fraud

Disclaimer: This article is provided for informational and educational purposes only. The investigation described is based on real world forensic work presented in an educational context; identifying details have been modified to protect confidentiality. This content does not constitute legal, financial, or professional advice, and no professional or client relationship is created by reading it. Fraud risks, legal requirements, and investigation standards vary by jurisdiction and organization. Consult a qualified attorney or certified fraud examiner for guidance specific to your situation. For questions about FraudOrder services, visit https://fraudorder.co/