The vendor had been in the system for three years. Thirty one invoices. Professional looking letterhead. A phone number. A website basic, but functional. An address in a nearby industrial park.
It did not exist.
The company, the phone number, and the website had all been created by the same person who was approving the invoices: the organization’s accounts payable manager. For three years, she had been paying herself through a company she’d registered under a close variant of her married name, using a P.O. box as the business address, and a prepaid cell phone that rang to her.
Total payments: $814,000.
Fake vendor fraud also called fictitious supplier fraud is the most common billing scheme in the ACFE’s occupational fraud taxonomy, appearing in a significant share of all accounts payable related fraud cases. It works because it exploits the same trust that makes vendor relationships function: the assumption that an invoice from an established supplier corresponds to real goods or services.
This is the full story of how that scheme worked, how it was discovered, and what every organization running an accounts payable function needs to do differently starting today.
How the Scheme Was Built
The AP manager set up the fictitious vendor in the company’s accounting system during her first year in the role early enough that the vendor would have an established payment history by the time anyone might scrutinize it. She used the company’s standard vendor onboarding process, submitting the required documentation herself. The EIN she entered belonged to a legitimately registered LLC she had formed eighteen months before joining the company.
This sequencing matters. Fake vendor fraud committed by a long tenured, trusted employee rarely involves obviously fabricated credentials. The sophistication of this scheme was in the preparation: she created the entity before she needed it, gave it a real tax ID, built a website, and waited until she had vendor setup authority before adding it to the approved supplier list.
The invoices were submitted monthly. They described IT consulting services a category vague enough that no one could verify a deliverable and broad enough that the expense code was appropriate for multiple cost centers. The amounts varied between $18,000 and $34,000 per invoice, deliberately kept below the threshold that would have required a second approval signature.
For three years, thirty one invoices, processed and paid without question. Nobody asked what services had been delivered. Nobody called the number on the invoice. Nobody cross referenced the vendor’s address against the company’s other supplier records. Nobody noticed that the vendor’s bank account which she had also set up was at the same branch where she held her personal checking account.
The Five Elements That Made This Scheme Possible
The AP manager didn’t create this scheme from nothing. She identified and exploited five specific control failures in her employer’s accounts payable process. These failures appear, in some combination, in virtually every fake vendor fraud case:
1. Single person vendor setup authority. She could add new vendors to the payment system without anyone else’s review or approval. The entire identity of the fictitious supplier EIN, bank account, contact details was entered by the same person who would later approve payments to it.
2. Single person payment approval below threshold. The company required dual authorization only for invoices above $50,000. All of her invoices came in under $40,000. She approved each one herself.
3. No deliverable verification for service invoices. The company had no process for confirming that IT consulting services had been received before paying invoices describing them. Physical goods require delivery receipts; service invoices were processed on face value alone.
4. No periodic vendor list audit. The company’s approved vendor list had never been reviewed for anomalies. Had anyone conducted a basic analysis looking for vendors with P.O. box addresses, vendors whose bank accounts shared a branch with employee accounts, or vendors with no procurement contact in the business unit this vendor would have flagged immediately.
5. No conflict of interest disclosure process. She had never been asked whether she had any ownership interest in, or personal relationship with, any company doing business with the organization. She didn’t disclose what she would not have disclosed voluntarily.
Our post on vendor fraud through fake invoices documents these same structural vulnerabilities across multiple case patterns. The specific combination of vendor setup authority and payment approval authority in a single person is the most reliable predictor of billing scheme fraud in any organization’s AP function.
How It Was Discovered
Discovery came in the second year after a new controller joined the organization and initiated a vendor master file review as part of his standard onboarding process. He wasn’t looking for fraud. He was trying to understand the organization’s supplier relationships and clean up duplicate entries.
The IT consulting vendor appeared in his review with three characteristics that didn’t match the organization’s other suppliers:
- A P.O. box address rather than a physical business address
- No corresponding procurement contact in any business unit no manager who could be identified as the internal sponsor of the vendor relationship
- A phone number that rang to voicemail without a company greeting
He tried to reach the vendor to confirm current contact details. The voicemail was never returned.
He brought the anomaly to the CFO without flagging it as fraud just as an odd vendor he couldn’t verify. The CFO contacted the AP manager to ask about the supplier. Her response was evasive enough that the CFO escalated to legal counsel, who engaged a forensic accountant.
The forensic review took three weeks. What bank statements reveal to fraud investigators is exactly what surfaced the link: payments from the company’s operating account to the fictitious vendor’s bank account, traced through the bank’s business account records, led to an account opened under the AP manager’s name variant at the same branch as her personal account. EIN records confirmed the LLC was registered to an address that matched her former residence.
The pattern was complete, documented, and incontrovertible. Three weeks. Thirty one invoices. $814,000.
The Five Controls That Stop Fake Vendor Fraud
The five control failures in this case have direct, implementable solutions. None of them require expensive software or large compliance teams. They require policy decisions and the organizational will to enforce them.
Separate vendor setup from payment approval. This is the foundational control. The person who adds a vendor to the payment system should not be the same person who can approve payments to that vendor. This can be enforced through role based access controls in any modern accounting system it requires a configuration change, not a new hire.
Require a business unit sponsor for every vendor. Before a new vendor is added to the approved list, a manager outside the AP function should attest that the vendor relationship serves a legitimate business need and that they have verified the vendor exists. This introduces a second person into the vendor onboarding process without creating significant friction.
Implement a periodic vendor master file review. At minimum annually, the approved vendor list should be reviewed for: P.O. box addresses, vendors with no physical address on file, vendors whose bank accounts share a branch with any employee account, duplicate or near duplicate vendor names, and vendors with no documented business unit sponsor. This review doesn’t require forensic expertise it requires a systematic comparison across available data.
Set approval thresholds based on annual cumulative spend, not per invoice amount. Calibrating invoices to stay below a per invoice threshold is one of the most common fake vendor fraud techniques. Setting dual authorization requirements based on the total annual payments to a single vendor rather than per invoice amounts closes this gap. A vendor receiving $400,000 per year in $35,000 invoices should require the same oversight as a vendor receiving a single $400,000 payment.
Conduct service invoice spot checks before payment. For invoices describing intangible services consulting, IT support, advisory work a periodic spot check process that requires a business unit manager to confirm the services were received before payment is processed creates the deliverable verification layer that this scheme depended on being absent.
Our post on catching embezzlement early with accounting software explains how the vendor transaction detail report and voided/deleted transaction log in standard accounting platforms can surface the patterns described above. Our post on dual control policies that stop internal theft covers the structural separation of duties that prevents single actor billing schemes.
What Happened After Discovery
The AP manager was terminated and the matter was referred to law enforcement. Criminal charges included wire fraud and embezzlement. She pleaded guilty and was ordered to pay full restitution.
Recovery from the restitution order: partial. A significant portion of the $814,000 had been spent on personal expenses that produced no recoverable assets. The organization’s fidelity bond covered a portion of the loss, though the claims process required documentation of the scheme that took several months to produce.
The organization also conducted an immediate review of all vendor relationships every approved supplier, every account opened in the prior five years, every payment made to vendors without a documented business unit sponsor. Four additional anomalous relationships were identified and investigated. Two resulted in terminations.
The real cost of fake vendor fraud is almost always higher than the direct financial loss. Our post on the hidden costs of embezzlement documents the full picture: investigation costs, legal fees, operational disruption, insurance claims complexity, and the cultural damage of discovering that a trusted employee built an eighteen month scheme before her first day of work.
Conclusion: The Vendor That Didn’t Exist Was Always in the Data
The IT consulting vendor that drained $814,000 was never invisible. It was in the vendor master file. It was in the accounts payable records. It was in the bank statements. The P.O. box was on the invoice. The missing business unit sponsor was a gap in the records. The phone number that went to voicemail was answerable.
Fake vendor fraud doesn’t survive because it’s sophisticated. It survives because nobody looked. The controls that would have caught this scheme vendor setup separation, annual vendor list review, service invoice verification were all simple, low cost, and absent.
Start with your vendor master file. If you don’t know, right now, who sponsors every active vendor relationship, which vendors have physical addresses that can be verified, and which vendors’ bank accounts have been cross referenced against employee accounts you have the same exposure this organization had before their new controller asked a simple question.
If something in your vendor relationships already looks wrong, the sequence is: preserve your accounting records, engage legal counsel, and call a forensic accountant before any personnel action. The evidence is almost always in the data. The question is whether you reach it first.
Frequently Asked Questions
1. How common is fake vendor fraud compared to other types of embezzlement? Billing schemes which include fake vendor fraud, inflated invoices, and fictitious supplier schemes are the second most costly category of occupational fraud in the ACFE’s 2024 data, with a median loss of $150,000 per scheme. They are disproportionately common in organizations where a single person controls vendor setup and payment approval, which describes most small and mid sized AP functions. Fake vendor fraud is particularly prevalent because it’s sustainable: once a fictitious vendor is established, recurring invoices can be processed indefinitely without creating new risks each cycle.
2. What are the most reliable red flags for a fictitious supplier in a vendor list? The most reliable indicators, based on documented case patterns, are: vendors with P.O. box addresses rather than physical locations; vendors whose bank account is at the same institution as an AP or finance employee; vendors with no documented internal sponsor or requisitioner; vendors whose invoices consistently fall just below the approval threshold; and vendors with sequential or nearly identical invoice numbers that suggest a small number of transactions rather than an active business relationship.
3. Can fake vendor fraud occur even with accounting software that tracks transactions? Yes accounting software records transactions but doesn’t verify them against reality. A fictitious vendor entered by someone with system access looks identical to a legitimate vendor in the accounting records. The audit trail will show who created the vendor and when, which is valuable forensic evidence after discovery, but software alone doesn’t prevent a fraudster from creating a vendor and approving payments to it if they hold both capabilities.
4. How do you verify that a vendor is legitimate before adding them to an approved list? At minimum: confirm the vendor has a physical business address (verifiable via Google Maps or a brief call to the number on file), verify the EIN through the IRS online EIN verification tool, confirm that a business unit manager outside AP can name the business need the vendor serves, and check that the vendor’s bank account doesn’t share an institution or branch with any employee’s known accounts. For higher value vendor relationships, a brief corporate records search confirming the business is registered and active adds another layer.
5. What’s the difference between fake vendor fraud and invoice manipulation fraud? Fake vendor fraud involves an entirely fictitious supplier that doesn’t exist the entity, the services, and in many cases the contact information are all fabricated by the perpetrator. Invoice manipulation fraud involves a real vendor whose legitimate invoices are altered amounts inflated, payee bank accounts changed, or duplicate invoices submitted for the same legitimate service. Both are forms of billing scheme fraud, but fake vendor fraud is typically more sustained because it creates a recurring billing mechanism rather than requiring manipulation of legitimate invoices.
6. Is a company liable if a vendor it paid turns out to be fictitious? In general, no the company is the victim in a fake vendor scheme. However, if a company’s negligent internal controls enabled the fraud and a third party suffered harm (for example, if the fraudulent payments depleted funds owed to legitimate creditors), civil liability theories can become more complex. From a practical standpoint, the company’s primary exposure is the direct financial loss plus investigation and recovery costs. Engaging legal counsel immediately upon discovery protects the organization’s interests in both the investigation and any subsequent litigation.
References
- Association of Certified Fraud Examiners (ACFE). (2024). Occupational Fraud 2024: A Report to the Nations. https://www.acfe.com/ /media/files/acfe/pdfs/rttn/2024/2024 report to the nations.pdf
- GRF CPAs & Advisors. (2024). ACFE Study Finds Median Losses from Occupational Fraud Increasing. https://www.grfcpa.com/resource/acfe study occupational fraud/
- YHB CPAs & Consultants. (2024). How to Use QuickBooks as a Fraud Detection Tool. https://yhbcpa.com/fraud investigation/how to use quickbooks as a fraud detection tool/
- Forensic Strategic Solutions. (2017). QuickBooks Audit Trail: Fraudulent Behavior Detection. https://forensicspot.com/topics/forensic accounting/asset tracing methodologies
- Moss Adams LLP. (2023). Prevent and Detect Fraud With These Key Internal Controls. https://www.mossadams.com/articles/2023/04/internal controls for fraud prevention
- Alvarez & Marsal. (2025). Segregation of Duties: A Simple Idea to Prevent Fraud. https://www.alvarezandmarsal.com/insights/segregation duties simple idea prevent fraud
- Clark Schaefer Hackett. (2024). Breaking Down the ACFE’s Latest Fraud Report. https://www.cshco.com/insights/breaking down the acfes latest fraud report
- Anchin CPAs & Advisors. (2024). 2024 ACFE Occupational Fraud Report Summary. https://www.anchin.com/wp content/uploads/2024/08/2024 ACFE Occupational Fraud Report.pdf
- 8020 Consulting. (2024). 10 Internal Controls for Small Business Fraud Prevention. https://8020consulting.com/blog/10 basic internal controls small business
- Federal Bureau of Investigation (FBI). (2024). White Collar Crime Financial Fraud Overview. https://www.fbi.gov/investigate/white collar crime
Disclaimer: This article is provided for informational and educational purposes only. The case described is based on real world forensic investigation experience presented in an educational context; identifying details have been modified to protect confidentiality. This content does not constitute legal, financial, or professional advice, and no professional or client relationship is created by reading it. Fraud risks, internal control requirements, and legal remedies vary by jurisdiction and organization type. Consult a qualified certified fraud examiner, attorney, or forensic accountant for guidance specific to your situation. For questions about FraudOrder services, visit https://fraudorder.co/