A junior AP clerk noticed something small during a routine month-end reconciliation: the same invoice number had been paid twice, four days apart, for $4,780. She almost let it go. Vendors resend invoices. Systems glitch. Duplicate payments happen at nearly every organization that processes high volumes of invoices.
She didn’t let it go. That one overpayment became the thread that unraveled a fraud ring responsible for more than $640,000 in losses over two years.
This is not a rare story, and it rarely announces itself the way our bookkeeper embezzlement case did either. According to the AFP’s 2025 Payments Fraud and Control Survey, 79% of organizations experienced attempted or actual payments fraud in the prior year, and duplicate invoices remain one of the most consistently reported warning signs across accounts payable departments. Separately, industry benchmarking from APQC finds that even top-performing organizations still see roughly 0.8% of annual disbursements go out as duplicate or erroneous payments, with the median company closer to 1.5%. On a payables run of any real size, that is not pocket change. It is a data trail, and in this case, it was the trail that led to a fraud ring.
Here is how that single duplicate payment led to the discovery, what the scheme looked like underneath it, and what it takes to catch duplicate payment fraud before it reaches six figures.
The Overpayment That Didn’t Add Up
The duplicate itself looked ordinary. Same vendor, same invoice number, same amount, paid twice within the same week. When the clerk flagged it for reversal, something about the vendor’s file gave her pause: the remittance address had changed three times in eighteen months, and none of the changes had a corresponding approval memo attached.
She escalated it to her controller instead of quietly requesting a refund. That decision mattered. Left as a routine duplicate payment correction, the case would have ended with a refund request and a closed ticket. Instead, the controller pulled twelve months of activity for that vendor and found a pattern: invoices that consistently landed just under the dual-approval threshold, a bank account that had been updated without a documented verification call, and a vendor contact who never answered the phone during business hours.
Following the Thread: How One Vendor Led to a Network
What started as one vendor’s file became three. The forensic review that followed traced payments across a small cluster of supplier accounts, all created within a narrow window, all routed to accounts at the same regional bank, and all approved by the same combination of two employees working in coordination.
The duplicate payment fraud pattern extended further than the AP clerk could have guessed from a single invoice. The two employees, one in procurement and one in accounts payable, had built a rotation: legitimate-looking invoices from real vendors were duplicated with slight alterations, submitted through a second, unofficial channel, and paid a second time into accounts the pair controlled. This is a variation on a pattern we’ve documented before: when vendor setup and payment approval sit with too few people, duplicate and fictitious billing schemes both become sustainable rather than one-off mistakes.
The Anatomy of a Six-Figure Fraud Ring
Once investigators mapped the full pattern, the scheme’s mechanics became clear. It relied on three specific behaviors repeated over roughly two years:
- Invoice duplication with minor alterations. A legitimate invoice was resubmitted with a slightly different reference number, avoiding automated exact-match duplicate detection.
- Split routing. The duplicated invoice entered the payment queue through a different intake channel than the original, so no single reviewer saw both versions side by side.
- Threshold awareness. Amounts were kept below the level that required a second signature, a technique that shows up in nearly every internal billing scheme investigated.
None of these behaviors were individually sophisticated. Together, they exploited the same blind spot: an organization’s duplicate payment detection was built to catch exact matches, not the fuzzy, deliberately altered duplicates that a coordinated scheme produces.
Why Duplicate Payment Fraud Is So Often Missed
Most organizations treat duplicate payments as a reconciliation nuisance rather than a fraud signal. That assumption is expensive. Research from the ACFE’s 2024 Report to the Nations found that asset misappropriation, the category covering billing and duplicate payment schemes, appears in roughly 89% of all occupational fraud cases, with billing schemes carrying a median loss around $150,000 per scheme.
The financial exposure compounds because duplicate payment fraud rarely announces itself. A separate industry study found duplicate invoices average around $2,000 each, individually forgettable, easy to write off as a processing error. It is only when someone asks why a pattern keeps recurring that the fraud becomes visible, the same lesson from our fictitious supplier investigation, where thirty-one paid invoices sat in plain sight for three years before anyone asked a basic question. That is exactly what happened here: one clerk’s decision not to write off a $4,780 anomaly as routine is what exposed a scheme six-figures deep.
Building Controls That Catch This Before It Reaches Six Figures
The fixes that would have stopped this scheme earlier are not exotic. They are the same layered controls that stop most billing and duplicate payment fraud:
- Fuzzy-match duplicate detection, not just exact-match, so altered reference numbers and near-identical invoices get flagged for review.
- Single intake channel for all invoices, so no vendor relationship can be paid through two separate, unreconciled paths.
- Segregated vendor setup and payment approval, removing the ability for one person, or one coordinated pair, to control both ends of a transaction.
- Verification calls for banking detail changes, made to a known contact number, not the number listed on the change request itself.
- Periodic reconciliation reviews treated as fraud detection exercises, not just accuracy checks, the way our guide on catching embezzlement early with accounting software recommends.
Duplicate payment fraud thrives in organizations that treat every anomaly as an isolated accident. It is stopped in organizations that treat every anomaly as a question worth answering.
Conclusion: Take the Small Anomaly Seriously
The fraud ring in this case did not begin with a dramatic red flag. It began with a payment that looked almost exactly like an honest mistake. The difference between a six-figure loss and a contained incident was one employee’s willingness to ask why, and an organization with the forensic capability to follow the answer.
If a duplicate payment, an unfamiliar vendor, or a pattern that doesn’t quite add up has crossed your desk, don’t wait for it to become a six-figure problem before you investigate. Talk to a forensic investigator about what your vendor and payment data might already be telling you.
Frequently Asked Questions
Is every duplicate payment a sign of fraud?
No. Most duplicate payments are honest errors caused by manual data entry, vendor resubmissions, or system glitches, not fraud. The distinction matters, but the investigation process for confirming which one you’re dealing with should be the same either way, since fraud is often disguised to look exactly like an error.
How much money do duplicate payments typically cost organizations?
Industry benchmarking places duplicate and erroneous payments at roughly 0.8% to 2% of annual disbursements, depending on control maturity. For a company processing $100 million a year in payables, that range represents anywhere from $800,000 to $2 million in exposure, some of it recoverable, much of it not.
What’s the difference between duplicate payment fraud and a duplicate payment error?
An error is unintentional: the same invoice paid twice by mistake. Duplicate payment fraud is deliberate: invoices altered or resubmitted specifically to evade duplicate-detection controls and redirect funds. The financial outcome looks similar on the surface, but the investigation, documentation, and legal response differ significantly.
How quickly should a duplicate payment be investigated?
Immediately, and ideally before assuming it’s routine. Escalating a duplicate payment to reconciliation staff first, rather than resolving it as a simple refund request, is often what surfaces a broader pattern. Waiting weeks or months to look deeper gives a coordinated scheme more time to expand.
Can accounting software alone prevent duplicate payment fraud?
Software helps significantly, but exact-match duplicate detection alone misses deliberately altered “fuzzy” duplicates. Effective prevention combines automated detection with segregation of duties, vendor verification protocols, and periodic human review of flagged anomalies.
What should we do if we suspect a duplicate payment is part of a larger scheme?
Preserve the relevant records without alerting the individuals involved, engage legal counsel, and bring in a forensic accountant or fraud examiner before taking any personnel action. Acting too early can tip off collaborators or compromise evidence needed for recovery and prosecution.
References
- Association of Certified Fraud Examiners (ACFE). (2024). Occupational Fraud 2024: A Report to the Nations. https://www.acfe.com/-/media/files/acfe/pdfs/rttn/2024/2024-report-to-the-nations.pdf
- Association for Financial Professionals (AFP). (2025). 2025 AFP Payments Fraud and Control Survey Report. https://www.financialprofessionals.org/topics/payment-topics/fraud
- Federal Bureau of Investigation (FBI). (2024). White-Collar Crime. https://www.fbi.gov/investigate/white-collar-crime
- Federal Trade Commission (FTC). (2025). Consumer Sentinel Network Data Book 2024. https://www.ftc.gov/reports/consumer-sentinel-network-data-book-2024
- Association of Certified Fraud Examiners (ACFE). (2024). Occupational Fraud 2024: A Report to the Nations (Full Report). https://legacy.acfe.com/report-to-the-nations/2024/
- American Institute of CPAs (AICPA). (2024). Forensic and Valuation Services: Fraud Risk Management Guide. https://www.aicpa-cima.com/resources/landing/forensic-and-valuation-services
- The Institute of Internal Auditors (IIA). (2024). Global Internal Audit Standards and Fraud Risk Guidance. https://www.theiia.org/en/standards/
- Corpay. (2026). What Is a Duplicate Payment? Causes, Detection, and Prevention. https://www.corpay.com/resources/blog/duplicate-payment
- APQC. (2025). Understanding Accounts Payable Benchmarks and Best Practices. https://www.apqc.org/resource-library/resource-collection/understanding-accounts-payable-benchmarks-and-best-practices
- U.S. Department of Justice (DOJ). (2024). Fraud Section, Criminal Division. https://www.justice.gov/criminal-fraud
This article is provided for informational and educational purposes only. The case described is presented in an illustrative, composite format based on common fraud investigation patterns; identifying details have been altered to protect confidentiality. This content does not constitute legal, financial, or professional advice, and no client relationship is created by reading it. Fraud risks and legal remedies vary by jurisdiction and organization type. Consult a qualified certified fraud examiner, attorney, or forensic accountant for guidance specific to your situation. For questions about FraudOrder services, visit https://fraudorder.co/