Home
Blog
Vendor Impersonation Scams: How Fraudsters Redirect Real Invoices to Fake Bank Accounts

Vendor Impersonation Scams: How Fraudsters Redirect Real Invoices to Fake Bank Accounts

Reviewed by
Table of Contents

Key Takeaways

The invoice looks exactly right. It's from a vendor you've worked with for years. The logo matches. The contact name matches. Even the invoice number follows the right sequence. The only thing that's changed (quietly, almost invisibly) is the bank account number at the bottom.

That's it. That's the whole scam.

And it works. Billions of dollars a year worth of "works."

Vendor impersonation fraud doesn't require sophisticated malware or zero-day exploits. It requires patience, a convincing email, and an accounts payable team that trusts what's in their inbox. For fraudsters, that's more than enough.

The numbers don't lie

Business email compromise (BEC), the umbrella category that covers vendor impersonation and invoice fraud, generated $3.046 billion in reported losses in 2025 alone, according to the FBI IC3 2025 Annual Report. That's a 10% jump from 2024. And 86% of those losses were transmitted via wire transfer or ACH, the exact payment methods used in routine B2B transactions.

The broader picture is just as grim:

  • 79% of organizations experienced attempted or actual payments fraud in 2024, according to the AFP Payments Fraud and Control Survey.
  • Invoice fraud costs the average business $1.2 million per year, per research cited by Adaptive Security.
  • 60% of all BEC scams in 2024 targeted organizations by impersonating vendors, per the same AFP survey.
  • In the UK, £3.9 million was lost across just 83 reported invoice fraud cases in September 2025 alone, with invoice fraud accounting for 85% of all payment-diversion fraud losses that month.
  • LevelBlue SpiderLabs recorded a 15% increase in BEC emails in 2025, averaging over 3,000 BEC messages per month.

These aren't edge cases. This is a systematic, high-volume attack on the everyday rhythm of B2B payments.

How vendor impersonation actually works

The mechanics of a vendor impersonation scam are deceptively simple. There are a few common variations, but they all follow the same basic blueprint.

Step 1: reconnaissance

Before a single fraudulent email is sent, attackers do their homework. They identify your company's active vendors, often through LinkedIn, public procurement records, your own website's "partners" page, or purchased data from prior breaches. They learn vendor names, email domains, invoice formats, and payment cycles.

Step 2: The deception setup

Fraudsters use one of three approaches to impersonate the vendor:

  • Domain spoofing: They register a lookalike domain. Think acme-invoicing.com instead of acmeinvoicing.com, or swapping a letter for a numeral. On mobile, these differences are nearly impossible to spot.
  • Email spoofing: The "From" name displays correctly in many email clients even when the underlying address is fraudulent. An email reading "Billing Team \" looks legitimate at a glance.
  • Account compromise (VEC): In more advanced attacks, fraudsters gain access to the real vendor's email account through phishing or credential theft, then communicate directly from the legitimate address. This is called Vendor Email Compromise, and it's nearly impossible to detect through email headers alone.

Step 3: The pivot

Once in position, the attacker sends a message, usually timed around a known billing cycle, informing your AP team of a "banking update." The message is polite, professional, and often brief:

"Hi [Name], please note we've updated our banking details effective this month. Please use the new account for all outstanding and future payments. Updated details are attached."

The attached invoice looks identical to previous documents, except for the bank account or routing number.

Step 4: The payment (and disappearance)

Your team processes the payment. The money lands in an account controlled by the fraudster, often a domestic "mule" account that's quickly drained and moved offshore. By the time anyone realizes something is wrong, the funds are gone. Recovering them is rare and slow.

Real-world cases: when it goes wrong

Arup: $25 million lost to a deepfake CFO

In January 2024, a finance employee at Arup, the UK engineering firm behind the Sydney Opera House, attended what appeared to be a routine video call with the company's CFO and several colleagues. He was instructed to authorize 15 separate wire transfers (CNN Business, May 2024).

Every other participant on the call was an AI-generated deepfake. The attackers had trained synthetic video and audio models on publicly available footage and created real-time personas convincing enough to override the employee's initial skepticism. The result: $25 million lost in a single session.

The Arup case broke a fundamental assumption: if you can see and hear someone, they must be real.

City of Baltimore: $803,000 drained from a contractor payment

The City of Baltimore wired $1.52 million to criminals posing as one of its legitimate development contractors; roughly $721,000 was later recovered, leaving a net loss of about $803,000 (CBS News Baltimore, 2025). Attackers gained access to the real vendor's email account, monitored correspondence until a payment was imminent, then inserted updated bank details into the active email thread. AP processed the update without secondary verification.

Roughly $721,000 was recovered. The city absorbed an $803,000 net loss. The Inspector General's review found that AP policies didn't require phone-based verification for vendor updates. It wasn't Baltimore's first time. Similar weaknesses had previously been flagged in fraud cases in 2020 and 2022 (CBS News Baltimore, 2025).

Google and Facebook: $120 million from a hardware supplier impersonation

Fraudsters impersonated Quanta Computer, a real hardware manufacturer with existing relationships with both tech giants, and submitted fraudulent invoices over an extended period. Both companies paid. A combined $120+ million was redirected before the scheme unraveled. The attacker, Lithuanian national Evaldas Rimasauskas, was eventually extradited and convicted (CyberScoop, 2019).

Nikkei Inc.: $29 million from a single fraudulent wire

A fraudulent email impersonating a legitimate vendor was sent to a US subsidiary of Japanese media company Nikkei. The email instructed the recipient to transfer funds. $29 million was wired before the fraud was detected (BleepingComputer, 2019).

Quebec packaging manufacturer: $203,000 from one domain swap

No deepfakes. No hacking. Just one carefully crafted email from a domain that had swapped -ca.com for the legitimate .ca. The fraud wasn't discovered for over a month, when the real broker called chasing the unpaid invoice (CP24, 2026).

Why AI is making this worse

Vendor impersonation fraud has existed for decades. AI is making it dramatically cheaper, faster, and more convincing.

The FBI's 2025 Internet Crime Report included a dedicated AI section for the first time, logging more than $893 million in AI-enabled scam losses across more than 22,000 complaints. Key developments:

  • Voice cloning: Attackers can clone a vendor contact's voice from as little as a few seconds of publicly available audio, then place a phone call "confirming" banking changes. The UK energy CEO who authorized a €220,000 transfer after a call from what he believed was his German parent company's CEO (it was a cloned voice) is now a textbook example.
  • Deepfake video: As the Arup case demonstrated, real-time synthetic personas can now override even a skeptical employee's instincts during a live video call.
  • AI-altered invoice PDFs: Newer attack variants use AI to alter embedded bank account numbers in intercepted PDFs in a way that's visually indistinguishable from the original.
  • Personalization at scale: AI lets attackers craft hyper-personalized phishing emails (referencing real invoices, project names, and contact names) without the grammatical errors that once served as a red flag.

Red flags your team should know cold

The good news: even sophisticated fraud leaves traces. Training your AP and finance teams to recognize these signals can stop an attack before funds move.

Email red flags:

  • Lookalike sender domains. Check every character. @acme-corp.net vs @acmecorp.com is a classic trick. Enable email header visibility if your client hides the true address.
  • Unsolicited "banking update" requests. Legitimate vendors rarely change bank details without prior notice, formal documentation, and a direct conversation.
  • Urgency or secrecy language. "Please process before EOD," "Don't loop anyone else in," or "This is time-sensitive" are manipulation tactics meant to bypass approval chains.
  • Replies routed to a different address. Check the Reply-To field. Fraudsters often set it to a separate attacker-controlled inbox.

Invoice red flags:

  • New or changed bank account details. Any change to payment details should trigger out-of-band verification, every single time, no exceptions.
  • Vague or generic line items. "Services rendered" or "Consulting Q3" without project specifics, or amounts that don't match prior patterns.
  • Formatting inconsistencies. Slightly different fonts, logos, or document structure compared to prior invoices from the same vendor.
  • Invoice numbers that don't follow sequence. A sudden jump or reset in numbering is worth investigating.

Behavioral red flags:

  • A vendor contact you haven't heard from in a while suddenly reaching out about payment, especially if they can't verify details you'd normally both know.
  • Phone follow-ups to "confirm" an email using a number provided in the suspicious message, not one you had on file previously.

How to protect your organization

Defending against vendor impersonation doesn't require advanced technology. It requires consistent, enforced process discipline.

1. Verify bank detail changes out-of-band, always.

Any request to change a vendor's payment details, regardless of how legitimate it looks, must be verified by phone using a number already on file (not one provided in the request). Never verify by replying to the same email thread. This single control would have prevented most of the case studies above.

2. Implement dual authorization for high-value payments.

No single person should be able to both approve a vendor banking change and authorize a payment against it. Segregation of duties is the foundational control here. Consider tiered thresholds: payments above a set dollar amount require two separate approvals.

3. Maintain a verified vendor master file.

Keep an authoritative, access-controlled record of verified banking details for every vendor. Any changes must go through a formal, documented update process, not an email request.

4. Train your AP team to pause and verify.

Social engineering works because it exploits habit and trust. Regular, realistic training that simulates invoice fraud attempts, not just generic phishing tests, helps AP staff build the instinct to pause on anything unusual.

5. Enable email authentication (DMARC, DKIM, SPF).

Configure DMARC, DKIM, and SPF on your own domain to prevent fraudsters from spoofing your outbound addresses. Encourage key vendors to do the same.

6. Watch for AI-augmented verification requests.

If a vendor requests confirmation via video or voice call, verify independently before the call. Establish code words or challenge questions with key contacts at large vendors.

7. Establish a clear escalation protocol.

Make sure every AP team member knows exactly what to do when something feels off, who to call, how to pause a payment in process, and that there will be no negative consequences for raising a concern. Fear of being wrong is one of the most common reasons fraud succeeds.

The uncomfortable truth about this fraud

Here's what makes vendor impersonation so persistently effective: it doesn't target your firewall. It targets your process, specifically the assumption that a familiar vendor, a familiar invoice, and a familiar email thread are inherently safe.

The Baltimore AP team wasn't careless. The Arup employee wasn't gullible. These were normal people doing normal jobs, trusting normal-looking communications, because that's what routine workflows require. The fraudsters knew that. They designed their attacks around it.

The only effective defense is building verification into the routine before an attack happens, not as a response to suspicion, but as standard operating procedure. Verify every banking change. Always. Without exception. No matter how legitimate it looks.

Because the most dangerous invoice you'll ever receive will look exactly like the ones you've always paid without a second thought.

Conclusion

Vendor impersonation is one of the fastest-growing categories of B2B financial fraud, and it starts with the same phishing and account-compromise tactics that put anyone's personal accounts at risk. Get started with a free scan to check whether your own accounts, identity, or inbox are already exposed to the phishing and credential-theft techniques fraudsters use to set these scams up.

CMS-based CTA:
Add Guardio to BrowserTake Security Quiz
Default CTA:
Smart protection, built for how you live online
Stay ahead of threats with real-time insights and proactive protection.
Add Guardio to BrowserTake Security Quiz
CMS-based "Did you know?" block
Did you know?
Default "Did you know?" block
Did you know?

Make sure you have a personal safety plan in place. If you believe someone is stalking you online and may be putting you at risk of harm, don’t remove suspicious apps or confront the stalker without a plan. The Coalition Against Stalkerware provides a list of resources for anyone dealing with online stalking, monitoring, and harassment.

Guardio Security Team
Guardio’s Security Team researches and exposes cyber threats, keeping millions of users safe online. Their findings have been featured by Fox News, The Washington Post, Bleeping Computer, and The Hacker News, making the web safer — one threat at a time.
Tips from the expert

Related articles

FAQs

What is a vendor impersonation scam?

A vendor impersonation scam is a fraud where criminals pose as a trusted supplier or business partner to trick an organization's accounts payable team into wiring payments to a fraudster-controlled bank account. The attacker typically sends a fake or altered invoice with updated payment details, relying on the target's existing trust in the vendor relationship. These scams fall under the broader category of business email compromise (BEC).

How do fraudsters redirect invoice payments to fake bank accounts?

Fraudsters redirect invoice payments by sending a spoofed or compromised email that impersonates a real vendor and requests a "banking update." The message includes a new account number, often on an otherwise identical invoice. When the AP team processes the payment using the new details, funds go directly to the attacker's account. The fraud often isn't discovered until the real vendor follows up on a missed payment.

How much money do businesses lose to vendor impersonation fraud each year?

The FBI's IC3 2025 Annual Report recorded $3.046 billion in business email compromise losses in 2025 alone, a 10% increase from the prior year. Vendor impersonation and invoice fraud are leading subcategories, with 60% of BEC scams in 2024 targeting organizations by impersonating vendors, according to the AFP Payments Fraud and Control Survey.

What is the difference between vendor impersonation and vendor email compromise (VEC)?

Vendor impersonation uses spoofed or lookalike email addresses to impersonate a supplier without actually accessing their accounts. Vendor Email Compromise (VEC) goes further: attackers gain actual access to the real vendor's email inbox, often through phishing or credential theft, and communicate from the legitimate address. VEC is harder to detect because the emails pass standard authentication checks.

What are the warning signs of an invoice fraud attempt?

Key warning signs include unsolicited requests to update bank account details, lookalike sender domains (e.g., one character swapped), urgency language like 'process before EOD,' a Reply-To address that differs from the sender, and invoices with vague line items or formatting inconsistencies compared to previous documents from the same vendor. Any banking change request should be verified by phone using a number already on file.

How can organizations prevent vendor impersonation scams?

The single most effective control is mandatory out-of-band verification: any request to change a vendor's banking details must be confirmed by phone using a number already on file, never by replying to the suspicious email. Supporting controls include dual authorization for high-value payments, a verified vendor master file, AP team training on social engineering, and enabling email authentication protocols like DMARC, DKIM, and SPF.

Is it possible to recover money lost to invoice fraud?

Recovery is possible but uncommon and time-sensitive. In the Baltimore contractor fraud case, $721,000 of $1.52 million was recovered. Speed is critical: wire transfers and ACH payments can sometimes be recalled if the fraud is reported to the bank within hours. The FBI's Internet Crime Complaint Center (IC3) and the Financial Crimes Enforcement Network (FinCEN) both have reporting mechanisms, but funds moved offshore are rarely recovered.

How is AI making vendor impersonation scams more dangerous?

AI gives fraudsters tools that were previously unavailable or expensive: voice cloning lets attackers place phone calls in a vendor contact's voice; deepfake video can impersonate a CFO on a live call; and AI writing tools produce grammatically flawless, hyper-personalized phishing emails. The FBI logged over $893 million in AI-enabled fraud losses in 2025 across more than 22,000 complaints, its first year tracking AI as a fraud category.

Table of Contents
Can You Spot a Scam Text Message?
Test your skills and learn how to protect yourself from online scams.
Take the quiz now
Can You Spot a Scam Text Message?
Test your skills and learn how to protect yourself from online scams.
Take the quiz now