Skip to content
Fraud casesFake documentsCompliance

Invoice fraud: $55.5B lost to one changed bank line

by Julia Jansen11 min read

A Tasmanian homeowner wired AU$120,000 to criminals who had spent weeks quietly reading her email correspondence with the construction company renovating her house. The invoice arrived when she expected it, in a thread she recognized, for an amount that made sense. Only the bank account had changed. She reported it late, and the Australian Federal Police could not claw the money back.

Here is the uncomfortable part: if this happened to your company last month, you would not know yet. Invoice fraud surfaces when the real supplier chases a payment you already made, and on 30, 60 or 90 day terms that call comes long after the money has moved through three accounts.

Invoice fraud is when a criminal gets a business to pay a genuine-looking invoice into an account they control. The usual route is a compromised mailbox: the attacker waits for a real supplier invoice, edits the bank details in the PDF, then lets your own accounts payable process do the rest. The document passes review because it started out authentic and was changed afterwards.

This is not a fringe crime. Invoice fraud through Business Email Compromise (BEC) is one of the most financially damaging categories of cybercrime on record, with $55.5 billion in reported losses between October 2013 and December 2023 according to the FBI.

European businesses are hit just as hard. The Dutch arm of cinema chain Pathe lost €19.2 million in a single BEC campaign in 2018. The pattern rarely changes: companies with solid payment controls still get caught, because nobody in the chain ever inspects the invoice PDF itself.

The short version

  • How it works. A criminal reads a real email thread, waits for a genuine supplier invoice, changes one line (the bank account) and resends it. The document is authentic. Only the destination is not.
  • Why your controls miss it. Dual authorization, callbacks and staff training all check the process. None of them check whether the file has been edited.
  • Where the evidence is. In the PDF’s internal structure: metadata that contradicts the invoice date, a bank account line in a substituted font, content added after the original save.
  • What to do. Run the invoice through document forensics before it enters the approval queue, and call the supplier on a number you already had on file if it comes back flagged.

€19.2 million left Pathe in under three weeks

If you want to see how far a fake invoice scam can run before anyone asks a question, look at Pathe.

In March 2018, management at Pathe Nederland received emails that appeared to come from the chief executive of the French parent company, requesting urgent confidential payments for an acquisition in Dubai. According to details of the Amsterdam District Court ruling on the resulting dismissal case, the first transfer went out on 9 March: €826,521, to an account in the name of Towering Stars General Trading. A second followed on 13 March for €2,479,563. More payments followed. By 27 March the Amsterdam office had paid out €19,244,304.

The fraud came to light that same day, when the Paris headquarters queried the unusual cash pool withdrawals. Both the Dutch chief executive and the finance director were dismissed. The court later ruled that the finance director’s dismissal was not justified.

How does this happen at a major European company? The emails were convincing. Framing the acquisition as confidential discouraged the recipients from verifying through normal channels. And critically, nobody questioned the paperwork: an invoice from the Dubai company, apparently signed by both the French parent’s manager and its chief executive, was taken at face value because it looked professional.

Why PDF invoices are the perfect fraud vector

Here is what most people miss: a PDF invoice is just a file. A bank statement at least originates inside a regulated institution’s systems. Nobody certifies who created an invoice PDF, or whether it was changed after creation.

Editing one takes no special skill. A fraudster opens a legitimate invoice in a PDF editor, and there are plenty of free ones, changes the bank account line and saves.

The embedded fonts survive. The layout survives, because nothing structural changed. Even the metadata can be preserved if the person doing it knows what to look for.

The result is a document that a human reviewer has almost no chance of separating from the real one. As we covered in why most fake documents are invisible to the human eye, the manipulation sits below the layer anyone reviewing a printout can see.

And it gets worse. Most accounts payable teams check invoices by confirming amounts, confirming the vendor is known and comparing the layout against previous invoices. Almost nobody checks whether the file itself has been altered. The document is treated as trustworthy because it looks right.

How one compromised mailbox becomes a million-euro loss

So how does an edited invoice reach your approval queue in the first place? The kill chain is simple. Almost insultingly so. Criminals have been running it for years.

Step 1, get into the mailbox. The attacker gains access to a legitimate email account, usually through a phishing email or stolen credentials. This can be the buyer’s account or, more commonly, the supplier’s. A single phishing email or a reused password is often all it takes.

Step 2, watch and learn. Once inside, the fraudster does nothing. For weeks. They read email threads, study payment schedules, learn which vendors send invoices and when. They often set up inbox rules that forward anything containing words like “invoice” or “wire transfer” to an external address, while hiding those forwarded messages from the legitimate user.

Step 3, clone the invoice. When the timing is right, usually when a real payment is due, the attacker produces a copy of the expected invoice. Same format, same logo, same line items, same amounts. The only change is the bank account number.

Step 4, send and intercept. The fake invoice goes out from the compromised account or from a look-alike domain (think company-invoices.com instead of company.com). The recipient has no reason to be suspicious. The invoice was expected, the amounts match and the email appears to come from a known contact.

Step 5, cash out. Once the transfer lands, the money is split across accounts and jurisdictions, often through money mules. Recovery then depends almost entirely on speed. In the same AFP cases, a New South Wales construction company that reported AU$41,800 in fraudulent supplier invoices immediately got the full amount back, while the Tasmanian victim who reported late got nothing.

That is the whole chain. Note what is missing from it: at no point does the attacker have to defeat a security control. The fraud works because the invoice looks exactly like the invoice you were already expecting.

Invoice fraud is the second-costliest cybercrime in the US

This is not a handful of unlucky companies, and the numbers are lopsided. The FBI’s Internet Crime Complaint Center logged $2.77 billion in BEC losses in 2024 across 21,442 complaints. That made BEC the second-costliest category of reported cybercrime in the US that year, behind investment fraud at $6.57 billion. Those are only the cases somebody reported.

Invoice fraud stays out of the headlines because it does not look like a cyberattack. No encryption, no ransom note, no downtime. A company receives an invoice that looks exactly like a real one, pays it and finds out weeks later when the actual supplier asks where the money went.

The 2025 AFP Payments Fraud and Control Survey found that 79% of the organizations surveyed were hit by attempted or actual payments fraud in 2024, and that BEC was the number one avenue, cited by 63% of respondents. The figure that should worry every CFO is the recovery rate: 22% of organizations recovered 75% or more of the funds they lost, down sharply from 41% the year before.

Fake invoices are not only an accounts payable problem, either. The same document trick shows up in trade and tax, where fake customs invoices drained €800 million from the EU over eight years through a single port. It also shows up at the very start of the relationship, in the fake W-9s and bank letters submitted during vendor onboarding.

What most businesses get wrong about invoice fraud detection

The standard advice runs like this: implement dual authorization for payments, verify bank detail changes by phone and train staff to spot suspicious emails. All good advice. All of it skips the document.

Think about what that means. You could run the most rigorous payment approval workflow in existence (dual sign-off, callback verification, segregation of duties) and still be applying every one of those controls to a forged PDF. You are authenticating the process while ignoring the evidence.

Detection lag is the predictable result. The ACFE’s 2024 Report to the Nations found that the median occupational fraud case ran 12 months before anyone noticed, and that 43% of cases surfaced through a tip rather than through a control. That study covers internal fraud, not BEC, but the lesson transfers: when detection depends on somebody happening to notice, it is not a detection strategy.

How to spot a fake invoice: the red flags live in the PDF

So how do you actually catch one? These are the signals document forensics can pick up:

  • Metadata inconsistencies. The creation date does not match the invoice date. The software that supposedly produced the invoice is not what the vendor normally uses. The author field holds an unexpected name or is suspiciously blank.

  • Font anomalies. The bank account number sits in a slightly different font or size than the rest of the page. This happens when a fraudster edits specific fields, because even good PDF editors sometimes substitute fonts during re-encoding.

  • Content stream modifications. The PDF’s internal structure shows signs of post-creation editing: multiple content layers, out-of-sequence object IDs or overlay objects added after the original save.

  • Producer mismatch. The invoice claims to come from an ERP system like SAP or Oracle, but the metadata shows the file was last written by Adobe Acrobat Pro or a free online editor.

  • Inconsistent compression. Different parts of the document use different compression methods, a strong hint that someone opened the file, made changes and re-saved it.

None of these are visible to the naked eye. You have to read the file’s internal structure, which is what AI-powered document forensics does. The fastest way to see it for yourself is on an invoice you have already paid: run it through the free check on our homepage and look at what the metadata says about who last touched the file. Submit the PDF with a business email address and we send you the full forensic report, one free check per business email, no account to create.

Where invoice fraud detection belongs in your payment process

Every layer of invoice fraud prevention focuses on process: who approves payments, how bank detail changes get verified, what training people receive. That all matters. But process controls cannot answer the one question that decides whether a payment is legitimate. Is this document genuine?

That is the gap document fraud detection software fills. Before an invoice enters the approval queue, run it through forensic analysis. VerifyPDF reads the PDF’s internal structure, flags metadata anomalies, looks for content modifications and returns a rating of Trusted, Low Risk, Needs Attention or High Risk. A single-page invoice typically comes back in about five seconds, with longer multi-page documents taking up to 30.

This is a layer, not a replacement. A fraudster who builds an invoice from scratch in a convincing template leaves fewer structural traces than one who edits a real PDF, so document forensics belongs alongside callbacks and dual authorization rather than instead of them. What it adds is the evidence those controls cannot reach: the file itself.

Trusted? Process it normally. Needs Attention or High Risk? That is your cue to call the supplier on a number you already had on file, before any money moves.

Stop trusting invoice PDFs at face value

Invoice fraud through business email compromise is not going away. The AFP reported in October 2025 that BEC losses in Australia alone hit AU$152.6 million in 2024, a 66% rise on the AU$91.6 million recorded in 2023. Recovery rates are falling. Fake invoices keep getting better at passing every human check.

The teams that stay exposed are the ones that stop at process (callbacks, dual authorization, training) and never question the file. The invoice looks right, so it must be right. That assumption has cost businesses billions.

The fix is not complicated. Put a document check in front of your approval workflow and run every invoice PDF through it. Try it on an invoice you have already paid and see what the metadata says about who last touched it. The best time to catch a fraudulent invoice is before the wire leaves.

Stop guessing. Know in 5 seconds.

Upload a PDF. In under 5 seconds, VerifyPDF tells you if it's genuine or forged, with detailed evidence of every modification. Try it free for 15 days, no credit card needed.

Trusted

This document is identical to others from this issuer

Match found in our document database
Document integrity verified
No traces of suspicious editing software