Invoice fraud can succeed even when the person making the transfer logs in securely and approves it themselves. The weak point is often the payment instruction: a changed account number, a fabricated invoice or a convincing request from an apparently familiar contact. Small teams need a check on the reason and destination of a payment before authorisation.

The EBA and ECB’s December 2025 report makes the problem visible. Strong customer authentication remains useful, but criminals also manipulate legitimate payers. The practical response is to separate invoice approval, supplier-detail changes and the final release of money.

Read the fraud figures in their proper period

The joint EBA-ECB release of 15 December 2025 reports €4.2 billion in payment fraud across the European Economic Area in 2024, compared with €3.5 billion in 2023. Those are historical aggregate figures, not a measurement of a particular company’s risk in April 2026.

The release says that payment service users bore approximately 85% of credit-transfer fraud losses in 2024, largely because of scams that persuaded users to initiate payments. It also explains that strong authentication remains effective against the kinds of fraud it was designed to mitigate.

The lesson is specific: proving that the real account holder approved a transfer does not prove that the account holder understood the true destination or purpose. Authentication and transaction judgement solve different problems.

Do not use the aggregate percentage to predict your chance of reimbursement. The outcome of a particular incident depends on its facts, jurisdiction and applicable rules. Use the report to understand the attack pattern and improve the process.

Find the moment when payment details become trusted

In many small businesses, an invoice arrives by email and the bank details are copied into the payment screen. That step can turn an unverified document into an instruction to move money.

Identify where the authoritative supplier record lives. Who can create it? Who can change it? How is a change confirmed? If the answers are unclear, the company may be relying on whichever email was received most recently.

Keep the invoice amount and the bank-account record as separate objects in the process, even if they are stored in the same application. An invoice can be valid while its payment details have been altered.

The person preparing a transfer should compare the invoice with the trusted supplier record. A difference should trigger a specific check, not an assumption that the supplier has simply changed banks.

Verify a change through an existing contact route

Use contact information established independently of the change request. Calling a number printed in the suspicious email merely asks the same source to confirm itself.

A callback can be simple: identify the supplier through the established route, confirm that a change was requested and verify the relevant details. Record who performed the check and when. For a significant relationship, agree the change process when onboarding the supplier.

Avoid sending a reply that includes confidential banking credentials or authentication codes. The supplier needs to confirm its own receiving details; it does not need access to your bank account.

A real supplier can still have a compromised mailbox, and a familiar voice alone is not a complete control. The callback should be one part of a process that also checks the invoice, contract and authority to change the supplier record.

Give the approver enough information to disagree

A second approval is useful only if it is an actual review. The approver should see the supplier, invoice, amount, business purpose, due date and destination account, plus any recent change or exception.

If the system shows only a total and a button, the approver may be confirming the preparer’s work without evidence. Add the information that could reveal a problem.

For a two-person business, one person can prepare the payment and the other review the supporting evidence. For a sole operator, use a deliberate second pass, a saved supplier record and an independent confirmation route for changes.

Payment situation Check before release Evidence to retain
Existing supplier, unchanged details Invoice and amount against records Approved invoice
New supplier Business identity and receiving details Onboarding record
Changed account Independent confirmation Change record and reviewer
Unusual urgent request Authority and business reason Explicit exception decision
Duplicate-looking invoice Prior payment and invoice reference Reconciliation result

The process should fit the payment’s consequence. A large unusual transfer deserves more investigation than an ordinary recurring bill to a verified account.

Use name checks without overestimating them

Verification of Payee can help identify a mismatch between an account and a recipient name. It is valuable evidence about the destination, but it does not establish that the invoice is genuine.

A criminal may ask for payment to an account that genuinely matches the supplied name. A legitimate supplier’s account may also be selected for a duplicate or unauthorised invoice. The name check cannot decide whether the business owes the money.

Our Verification of Payee guide explains how to handle matches, mismatches and unavailable checks. The key is to record the result alongside the invoice decision, not replace the invoice decision with it.

If a mismatch appears, investigate it before experimenting with alternative names. The expected account holder should be established from verified information, rather than guessed until the interface turns green.

Rehearse an urgent-request scenario

Imagine an illustrative agency with a €12,400 supplier payment due on Friday. On Thursday afternoon, an email in an existing thread says the supplier’s bank account has changed and that a delay will stop delivery.

The preparer notices that the new IBAN differs from the supplier record. The payment is marked as awaiting verification. A call to the established contact reveals that the supplier did not request the change.

The company keeps the original message, stops the attempted change and informs the relevant people through trusted channels. The normal payment can then proceed only after the genuine details and invoice are confirmed.

Now suppose the supplier really did change banks but the contact cannot be reached. The process still has value: the unresolved fact is visible to the person deciding whether to delay or authorise an exception. Urgency is a business consideration, not evidence that the new account is correct.

Reduce the pressure that makes exceptions attractive

Late invoice collection, unclear approval ownership and a single unavailable approver create conditions in which staff feel compelled to bypass checks. Fraud prevention therefore includes ordinary process design.

Agree payment cutoffs, backup approvers and the information required from suppliers. Tell suppliers how bank-detail changes are handled. A predictable process makes a sudden demand for an exception easier to recognise.

Keep the emergency route narrow. Record what could not be checked, who accepted the risk and which follow-up remains. If the same exception happens every week, repair the ordinary process rather than normalising the exception.

Avoid judging the preparer solely on payment speed. A person who pauses a suspicious request should not be penalised for missing a target that implicitly requires skipping the agreed checks.

Know the first actions after a mistaken transfer

Contact the bank or payment provider promptly through its official route and explain that the transfer may be fraudulent. Ask what recovery or recall steps are available. Do not assume that the recipient will cooperate or that a recall is guaranteed.

Preserve the invoice, messages, payment reference, account details and relevant timestamps. Keep the evidence in a controlled location. Avoid forwarding sensitive material widely while trying to alert colleagues.

Stop further payments connected with the same uncertainty. If a mailbox or account may be compromised, involve the appropriate administrator and secure the account through trusted means. A payment incident and an account incident may need separate actions.

Report the incident to the relevant authorities or service channels as appropriate to the jurisdiction. This guide cannot determine a legal reporting obligation for every business, but the internal plan should identify who will make that assessment.

Investigate the path, not just the person who clicked

After the immediate response, reconstruct how the instruction became trusted. Was the supplier record altered? Did the approver see the changed details? Was a warning overridden? Did the process rely on contact information from the same message?

The purpose is to find a repeatable weakness. Simply telling staff to be more careful leaves the same conditions in place.

Review whether access rights allowed one person or compromised account to change supplier details and release a payment without another check. Adjust the workflow where that combination is unnecessary.

Also check ordinary errors: duplicated invoice numbers, missing credit notes, stale account details and inconsistent supplier names. The same records that make fraud easier can also create costly mistakes without any attacker.

Keep the checklist short enough to use

A practical payment check can fit on one screen: is the invoice owed, is the amount correct, is the recipient the intended entity, have account changes been independently verified, and has the right person approved the transfer?

Add a visible exception field rather than a long generic declaration that everyone clicks through. A reviewer should be able to see what remains uncertain.

Use periodic samples to confirm that the process is actually followed. A policy document and a configured approval button do not prove that anyone examines the evidence.

The strongest small-team process is often a modest one maintained consistently. Trusted supplier records, independent checks on changes and a clear approval decision address the point where an ordinary business document becomes a movement of money.

Reconcile after payment as well

Match the completed transfer with the approved invoice and supplier record. A correct approval can still be followed by a data-entry mistake or duplicate execution. Check the actual payment reference and amount, then mark the invoice paid so it does not re-enter the next batch.

If the supplier reports non-receipt, investigate through the existing contact route and payment provider before making another transfer. Repeating the payment can compound an ordinary delay or a fraud attempt.

Questions

Can invoice fraud happen when two-factor authentication is enabled?

Yes. Authentication can confirm that the legitimate user approved a transfer while the user was deceived about its purpose or destination.

Does a familiar email thread prove a bank-detail change is genuine?

No. Confirm material changes through an established independent route and retain the result.

What should I do immediately after a suspected fraudulent transfer?

Contact the payment provider through its official channel, preserve the evidence and stop related uncertain payments. Recovery is not guaranteed.

Does every payment need two people?

The arrangement should match the business and consequence. Where separation is possible, make it a real evidence-based review; a sole operator still needs a deliberate verification process.