Protecting Your Business From Vendor Payment Fraud
Key Takeaways:
- Vendor payment fraud is the most expensive scam impacting businesses today and can’t be solved through effective cybersecurity alone.
- It often uses real vendor names and legitimate-looking invoices, so any unexpected change to payment details deserves scrutiny before approving the request.
- According to Tim Hadley, having layered internal controls, like dual approval and change alerts, ensure a single email or employee mistake can’t turn into a costly, hard-to-recover payment.
Business email compromise (BEC) and vendor payment fraud have become the most expensive scams for businesses today. In fact, according to the FBI’s Internet Crime Report, BEC was the second-costliest cybercrime category in the country in 2025, behind only investment fraud, with nearly 25,000 reported cases resulting in a loss of $3.05 billion.
This type of deception is particularly dangerous because it exploits routine AP processes rather than obvious cybersecurity vulnerabilities: Bad actors impersonate suppliers and request a change in the established process, which redirects legitimate payments.
These scams can be particularly difficult to spot since they often involve approved vendors and real invoices. The potential losses underscore why payment change requests should not just be treated as routine administrative updates.
RECOGNIZE: What Is Vendor Payment Fraud?
Vendor payment fraud occurs when the perpetrator impersonates a legitimate supplier or otherwise manipulates a payment process to redirect money to an account they control. This can look like changing a vendor’s banking information, sending payment to a different account, or submitting an invoice that appears to come from a recognized business.
These schemes can take several forms, but they often rely on familiar business information and routine AP processes to appear credible.
Common approaches include:
- Fake invoices
- Compromised vendor email accounts
- Spoofed email addresses/domains
Because these requests may involve a real vendor, a legitimate invoice, or information the attacker has gathered about the business, employees may have little reason to question the request at first glance. That makes it important to look for changes in the request or communication itself.
Potential red flags that should trigger additional attention:
- An unexpected request to change bank account or payment information
- Changes to a vendor’s usual communication pattern, such as inconsistent names or account details
- Instructions to bypass normal contacts or procedures or to use a different payment method
- Urgency or pressure to act quickly
- Messages sent from an unfamiliar email address or slightly altered domain
While a red flag may have an innocent explanation, any payment request should be independently verified. Employees should have a clear process for escalating questions rather than feeling responsible for making that call alone.
RESPOND: How Should Businesses Verify Vendor Payment Changes?
A consistent process helps ensure that requests are not approved based on each person’s attentiveness to the warning signs.
These steps can include:
1. Pause before automatically making the change.
Don't update vendor records or release a payment based solely on the incoming message.
2. Verify through an independent channel.
Contact the vendor using a trusted phone number or contact information already on file, not the information included in the request.
3. Require secondary approval.
Have another authorized employee review and approve changes to payment information.
4. Document the verification.
Record who confirmed the request and when the change was approved.
5. Apply the same process every time.
Don’t make exceptions, even for familiar vendors or senior employees.
By making verification a defined part of the payment process, rather than an extra step employees must remember, every request gets the same level of scrutiny. Written procedures can also help organizations maintain consistency when different employees handle vendor setup, invoice processing, and payment approval.
PREVENT: Build Internal Controls That Add Friction to Make Fraud Harder
The risks can extend beyond a single transaction: Once a bad actor gains access to a vendor relationship or payment process, the business may face additional false requests, leading to operational disruption and time-consuming efforts to recover funds. That makes vendor payment fraud a business-process risk as much as a cybersecurity concern.
Strong internal controls add layers of protection, allowing fewer opportunities for fraud to move from an email to an approved payment. They also reduce the risk that a single compromised account or employee mistake can result in a financial loss.
Here are some organizational protocols that strengthen security:

Organizations should also reassess these controls periodically as payment processes, staffing, and vendor relationships change. A control that works well on paper may unintentionally open a window to criminal activity if responsibilities shift or employees develop workarounds for a difficult-to-follow process.
Prevention Starts Before the Fraud Attempt
Vendor payment fraud cannot be addressed through cybersecurity tools alone. An attack will only be successful if there aren’t guardrails for sufficient verification and oversight that prevent the request from moving through the organization.
That’s why departments such as AP, finance, procurement, and IT all need to work together to reduce the opportunity for a fraudulent request to become a fraudulent payment.
The most effective approach is to make secure payment practices part of the normal workflow. Employees should know how to recognize warning signs but also have an established verification process to follow. With the right controls in place, organizations can strengthen payment security while keeping legitimate vendor transactions moving efficiently.
Learn more about how to recognize and prevent scams with Old National’s fraud prevention resources.
About the Author
Tim Hadley, CTP, MBA, is Senior Vice President & Treasury Management Product Director at Old National Bank. He works with commercial clients to strengthen payment controls, improve cash management, and help mitigate fraud risk through strategic treasury management solutions.