Business email compromise is now one of the most costly fraud schemes affecting organizations of all sizes. According to the Association of Certified Fraud Examiners’ Report to the Nations, fraudulent disbursement schemes take many forms, and scammers continue inventing tactics that fall outside the traditional categories. One real-world case illustrates exactly how these attacks work, why they succeed at some companies, and what your organization can do to stop them.
The stakes are significant. The FBI’s Internet Crime Complaint Center has consistently ranked business email compromise among the highest-loss cybercrime categories, with billions of dollars stolen each year. These scams succeed because they exploit trust, routine, and gaps in internal controls rather than technical vulnerabilities. Understanding how they operate is the first step toward business fraud prevention, and it is a natural extension of the risk advisory services that protect a company’s finances.
How a real-world invoice fraud scam works
A sophisticated invoice fraud scheme recently targeted an automotive group, and it almost worked. Lisa, the CFO of Arbor Automotive Group, received an email requesting payment on an overdue invoice for $78,500. What made this email particularly convincing was that it appeared to include a reply from Marty, the company’s CEO, apologizing for the delay and instructing Lisa to process payment immediately.
The scammers had done their homework. They registered a fake business entity with the state, opened a legitimate-looking bank account, and crafted an email thread that mimicked internal communication. On the surface, everything appeared authentic: a vendor requesting payment, with apparent CEO approval already in place.
This type of attack is a textbook example of email impersonation fraud. Rather than hacking into email systems directly, the scammers fabricated an email conversation that appeared to originate from a trusted executive. The goal was simple. Trick the accounts payable team into wiring funds to a fraudulent account before anyone asked questions.
Red flags that exposed the accounts payable fraud
The scam unraveled because Arbor Automotive had strong processes and a CFO who trusted her instincts. Lisa noticed several red flags that stopped the fraudulent payment in its tracks.
The CEO verification check. Lisa found it unusual that Marty, the CEO, had apparently responded to the vendor without including her in the conversation. She contacted Marty directly, providing the recipient’s email address and the date and time of the supposed message. Marty checked his Sent Items folder and confirmed he had never sent the email. He also did not recognize the vendor. These were the first two critical red flags.
The vendor database check. Now on alert, Lisa searched for the purported vendor in the company’s accounting system. No record existed. She then cross-referenced the vendor’s state business registration and discovered the entity had been registered after the date the invoice claimed services were performed. A company cannot invoice for work it performed before it legally existed. This was the final confirmation the request was fraudulent.
The amount raised scrutiny. Perhaps the scammers’ biggest tactical error was requesting $78,500. An amount this large guaranteed CFO-level review. If they had requested $4,500 instead, the invoice might have been processed through accounts payable without the same level of scrutiny, a sobering thought for any organization that lacks controls on smaller payments.
Why strong fraud prevention controls matter at every level
Arbor Automotive Group survived this attack because its fraud prevention controls operated on multiple layers. Even if one safeguard had failed, another was in place to catch the problem.
The first layer was human judgment. Lisa’s experience told her something was off about the email chain. Executives who are trained to question unusual payment requests serve as a critical first line of defense against email-based fraud.
The second layer was procedural. Arbor had a policy requiring vendors to be added to the accounting system before the company entered into any service agreement. This meant that even if Lisa had not grown suspicious of the email, the invoice would have been flagged when accounts payable attempted to enter it, because the vendor did not exist in the system.
The third layer was verification. Rather than simply trusting the email at face value, Lisa took the extra step of confirming with the CEO directly. This out-of-band verification, meaning contacting someone through a separate channel to confirm a request, is one of the most effective defenses against vendor fraud prevention gaps and spoofed communications. A periodic audit and assurance review can confirm these controls are operating as designed across the year.
Organizations that rely on a single control point are vulnerable. A well-designed anti-fraud program layers procedural, technological, and human safeguards so that no single failure can result in a loss.
How to build your own anti-fraud procedures
Protecting your business from sophisticated fraud schemes requires a systematic approach. The following practices, drawn from the principles that saved Arbor Automotive, apply to organizations of any size.
Establish vendor onboarding protocols. Every new vendor should be verified and added to your accounting system before any agreement is signed or any invoice is accepted. This creates a clear audit trail and makes it much harder for a fraudulent vendor to slip through.
Implement payment authorization thresholds. Define dollar amounts that require escalating levels of approval. Payments above a certain threshold should require dual authorization, meaning two people must independently approve the transaction. This reduces the risk of both email impersonation scams and internal fraud.
Require out-of-band verification for unusual requests. Any payment request that arrives unexpectedly, comes from a new vendor, or involves a change in payment instructions should be verified through a separate communication channel. If you receive an email requesting payment, pick up the phone and call the requester at a known number, not a number listed in the suspicious email.
Train your team regularly. Fraud awareness training should not be a one-time event. Scammers constantly refine their tactics, and your staff needs to recognize the latest schemes. Training should cover how to spot spoofed emails, fabricated invoice threads, and social engineering techniques that pressure employees into acting quickly.
Reconcile accounts payable regularly. Routine reconciliation of vendor accounts helps surface unauthorized payments, duplicate invoices, and other anomalies before they become significant losses. Accounts payable fraud often goes undetected for months when reconciliation is infrequent or superficial.
Review state registrations and business credentials. When a new vendor submits an invoice, verify that the business has been registered for longer than the period in which it claims to have provided services. This simple check caught the scam at Arbor Automotive and can be performed in minutes through state secretary of state databases. For guidance on recognizing the broader threat, the FBI’s public service announcements on business email compromise outline current attack patterns and reporting steps.
The growing sophistication of email impersonation scams
These attacks have evolved well beyond simple phishing emails. Modern scammers research their targets thoroughly, studying company websites, LinkedIn profiles, and public filings to understand organizational hierarchies and communication styles. They time their attacks to coincide with busy periods such as end of quarter, year-end close, or leadership travel, when employees are more likely to process requests without full scrutiny.
Some attackers now use AI-generated content to craft emails that perfectly mimic a CEO’s writing style. Others register domains that differ from the target company’s domain by a single character, making spoofed emails nearly indistinguishable from legitimate ones at a glance.
This escalation means that vendor fraud prevention and accounts payable fraud controls must evolve in parallel. Static procedures that were adequate five years ago may not withstand today’s attacks. Organizations should review and update their anti-fraud procedures at least annually, incorporating lessons from recent fraud attempts and industry trends.
What to do if you suspect a fraudulent request
Acting quickly when you suspect fraud can prevent losses and help law enforcement track down the perpetrators. If you receive a suspicious invoice or payment request, do not process the payment. Instead, flag it internally and begin your verification process immediately.
Report confirmed or suspected attempts to the FBI’s Internet Crime Complaint Center (IC3) and to your bank. If a wire transfer has already been sent, contact your financial institution immediately, because in some cases funds can be recalled if the fraud is reported quickly enough.
Document everything. Preserve the original emails, including full headers, and record the steps you took to verify the request. This documentation will be valuable for both internal review and any subsequent investigation.
Finally, use the incident as a learning opportunity. Brief your team on what happened, how the fraud was detected, and what controls prevented a loss. Real-world examples are far more effective than hypothetical scenarios when training employees on business fraud prevention.
Frequently Asked Questions
What is business email compromise?
BEC is a type of fraud where scammers impersonate executives, vendors, or trusted contacts through email to trick employees into transferring funds or sharing sensitive information. It is one of the most financially damaging cybercrimes, often bypassing technical security measures by exploiting human trust and organizational procedures.
How can I tell if an invoice is fraudulent?
Check whether the vendor exists in your accounting system, verify the business registration date against the claimed service period, and confirm the request through a separate communication channel. Fraudulent invoices often come from vendors with no prior relationship, include urgency language, or arrive with unusual payment instructions such as new bank account details.
What are the most effective fraud prevention controls for small businesses?
The most effective controls include requiring dual authorization for payments above a set threshold, maintaining a verified vendor list, conducting regular accounts payable reconciliation, and training all employees who handle payments to recognize social engineering tactics. Even basic controls like calling to verify unexpected requests can prevent significant losses.
How do scammers spoof CEO emails in BEC attacks?
Scammers may register domains that closely resemble the target company’s domain, use email display name spoofing to show the CEO’s name on a message sent from a different address, or in some cases gain access to the actual email account through phishing. More advanced attackers fabricate entire email threads to make their requests appear as continuations of legitimate conversations.
Should I report a suspected email fraud attempt?
Yes. Report confirmed or suspected attempts to the FBI’s Internet Crime Complaint Center (IC3) and to your financial institution. If funds have already been transferred, contact your bank immediately because early reporting increases the chance of recovering the money. Reporting also helps law enforcement identify and disrupt fraud networks.
How often should a company update its anti-fraud procedures?
Companies should review and update their anti-fraud procedures at least once a year, and immediately after any fraud attempt or significant organizational change. Scammers constantly adapt their methods, so procedures that were effective last year may have gaps today. Annual reviews should incorporate lessons from recent incidents, industry alerts, and emerging fraud trends.




