All insights

Wire fraud

You approved the invoice. The account field did the damage.

Published
September 25, 2026
Read
4 min
Desk
Coffr Content Desk

Invoice manipulation fraud can leave the bill intact while changing the payment instruction AP relies on.

Accounts payable invoice with a changed bank account field highlighted before payment release.

The invoice is familiar. The vendor name is right. The amount matches the purchase order. The due date makes sense. No one is asking for an odd prepayment.

One field has changed.

That is the quiet strength of invoice manipulation fraud. It does not ask AP to believe a new story. It asks AP to keep processing an old obligation with a different payment destination attached.

The FBI's 2023 Internet Crime Report recorded 21,489 business email compromise complaints with more than $2.9 billion in adjusted losses. The report does not isolate every manipulated invoice. It does show the scale of payment redirection as a finance-office problem, not a fringe email problem.

The invoice can be real and still be unsafe

A valid payable can carry a false instruction. That is the distinction AP has to protect.

The vendor may exist. The work may be complete. The internal requester may confirm receipt. The invoice total may match the PO. The corrupted part is the destination of funds.

That makes the failure hard on professionals who did ordinary work in the ordinary way. An AP specialist may process the document in front of them. An approver may confirm the business owes the money. A controller may discover the loss only after the real vendor asks why payment never arrived.

Then the office stops. Staff pull remittance records. Banks are called. Future payments are frozen. Email headers are collected. The vendor file is rebuilt under pressure.

The money is the visible damage. The human cost sits beside it. Authority is narrowed. Trust changes. People who acted in good faith can carry the incident long after a recall attempt fails.

How the field gets poisoned

The decisive act is usually small. Someone accepts a changed account number, routing number, IBAN, beneficiary name, or remittance address as if it were ordinary invoice data.

Sometimes the invoice itself is intercepted and edited. The line items stay the same. The total stays the same. Only the account field moves.

Sometimes the instruction comes from a real vendor mailbox. A compromised account is hard to judge by tone or thread history because the thread may be genuine.

Sometimes the vendor master is changed before the invoice arrives. The next payment then flows through a bad record that already looks approved inside the system.

In each version, the false instruction becomes operational fact when it enters the ERP, bank portal, payment file, or vendor record. After that, later checks may only confirm the wrong thing.

Approval can confirm the wrong fact

Invoice approval is not payment-instruction approval. One confirms the obligation. The other confirms where money should go.

A second approver can confirm the amount. A payment release checklist can confirm the vendor is active. A bank portal can confirm the account format is valid. None of those facts prove the vendor controls the destination account.

Email can also give false comfort. A reply in the same thread may feel persuasive. A PDF on familiar letterhead may feel complete. A phone call to the number printed on the changed invoice may feel careful.

But if the contact path came from the suspect instruction, the business may only be asking the attacker to confirm the attack.

Training helps staff notice patterns. It cannot carry the control alone. A well-timed invoice from a known supplier is normal business with one corrupted instruction.

Secure the next instruction

The control objective is plain. Treat payment instructions as controlled data, separate from the invoice.

AP needs evidence that the payment destination belongs to the intended counterparty before money moves, especially when any bank field has changed.

  • Separate spend approval from destination approval. The business can approve the invoice. A different control should verify where the funds will land.
  • Flag every payment-detail change. Account number, routing number, beneficiary name, remittance contact, and payment country changes should trigger added review.
  • Use trusted contact records. A callback should use independently maintained vendor contact data, not a number or email address supplied in the change request.
  • Test ownership, not format alone. A valid account format is useful. It is not proof that the vendor owns the account.
  • Keep the evidence trail. AP should be able to show who supplied the instruction, what changed, who verified it, what source was used, and who approved the change.
  • Watch small changes as well as large payments. A low-value payment can test the path for a later loss.
  • Treat urgency as a risk signal. Rush payments, overdue notices, and month-end pressure should raise scrutiny before release.

The next manipulated invoice will likely look like a payable already earned. If AP cannot prove the destination outside the document that supplied it, the payment run is accepting a claim, not a control.

Questions practitioners ask

What is invoice manipulation fraud?

Invoice manipulation fraud is a payment redirection scheme where a genuine or plausible invoice is altered so payment goes to an account controlled by the attacker.

Why can invoice manipulation pass normal AP review?

It can pass because the vendor, amount, purchase order, and approval path may appear valid. The corrupted element is often the bank account or remittance instruction.

Does invoice approval verify bank ownership?

No. Invoice approval confirms the business obligation. Bank ownership needs a separate verification step using trusted contact data or other independent evidence.

What should trigger added review?

Any new or changed payment detail should trigger review, including account number, routing number, beneficiary name, remittance contact, or payment country.

Share and cite

XLinkedInRedditEmail

Community newsletter

The Trust Layer Briefing

CFOs, controllers, and AP leaders subscribe for weekly research on BEC vectors, ERP gaps, and payment instruction security.

One email each Thursday. No spam, one-click unsubscribe.

Practitioners can also request a seat on The Coffr Research Panel.