Invoice fraud names the instrument: a fake or altered invoice used to redirect a payment. Business email compromise names the delivery method: a trusted email identity. Most large invoice frauds are carried out by BEC, but an invoice fraud can arrive by post or portal with no email involved at all.
Keeping them separate helps because the controls sit in different places. BEC controls protect the mailbox. Invoice-fraud controls protect the vendor master file and the payment run.
Documented cases
- Rimasauskas is both at once: fraudulent invoices, delivered under a supplier identity, for $120 million.
- Dickinson Public Schools shows vendor-payment redirection against a school district in 2026.
- Cabarrus County lost public funds to a redirected construction payment.
The control that breaks it
- Protect both layers. Mailbox hardening does not help if bank details can be changed on a phone call.
- Reconcile invoices to purchase orders before payment, not after.
- Require callback plus dual approval for any payee bank change, whatever channel it came through.
Related: how to prevent invoice fraud · CEO fraud vs BEC · Invoice fraud
Related