Skip to main content

AI-Generated Fake Invoices Are Fooling Accounts Payable Teams — Here's How to Stop Them

6 min readMike ThriftMike Thrift
AI-Generated Fake Invoices Are Fooling Accounts Payable Teams — Here's How to Stop Them

A textile importer got an urgent email from what looked exactly like their usual supplier in Vietnam. The factory's bank account had been "temporarily frozen by authorities," the email said, and payment needed to go to an alternate account in Hong Kong instead — today, to avoid missing a shipping deadline. The company wired $280,000. Weeks later, the real supplier called asking why an invoice was overdue. By then, the money was gone, routed through an account that, like most fraudulent transfers of this kind, was effectively untraceable once it left the country.

Nothing about that email was sloppy. No typos, no broken logos, no generic "Dear Sir/Madam." The fraudster had reportedly monitored the company's email threads for weeks before striking, timing the request to match a real, expected invoice. That level of patience and polish used to be rare. In 2026, it's becoming routine — because generative AI has made it cheap.

Why This Is Suddenly Everywhere

Invoice fraud and vendor impersonation aren't new. What's changed is who can pull it off and how convincing the result looks. According to the 2026 AFP Payments Fraud and Control Survey, 76% of organizations experienced attempted or actual payments fraud in 2025, with vendor impersonation the single most common tactic behind business email compromise (BEC) attacks — and BEC itself was named the top fraud vector by 63% of respondents. Security researchers tracking these attacks saw business email compromise attempts rise another 15% in 2025 over the prior year, with some firms intercepting thousands of BEC messages a month.

The mechanics of the scam are simple, which is exactly why it works:

  1. A criminal compromises or spoofs a vendor's email account, or simply registers a lookalike domain.
  2. They insert themselves into a real, ongoing conversation ("just resending the invoice," "quick update on our banking details") or fabricate a plausible-sounding new one.
  3. They ask you to update payment details — a new bank account, a new wire routing number — before the next invoice is due.
  4. Your team pays the "vendor" exactly as instructed. The money goes to the fraudster instead.

What's new is the tooling behind step 2 and step 3. Large language models can now generate an entire fake vendor identity: a forged W-9, a professional-looking website, plausible tax documents, even a voice agent that answers the phone if someone tries to verify by calling the number on the invoice. Fraud investigators describe criminals "building complete vendor identities," not just faking a single document. The emails themselves read as if a native English-speaking professional wrote them, because in a sense, one did — the AI was trained on millions of them.

It isn't limited to invoices from outside vendors, either. AI-generated fake receipts now account for an estimated 70.8% of expense-report fraud, according to one 2026 industry analysis, and nearly 4 in 10 employees surveyed in the US and UK admitted to having used AI to fabricate at least one expense receipt. Separately, AP automation researchers who reviewed $500 million in customer invoices found that 8.5% were duplicates — a reminder that not all invoice fraud is exotic; plenty of it is just old-fashioned resubmission that nobody caught.

What Makes These Harder to Catch Than Old-School Phishing

The old advice — "watch for typos and weird phrasing" — doesn't hold anymore. A few things specifically changed:

  • The grammar is perfect. AI-written scam emails match the tone, vocabulary, and formality level of a real business correspondent, tailored per victim.
  • The documents look right. Logos, letterhead, invoice formatting, and even tax ID numbers can be close enough to the real thing that a quick visual check won't flag anything.
  • The skill floor dropped to nearly zero. Someone with no technical background and a laptop can now run a scheme that previously required either social engineering expertise or a team.
  • Distributed procurement multiplies entry points. More companies accept invoices through more channels — email, vendor portals, chat — and each one is a place a fake can slip in.

The Controls That Actually Work

None of this means AP automation is doomed — it means verification has to move outside the document itself, because the document can no longer be trusted to prove anything on its own.

Verify banking changes out-of-band, every time. If a vendor asks to change payment details, call them back using a phone number you already have on file — never one provided in the email or invoice requesting the change. This single habit stops the large majority of payment-diversion fraud, because the fraudster doesn't control your existing contact record.

Separate the people who approve vendors from the people who pay them. A clean, minimal master vendor file with a real onboarding process (confirming the vendor is who they say they are before they're ever added) closes off the easiest way fraud gets in: a new "vendor" nobody double-checked.

Require two people on anything that moves money. Dual authorization for new vendors and for any change to existing payment instructions means a single compromised inbox or one rushed employee can't complete a fraudulent transfer alone.

Train people to recognize what AI fraud actually looks like now. The old "look for red flags" training doesn't work when there aren't obvious red flags. Staff need to know that a flawless, well-timed email is not proof of legitimacy — and they need explicit permission to slow down and verify, especially under "urgent" pressure, which is itself the biggest tell.

Use positive pay and bank-side controls where available. Many business banks offer positive pay or ACH-block services that flag payments to unrecognized accounts before they clear — a backstop for when the human checks fail.

Where Bookkeeping Fits In

Most of these controls are procedural, not accounting ones — but your books are where fraud either gets caught early or hides in plain sight. A vendor whose payment account keeps changing, an invoice that doesn't match a purchase order, a duplicate payment logged twice under slightly different vendor names — all of these are visible if your ledger is clear, current, and easy to audit. They're much harder to spot in a system where transactions are batch-imported and reconciled weeks later, or buried in a black-box categorization engine that hides the underlying detail.

Keep Your Books Auditable, Not Just Automated

The best defense against invoice fraud isn't a smarter filter — it's a financial system transparent enough that a mismatched vendor, a duplicate payment, or a shifted bank account stands out immediately instead of blending into the noise. Beancount.io offers plain-text accounting that gives you complete transparency and version-controlled history over every transaction — no black boxes, no vendor lock-in. Get started for free and see why developers and finance professionals are switching to plain-text accounting.

Share this article