Skip to main content

Authorized Push Payment Fraud: The Invoice Scam Your Bank Won't Reverse

Published 10 min readMike ThriftMike Thrift
Authorized Push Payment Fraud: The Invoice Scam Your Bank Won't Reverse
On this page

Imagine this: your bookkeeper pays a $48,000 invoice from a supplier you have worked with for years. The email thread is real. The invoice number matches. The only thing different is a short note saying the vendor changed banks, with new wire instructions attached. Your bookkeeper sends the money — and it lands in a scammer's account. When you call the bank, you learn the worst part: because you authorized the transfer, the bank is not required to give a dollar of it back.

That is authorized push payment fraud, or APP fraud, and it is the fastest-growing way criminals steal from businesses. Unlike credit card fraud, there is no stolen card number and no unauthorized charge to dispute. Somebody tricks you into pushing the button yourself. Deloitte estimates APP fraud losses in the United States reached $8.3 billion in 2024 and could hit $14.9 billion by 2028 — or $18.2 billion if AI-powered scams outrun society's defenses. The FBI's Internet Crime Complaint Center logged 24,768 business email compromise complaints in 2025 alone, totaling $3.05 billion in reported losses. And 79% of organizations experienced attempted or actual payments fraud in 2024, according to the Association for Financial Professionals, which ranked business email compromise the most common attack vector.

If you run a small business, this is not a problem for someone else's finance department. You are the finance department. Here is how the scam works, why the money is so hard to recover, and the controls that actually stop it.

How the scam works: the vendor-invoice playbook

Business imposter scams were the single most reported type of APP fraud in 2024, with more than 360,000 cases reported. The version aimed at small businesses usually follows the same three-act script.

Act 1: The setup — a hijacked inbox you cannot see

The attacker compromises an email account — sometimes yours, more often your vendor's — and then goes quiet. For weeks, inbox rules auto-forward every message containing words like "invoice," "payment," or "wire" to the scammer, who studies your payment rhythms: who approves what, which vendors get paid when, and what a normal invoice thread looks like. Nothing looks wrong because nothing is wrong yet. The criminals are just reading.

Act 2: The switch — new bank details on a real thread

When a real invoice is due, the scammer strikes inside the genuine email thread, either from the compromised account or from a lookalike domain (your-vendor.com versus yourvendor.com). The message is short and plausible: "We've changed banks — please use the attached instructions for this and future payments." The invoice itself is legitimate. The amount is expected. The only thing that changed is where the money goes.

This works because it arrives exactly when you expect to pay, from someone you trust, about an amount you recognize. Your normal skepticism never engages. Many victims only discover the fraud weeks later, when the real vendor calls to ask why the invoice is still unpaid.

Act 3: The AI upgrade — flawless forgeries at scale

Generative AI has removed every tell that used to give these scams away. The broken English is gone. Scammers now clone a vendor contact's voice for a "quick confirmation call," generate deepfake video for virtual verification meetings, and deploy AI agents that run dozens of personalized fraud conversations at once. Deloitte flags investment scams as the biggest driver of APP fraud growth — up fourteen-fold since 2020 to an estimated $4.6 billion in 2024 — but the same AI tooling is aimed squarely at business payments too, where a single redirected wire can be worth tens of thousands of dollars.

Why your bank probably won't make you whole

Here is the asymmetry every business owner needs to understand. When someone steals your credit card number, federal law caps your loss and the bank eats the rest. When someone tricks you into wiring money to them, you sent it. The transfer was authorized — by you, under false pretenses — and authorized transfers are brutally hard to reverse once the funds leave, especially over wires and real-time payment rails that settle in seconds.

For businesses, the protection gap is even wider than for consumers. Regulation E's error-resolution rights cover consumer accounts, not business accounts, and they were written for unauthorized transfers anyway. Business wires generally fall under state commercial law, where the question is whether the bank followed "commercially reasonable" security procedures — not whether you were fooled. If your bank followed its agreed procedures and you authenticated the payment, the loss is presumptively yours.

Other countries have started closing this gap. Since October 2024, UK banks have been required to reimburse APP fraud victims up to £85,000 per claim, with the cost split evenly between the sending and receiving institutions. The United States has no equivalent rule. A bipartisan bill, the TRAPS Act, would create a federal task force on digital payment scams, but it is early-stage legislation, not a safety net. Until the law changes, your internal controls are your only insurance policy — and unlike insurance, they are free.

The controls that actually stop it

You do not need an enterprise fraud department. Every control below is sized for a business where the owner approves payments between everything else. Implement them in order; the first two alone would have prevented most of the losses in the FBI's complaint data.

1. Verify every bank-detail change out of band — no exceptions

Make this your one non-negotiable rule: no payment instruction change is ever accepted by email alone. When any vendor — even a trusted one on a familiar thread — sends new bank details, somebody calls a known, previously saved phone number for that vendor (not a number in the email) and confirms the change verbally. Then a second person re-verifies amounts above your threshold before the wire goes out.

Write the rule down, tell your vendors about it in advance, and give your bookkeeper explicit permission to delay any payment that skipped verification. Scammers manufacture urgency ("this needs to go out today or shipment stops"); your policy should manufacture calm. A vendor with a genuine bank change will survive a 24-hour verification delay. A scammer will not survive the phone call.

2. Require two sets of eyes on every payment over a threshold

Segregation of duties sounds like corporate jargon, but at small-business scale it is simple: the person who enters a payment cannot be the only person who approves it. Pick a threshold that fits your volume — many small businesses use $1,000 or $2,500 — and require a second approval above it. If you are a company of two, the second approver is whoever did not enter the payment. Most business banking platforms support dual authorization natively; turn it on.

This single control defeats both outside scammers and the awkward inside risk nobody likes to discuss: a single employee with sole authority to create vendors, enter invoices, and release payments can steal without any hacker at all. Two sets of eyes protect you in both directions.

3. Lock down the email accounts that move money

Because these scams start with a compromised inbox, email hygiene is payment security:

  • Turn on multi-factor authentication for every mailbox that sends invoices, approves payments, or receives vendor banking details. This is the highest-leverage step on this list.
  • Audit auto-forwarding and inbox rules quarterly. Attackers hide rules that forward finance-related mail to outside addresses and mark their own messages as read. Review the rules list on every finance mailbox; delete anything you did not create.
  • Register lookalike domains of your own company name so scammers cannot use them against your customers and vendors, and train your team to hover over sender addresses. Display names lie; domains do not.
  • Adopt an internal code word or verification phrase for payment approvals requested by phone or video. A cloned voice can say anything except a secret it was never told.

4. Turn on the bank controls you are already paying for

Your business bank account likely includes fraud tools that sit disabled by default. Call your banker and ask for:

  • Positive pay for checks, and its ACH equivalent — the bank only honors payments matching a list you pre-approve.
  • ACH debit blocks and filters, so only authorized originators can pull from your operating account.
  • Wire callbacks and dual control, where the bank phones an authorized signer before releasing wires above a set amount.

These services sometimes carry a small fee. Compare it against a single average BEC loss — well over $100,000 per complaint in the FBI's 2025 data — and the math answers itself.

5. Slow down real-time payments on purpose

Instant payment rails are wonderful for cash flow and terrible for fraud recovery: once funds settle in seconds, there is nothing to claw back. Build a deliberate pause into your process for first-time payees and changed instructions — even same-day verification by phone beats instant execution. Speed is a feature of the rail, not a requirement of your business. Nothing legitimate breaks because a new vendor's first payment went out on Thursday instead of Tuesday.

6. Know your first-24-hours drill before you need it

Recovery odds collapse after the first day, so rehearse this sequence now:

  1. Call your bank's fraud department immediately — not the branch, the fraud team — and request a wire recall or reversal attempt.
  2. File a complaint with the FBI's IC3 at ic3.gov and contact your local FBI field office; time stamps matter for fund tracing.
  3. Preserve everything: full email headers, the original message files, invoices, and wire confirmations. Do not delete the scammer's emails.
  4. Alert the impersonated vendor through a trusted channel so they can warn their other customers and secure their own systems.

Post this checklist where whoever handles payments can find it in a panic. You will not be thinking clearly; the checklist will be.

Good bookkeeping is a fraud control

Notice how many of these scams survive on sloppy back-office habits: vendor banking details updated from an email with no approval trail, invoices paid without matching to a purchase record, bank reconciliations done quarterly instead of weekly so a missing payment hides for months. Tight books close those gaps.

Keep a controlled vendor master file — every new vendor and every banking change logged with who verified it, how, and when. Match invoices to supporting records before payment rather than paying from the email alone. Reconcile your operating accounts at least weekly so an unpaid "paid" invoice surfaces in days, not at quarter-end — reviewing your cash position visually makes anomalies harder to miss. And because every payment decision should leave an audit trail, keep your ledger somewhere transparent and version-controlled, where a changed payee or an unusual amount stands out instead of blending into a black box.

Keep Your Payments — and Your Books — Fraud-Resistant

APP fraud works because it hides inside legitimate processes: a real invoice, a trusted vendor, a payment you meant to make. The defense is making those processes visible and verifiable — dual approvals, verified vendor records, and books you can actually audit. Beancount.io provides plain-text accounting that gives you complete transparency and control over your financial data, so unusual payments stand out and every change leaves a trail. Get started for free and see why developers and finance professionals are switching to plain-text accounting.

Share this article

Source: https://beancount.io/blog/2026/09/19/authorized-push-payment-fraud-invoice-vendor-scams-small-business-guide

Published: September 19, 2026