← All articles

How to spot invoice fraud and fake payment confirmations

By InvoiceReminder Editorial Team · Published 6th August 2026

Invoice fraud is a serious and growing threat to UK small businesses. A single fraudulent transaction can wipe out months of profit and cause immense stress. Scammers are becoming increasingly sophisticated, using tactics like intercepting emails to change bank details or sending fake payment confirmations to trick you into stopping your credit control efforts. Understanding their methods is the first step to protecting your cash flow and your business.

This guide will walk you through the most common types of invoice and payment fraud targeting UK SMEs. We’ll explain how the scams work, the red flags to look for, and the practical steps you can take to build a more secure accounts receivable process.

What is Invoice Fraud? The Two Main Scams to Watch For

While fraud can take many forms, most invoice-related scams targeting small businesses fall into two main categories. Both exploit the trust and routine of the payment process.

  1. Invoice Interception and Redirection: This is when a criminal intercepts an invoice you’ve sent to a client. They then alter the bank details on the invoice to their own "mule" account before the client sees it. Your customer pays the invoice in good faith, but the money goes directly to the scammer, leaving you unpaid and with a very difficult situation to resolve with your client.

  2. Fake Payment Confirmation (Proof of Payment Fraud): In this scenario, a fraudulent client (or someone impersonating them) sends you a fake remittance advice or a doctored screenshot to "prove" they have paid an outstanding invoice. Their goal is to get you to stop chasing them for payment, or worse, to persuade you to release goods, ship a product, or continue providing services before the non-existent funds have cleared.

Understanding the mechanics of these two scams is critical for spotting them before they cause financial damage.

Scam 1: The Bank Details Switch (Invoice Interception)

This is one of the most damaging forms of invoice fraud because it can go undetected for weeks. By the time you realise you haven't been paid and start chasing your client, they believe they have already settled the bill.

The most common method used is Business Email Compromise (BEC). Here’s how it typically unfolds:

  1. Infiltration: A fraudster gains access to either your email account or, more often, your client's email account. They might use phishing techniques (tricking someone into revealing their password) or malware.
  2. Surveillance: Once inside, they don't act immediately. They quietly monitor the inbox, looking for patterns and keywords related to invoices, payments, and accounting.
  3. Interception: When you send a legitimate invoice as a PDF attachment, the scammer intercepts the email. They prevent it from reaching your client's main inbox, perhaps by moving it to an obscure folder.
  4. Alteration: The scammer downloads the invoice PDF. Using simple editing software, they replace your legitimate sort code and account number with the details of a mule account they control. The rest of the invoice—your logo, the amount, the due date—remains identical.
  5. Deception: The fraudster then forwards the altered invoice to your client from a very similar-looking email address, or even from the compromised account itself, often with a simple message like "Hi, here's the invoice as requested."
  6. The Wrong Payment: Your client receives what looks like a perfectly normal invoice and pays the amount due into the scammer's account.

You're left waiting for a payment that will never arrive, while your client believes their obligation is fulfilled.

How to Spot a Redirected Invoice or a Fake "Change of Details" Request

A common variation involves the scammer contacting your client directly, impersonating you, and asking them to update your payment details on file. Be alert for these red flags:

  • A Sudden "Change of Bank Details" Email: This is the biggest warning sign. Most established businesses rarely change their primary bank account. Treat any such notification with extreme suspicion.
  • A Sense of Urgency or Pressure: The email might insist the change is "for our new payment system" and must be updated "before the end of the day" to avoid issues. Scammers use pressure to make people rush and skip proper checks.
  • Slightly "Off" Email Addresses: Look closely at the sender's email address. Scammers often register domains that are visually similar to yours, like accounts@yourcompanny.co.uk (with a double 'n') or using a different domain suffix like @yourcompany-ltd.com.
  • Unprofessional Language: The email may have spelling or grammar mistakes, or use phrasing that feels slightly out of character for your usual communications.
  • Personal Bank Account Details: If the "new" bank details are for an account in an individual's name rather than your registered business name, it's a major red flag.

How to Protect Your Business from Invoice Interception

Prevention is far more effective than trying to recover stolen funds.

  1. Verbal Confirmation is Essential: This is the single most important rule. Always verbally confirm any request to change bank details with a known contact at your client's company. Use a phone number you already have on file for them, not one provided in the suspicious email.
  2. Secure Your Email with Two-Factor Authentication (2FA): 2FA adds a second layer of security to your email account, requiring a code from your phone in addition to your password. This makes it significantly harder for criminals to gain access even if they steal your password.
  3. Add a Warning to Your Invoices: Include a static line of text in the footer of every invoice you send. For example: "Security notice: Our bank details will never change without official letterheaded confirmation. Please call us on our trusted office number to verify any email requesting a change."
  4. Use Client Portals: If your accounting software (like Xero or QuickBooks) offers a secure client portal, encourage your customers to log in to view and pay their invoices there. This bypasses email entirely, removing the opportunity for interception.

Scam 2: The Fake Payment Confirmation

This scam is less about stealing money directly and more about deception and delay. A dishonest client or outright fraudster will try to convince you they have paid an invoice when they haven't.

The goal is to get you to:

  • Stop your credit control and chasing emails.
  • Release goods or start work on a new project.
  • Mark an invoice as "paid" in your system prematurely.

The primary tool for this scam is a doctored "proof of payment" document, usually a PDF remittance advice or a screenshot of a banking app.

Red Flags on a Fake Remittance Advice or Payment Screenshot

Genuine remittance documents from UK banks are clean, professional, and computer-generated. Fakes often show signs of amateur manipulation.

  • Mismatched Fonts and Alignment: Look closely at the text. Are all the fonts the same? Is the text perfectly aligned in columns? Scammers often struggle to match the exact font and spacing used by banking software, leading to subtle visual errors.
  • Pixelation or Blurring: If parts of the document, especially around the payment amount or date, look blurry, pixelated, or of a different quality, it's a sign they may have been digitally altered.
  • Incorrect or Missing Details: Check if the correct invoice number is listed as the payment reference. Scammers may forget this or use a generic reference like "Invoice Payment". The date or value might also be slightly wrong.
  • Unusual Timing: A classic tactic is to send the fake confirmation late on a Friday afternoon. The sender will claim the payment was made via Bacs and "will clear on Monday or Tuesday". This buys them several days before you realise the money hasn't arrived.

The "Payment is Processing" Stall Tactic

This is a very common delaying tactic used by both deliberate fraudsters and simply disorganised clients. They'll email you saying, "Payment has been made, it's just processing with the bank." They might even send a screenshot of their banking portal before they have clicked the final "confirm payment" button.

The rule here is simple: a payment isn't a payment until the money is cleared in your bank account.

How to Defend Against Fake Payment Confirmations

Your defence here is not about spotting fakes—it's about having a process that doesn't rely on them.

  1. Trust Your Bank Account, Not Their Email: This is the golden rule of accounts receivable. Never stop chasing an invoice, ship goods, or mark a debt as settled based solely on a remittance advice or a client's email. Log in to your business bank account and verify the funds are present and cleared.
  2. Understand UK Payment Timelines: Knowing how long payments should take helps you call their bluff.
    • Faster Payments: The most common method for online payments in the UK. It's designed to be near-instant (usually within 2 hours, often within seconds) and runs 24/7.
    • Bacs: Typically used for Direct Debits and payroll. It takes three working days to clear. A payment submitted on Monday will arrive on Wednesday.
    • CHAPS: A same-day, high-value payment system. If a payment is sent via CHAPS, it should arrive the same working day, provided it was sent before the bank's cut-off time.
  3. Maintain a Consistent Chasing Process: Your credit control process should only stop when a payment is reconciled in your accounting system. Using an automated tool can help enforce this discipline. For example, a system like InvoiceReminder works directly from the invoice status in your accounting software (Xero, Sage, QuickBooks, or FreeAgent). It will continue to send scheduled reminders until you reconcile a real payment against that invoice, meaning it can't be tricked by a fake email from a client.

A Table of Common Red Flags: At a Glance

Use this table as a quick reference for spotting suspicious activity in your accounts receivable process.

Red Flag What it Might Mean What You Should Do
An email announces "new bank details" Your email or your client's may be compromised. This is a classic interception attempt. Do not reply or use the new details. Call your client on a trusted phone number to verify the request verbally.
A remittance advice has blurry text or bad fonts The document is likely a forgery or has been digitally altered. Ignore the document. Log in to your bank account to check for cleared funds. Continue chasing if unpaid.
The sender pressures you to act urgently Scammers create a false sense of urgency to make you bypass normal security checks. Slow down. Take the time to follow your standard verification procedures, especially for payment-related changes.
The sender's email address is slightly wrong This is a strong indicator of an impersonation attempt (typosquatting). Delete the email. Do not click any links or open attachments. Block the sender.
Proof of payment is sent late on a Friday The sender is likely trying to buy time over the weekend, hoping you'll stop chasing. Acknowledge the email politely, but state that you will confirm receipt once the funds clear in your account.
A client refuses to confirm details by phone A legitimate client should have no problem verifying a significant change verbally. This is a major red flag. Do not proceed. Re-state your policy of verbal confirmation for all such changes.

What to Do If You Suspect You've Been Scammed

If the worst happens and you believe you or your client has paid a fraudulent invoice, you must act extremely quickly. Time is critical.

  1. Contact Your Bank Immediately: If you have sent money to a fraudulent account, call your bank's fraud department straight away. Under the "contingent reimbursement model" (CRM) code, you may be able to get the money back if you were not at fault, but swift action is key.
  2. Tell Your Client to Contact Their Bank: If your client has paid a scammer who was impersonating you, advise them to contact their bank's fraud team immediately. They will need the details of the fraudulent payment. They may be able to recall the payment if they act fast enough.
  3. Report it to Action Fraud: Action Fraud is the UK's national reporting centre for fraud and cybercrime. Reporting the incident helps law enforcement build a picture of scam operations and may prevent others from falling victim. You will receive a police crime reference number, which can be important for insurance or legal purposes.
  4. Secure Your Systems: Immediately change all your key passwords, starting with your email account. Enable Two-Factor Authentication (2FA) if you haven't already. Run a comprehensive malware scan on your computer.
  5. Review Your Processes: Once the immediate crisis is over, conduct a thorough review of what happened. Use the incident to strengthen your internal processes and implement the preventative measures outlined in this article to ensure it doesn't happen again.

Frequently asked questions

My client paid an invoice, but it was to a scammer who changed my bank details. Who is liable?

This is a complex legal area and not always clear-cut. Liability can depend on whose email account was compromised and whether either party was negligent. In many cases, the payer (your client) may bear the loss as it was their responsibility to ensure they paid the correct beneficiary. However, this creates a difficult commercial situation. The best approach is to focus on prevention and have a clear process for verifying bank details. This is general guidance, not legal advice.

My client insists they've paid but the money isn't in my account. What should I do?

Politely but firmly hold your ground. Explain that your policy is to mark invoices as paid only when the funds have cleared in your account. Ask them to provide the official transaction ID and the exact time and date of the payment so they can initiate a trace with their bank. Do not stop your credit control process based on their word alone.

Can I get my money back after an invoice redirection scam?

It is very difficult, and success is not guaranteed. It depends almost entirely on how quickly the fraud is reported to the banks involved. Banks will attempt to freeze and recover the funds, but if the scammer has already moved the money out of the mule account, recovery is unlikely. This is why prevention is so crucial.

Is it safe to put my bank details on my public website?

This is a trade-off. While it can be convenient for customers, it also makes it very easy for anyone—including scammers—to find and copy your details. A safer approach is to provide your bank details only on the invoices you send directly to vetted clients. Including a warning on your invoice about not changing details via email adds another layer of protection.

What is the single most important habit to prevent invoice fraud?

It's a tie between two things. For invoice interception: always verbally verify any request to change bank details using a trusted phone number. For fake payment proofs: only trust your own bank statement, never a document sent by a client. If you follow these two golden rules, you will be protected from the vast majority of invoice scams.

Automate Your Chasing, Secure Your Process

While no software can stop a determined criminal from attempting fraud, building a robust and consistent accounts receivable process is your strongest defence. A predictable system makes suspicious activities and anomalies stand out. Automating your invoice chasing ensures that reminders are sent on time, every time, based on the real payment status in your accounting software—not on a fake "proof of payment" email.

InvoiceReminder is built for UK freelancers, small businesses, and accountants who want to stop chasing invoices by hand. It connects to Xero, QuickBooks, Sage, and FreeAgent to send scheduled, escalating reminders for overdue invoices. This enforces a consistent credit control policy that doesn't get tricked by delaying tactics. The system is built by the team behind WeCovr, a UK business that has arranged over 1,000,000 insurance policies and is authorised and regulated by the Financial Conduct Authority. You can currently get started with unlimited automated email reminders at no cost.