CEO Impersonation, Fake Invoices and ACH Fraud: What Small Businesses Need to Check
A 10-minute payment verification system for small businesses — built for the moment when the invoice looks right, the email thread looks right, the boss appears to have approved it, and the bank account is still wrong.
The scammer does not need your password anymore. Sometimes your trust is enough.
The dangerous invoice scam is often an authorized-payment fraud: the employee really does approve and send the money. The deception happens before the ACH or wire is originated.
| What people used to inspect | Why that is weaker now | What to verify instead |
|---|---|---|
| Grammar and spelling | AI can produce polished business language instantly. | Whether the vendor and payment destination match independently verified records. |
| Invoice design | Logos, formatting, line items and company details are easy to recreate. | PO, contract, prior invoice history and the actual beneficiary account. |
| Long email thread | A complete-looking conversation can be fabricated inside one message. | The actual mailbox history and a separate callback to a known contact. |
| CEO or CFO approval | Display names, signatures, domains and even voices can be impersonated. | Approval through your established internal process, not the request itself. |
| Caller ID or familiar voice | Caller ID can be spoofed and AI voice cloning is increasingly accessible. | Hang up and initiate the call yourself using a previously known number. |
Microsoft watched the whole fraud package arrive at once
In September 2026, Microsoft Security Research described an August campaign that shows how far invoice impersonation has moved. The attackers sent more than one million financial-fraud emails through third-party email infrastructure. Most targeted U.S. users.
The message did not rely on a lone fake invoice. It stacked several trust signals together: an impersonated company executive, vendor branding, a fabricated invoice, a supposed forwarded conversation between executives and instructions for an ACH payment approaching $50,000.
Why it looked credible
- Executive name and signature appeared in the request.
- The invoice contained normal billing fields and itemization.
- The victim company was personalized in the billing section.
- A fake prior conversation supplied a plausible backstory.
- A lookalike vendor domain supported the impersonation.
Where the seams still showed
- The sender and reply-to details did not line up cleanly.
- The purported forwarded thread lacked normal email-header structure.
- The narrative discouraged normal copying and verification.
- The lookalike domain had been registered shortly before the campaign.
- Most importantly: the payment destination had not been independently verified.
BEC did not fade away when everyone learned about phishing
The FBI’s Internet Crime Complaint Center recorded 24,768 Business Email Compromise complaints in 2025 with $3.0466 billion in adjusted losses. In 2024, IC3 recorded 21,442 complaints and approximately $2.77 billion in losses.
| FBI IC3 measure | 2024 | 2025 | Change |
|---|---|---|---|
| BEC complaints | 21,442 | 24,768 | +15.5% |
| BEC adjusted losses | $2.770B | $3.047B | +10.0% |
| AI-related complaints | Not separately captured | 22,364 | New IC3 descriptor |
| AI-related adjusted losses | Not separately captured | $893.3M | New IC3 descriptor |
IC3 statistics reflect complaints reported to the FBI and should not be treated as a complete measurement of all fraud occurring in the economy. “AI related” is an IC3 descriptor and can overlap with underlying crime categories.
Bank-detail changes deserve their own security procedure
A practical small-business policy does not have to be complicated. It needs a few hard stops that employees are allowed to enforce even when the request supposedly comes from the owner.
Automatic verification triggers
- Any vendor bank-account or routing-number change.
- Any first payment to a new vendor.
- Any change from check to ACH, wire or instant payment.
- An invoice that bypasses the normal purchasing process.
- A request from an executive that arrives outside the usual workflow.
- An unusual rush, secrecy request or instruction not to contact someone.
Acceptable independent verification
- Call a vendor number already stored in your verified vendor master.
- Use a number from a prior legitimate contract or independently located official source.
- Confirm the change with a known vendor contact through a separately initiated channel.
- Use bank-account ownership or payment-instruction validation where available.
- Require a second employee to approve sensitive changes before release.
The 10-minute payment verification
This is deliberately short. If fraud prevention takes half an hour for every invoice, people will work around it. Reserve the full check for new vendors, changed bank details, unusual payments and anything that simply feels outside the normal pattern.
Seven things that can look real and still prove almost nothing
| Trust signal | What it actually proves |
|---|---|
| A beautiful PDF invoice | Someone can make a beautiful PDF. |
| A familiar company logo | The sender knows what the company’s logo looks like. |
| A CEO signature | The sender knows the CEO’s name and title. |
| A long forwarded thread | Text can be inserted beneath an email. |
| Perfect grammar | The writer — human or automated — can produce polished English. |
| A familiar voice | Voice alone is no longer reliable identity proof for an unexpected financial request. |
| “The bank details changed” | Nothing until the change is independently verified. |
ACH fraud monitoring is getting more formal
Nacha’s 2026 risk-management changes expanded fraud-monitoring expectations across the ACH ecosystem. Phase-one requirements became effective in March, and phase two extended the requirements to the remaining non-consumer ACH originators and receiving financial institutions in June.
The rules specifically contemplate payments induced under “False Pretenses” — including Business Email Compromise, vendor impersonation, payroll impersonation and other payee-impersonation schemes.
The first few calls matter more than the post-mortem
Do not spend the first hour holding an internal meeting to decide whether you are certain. If there is a credible possibility that an ACH or wire was fraudulently redirected, start the recovery process while the facts are still being gathered.
Immediately
- Contact your financial institution and report the fraudulent or misdirected payment.
- Ask about recall, recovery, hold or receiving-bank notification options.
- Preserve the invoice, original email, headers, payment record and related messages.
- File a report promptly with the FBI’s Internet Crime Complaint Center where appropriate.
Then investigate the access
- Determine whether an employee or vendor mailbox was compromised.
- Review suspicious forwarding and inbox rules.
- Reset affected credentials and revoke active sessions.
- Enforce multifactor authentication.
- Search for other vendor or payroll changes made during the same period.
The one-paragraph version for a small company
Run the 10-Minute Invoice Test
Check what applies. The tool does not declare an invoice legitimate; it tells you when the payment deserves a hold and independent verification.
1. Mark the risk signals
2. Mark what you independently verified
Start with the facts
Mark the applicable risk signals and the verification steps you completed.
This screening tool is a practical internal-control aid, not a guarantee that a payment is legitimate. For suspected fraud, contact your financial institution promptly and follow its recovery procedures.
