Docento.app
Business meeting around a table
All Posts

Invoice Fraud and Business Email Compromise: Spotting Altered PDF Invoices

By The Docento.app TeamPublished 3 min read
Try Docento's free PDF editor — No sign-up, 100% private — sign, annotate, and stamp PDFs in your browser.Open the editor

Business email compromise (BEC) is consistently one of the most expensive forms of cybercrime reported to the FBI, with losses in the billions of dollars each year. One of its most common forms is simple: a supplier's real invoice, sent from a real-looking address, with one change: the bank account. AI tools have made the emails more convincing and the PDF edits invisible.

How the scam works

  1. Attackers gain access to a supplier's mailbox (or yours), often through phishing, and read invoice threads for weeks.
  2. When a real invoice is due, they send it themselves, from the compromised account or a lookalike domain, with altered bank details.
  3. The email often says the company "changed banks" or is "under audit", and asks for quick payment.
  4. Money goes to a mule account and is moved on within hours.

The PDF itself can be the supplier's genuine invoice, edited in one place. Nothing about its appearance gives it away.

Warning signs in the email

  • A change of bank details, by email, especially near a payment date.
  • A slightly different sender address: accounts@supp1ier.com, an extra hyphen, a different top-level domain.
  • Reply-to address that differs from the sender.
  • Urgency or secrecy: "please process today", "do not call, our phones are down".
  • Unusual timing: sent late on a Friday or before a holiday.

Warning signs in the PDF

  • Fonts or alignment that differ slightly around the bank details.
  • Document properties that show a different producer or a modification date that does not match. See how to detect tampered PDFs.
  • A hybrid e-invoice whose embedded XML has different bank details from the visible page. If you receive Factur-X or ZUGFeRD invoices, your accounting software reads the XML; check both.

Do not rely on these. A careful forger leaves none.

The control that actually works

Verify every bank detail change by phone, using a number you already have, not one from the email or invoice. Call the supplier contact you know. Ask them to confirm the new account number.

That single rule defeats most BEC attempts. Make it a written policy that no one, including senior managers, can override by email.

Supporting controls

  • Dual approval for new or changed payee details.
  • A cooling-off period for payments to newly changed accounts.
  • Confirmation of payee or account name checking, where your bank offers it.
  • E-invoicing through approved networks such as Peppol, where available, which reduces invoices arriving by plain email. See Belgium's Peppol rule.
  • Phishing-resistant MFA on finance mailboxes, so accounts are harder to take over.

If you paid a fraudulent invoice

  1. Call your bank immediately. The first hours matter for recalling funds.
  2. Report to the police and, in the US, to the FBI's IC3.
  3. Tell the real supplier, whose mailbox may be compromised.
  4. Preserve evidence: the emails with headers and the PDF.

Takeaway

The PDF will look perfect. The phone call is what catches the fraud. Treat any change of bank details as suspicious until verified through a channel the attacker does not control. For related scams, see QR code phishing in PDFs and AI-generated fake receipts.

Try Docento's free PDF editor

No sign-up, 100% private — sign, annotate, and stamp PDFs in your browser.

Open the editor

Related Posts