Key Takeaways
- The FBI recorded $2.77 billion in reported business email compromise losses during 2024
- The FBI's 2024 Internet Crime Report recorded 21,442 business email compromise complaints
- AFP found that 79% of surveyed organizations experienced attempted or actual payment fraud in 2024
- Checks remained the payment method most exposed to fraud in AFP's 2025 survey
- Independent callback verification is a central control when payment instructions change
Small business invoice fraud statistics describe a broad set of payment crimes. A criminal may impersonate a supplier, change bank details on a real invoice, compromise an employee's mailbox, submit a fabricated bill, or alter a check. Public data rarely separates small firms cleanly from larger organizations, so this review distinguishes national crime reports from business surveys.
Invoice fraud statistics at a glance
| Measure | Finding | Scope |
|---|---|---|
| Business email compromise complaints | 21,442 | FBI reports for 2024 |
| Reported business email compromise losses | $2.77 billion | FBI reports for 2024 |
| Organizations encountering payment fraud | 79% | AFP survey covering 2024 |
| Respondents reporting check fraud | 63% | AFP survey covering 2024 |
| Most common contact channel for impersonation scams | FTC business guidance |
Sources: FBI Internet Crime Report 2024, Association for Financial Professionals 2025 Payments Fraud and Control Survey, and Federal Trade Commission business guidance.
Business email compromise remains a costly payment threat
The FBI defines business email compromise as a sophisticated scam that targets businesses and people who make legitimate wire-transfer payments. Its 2024 Internet Crime Report recorded 21,442 complaints and $2.77 billion in reported losses. These figures include organizations of different sizes and only incidents reported to the FBI. They are not a small-business prevalence rate.
Invoice diversion often begins with ordinary operational information. A criminal learns who approves bills, which supplier is expected to invoice, or when a property closing will occur. The criminal then sends payment instructions that appear to fit the normal process. A familiar sender name is not sufficient evidence because the mailbox or a similar-looking domain may be under the attacker's control.
The FBI advises victims to contact the sending financial institution immediately and then report the event to the Internet Crime Complaint Center. Speed matters because a bank may be able to recall or freeze funds before they move through additional accounts.
Payment fraud is wider than fake invoices
The Association for Financial Professionals reported that 79% of surveyed organizations experienced attempted or actual payment fraud in 2024. Checks were the most frequently affected method, with 63% of respondents reporting check fraud activity. The survey is organization-level evidence, not a random sample of all U.S. small businesses, but it shows why an invoice-control program must cover more than electronic transfers.
Each payment method has a different exposure:
- A check can be stolen, altered, counterfeited, or deposited more than once.
- An ACH instruction can redirect a recurring vendor payment.
- A wire can move money quickly and may be difficult to recover.
- A card can be charged with stolen credentials or used outside policy.
- A platform account can be taken over even when the underlying invoice is genuine.
The useful question is not whether one method is perfectly safe. It is whether the business uses controls that match the method, dollar amount, supplier history, and speed of settlement.
Why small businesses are exposed
Small organizations often combine duties because there are not enough employees to separate purchasing, invoice entry, approval, and payment. Owners may approve bills from a phone while traveling. Supplier records may live in email, spreadsheets, bookkeeping software, and a bank portal at the same time. Those conditions do not prove fraud, but they create opportunities for an instruction change to bypass review.
Common warning signs include:
- a request to replace established bank details;
- an urgent demand to avoid the normal approval path;
- a reply-to address that differs from the visible sender;
- an invoice number or purchase description that does not match prior records;
- a new beneficiary in a familiar supplier's name; and
- repeated small invoices just below an approval threshold.
Controls that reduce invoice-payment risk
The Cybersecurity and Infrastructure Security Agency recommends phishing-resistant multifactor authentication and user training as part of broader email security. Email controls help, but accounts payable also needs process controls.
Use an independently sourced phone number to verify any change in bank details. Do not use the number contained in the change request. Require a second person to approve sensitive vendor-master changes or high-value payments. Separate the ability to create a supplier from the ability to release payment wherever staffing permits.
A practical control set includes:
- Match the invoice to an approved order, contract, or documented service owner.
- Check supplier name, invoice number, amount, tax details, and destination account.
- Route exceptions and first-time suppliers for additional approval.
- Verify bank changes through an independent callback.
- Review new beneficiaries and unusual payment timing before release.
- Reconcile the bank promptly and investigate unmatched transactions.
- Preserve messages, headers, invoices, call records, and approval logs after an incident.
A small-business invoice fraud scorecard
Track attempted fraud as well as successful loss. A blocked instruction change reveals exposure before money leaves the account.
| Metric | What it shows |
|---|---|
| Vendor-detail changes | Volume of high-risk master-data events |
| Changes independently verified | Whether callback controls are followed |
| Duplicate invoices blocked | Effectiveness of invoice matching |
| New payees added | Expansion of the payment surface |
| Exceptions approved | Frequency of process bypass |
| Fraud attempts and losses | Incident trend and financial impact |
| Recovery amount | Effectiveness of rapid response |
An accounts payable virtual assistant can support invoice intake, matching, documentation, and exception queues. The business should retain payment authority, vendor approval, and control design. Outsourcing administration does not transfer responsibility for fraud decisions.
Frequently asked questions
How common is invoice fraud among small businesses?
No single authoritative national statistic isolates invoice fraud across all small businesses. The FBI reports business email compromise complaints and losses, while AFP surveys organizations about payment fraud. Use those as risk indicators, not as an SMB-specific incidence rate.
What should a business do after sending money to a fraudster?
Contact the financial institution immediately, ask whether the payment can be recalled or frozen, preserve evidence, and report the incident to the FBI's Internet Crime Complaint Center and appropriate local authorities. Do not wait for an internal investigation to finish before contacting the bank.
What is the most important preventive control?
Independently verify changes to payment instructions using trusted contact details. Multifactor authentication, separation of duties, invoice matching, and bank reconciliation add important layers.
Sources and methodology
- FBI, Internet Crime Report 2024. Complaint and loss data for business email compromise.
- FBI, Business Email Compromise. Definition and response guidance.
- Association for Financial Professionals, 2025 Payments Fraud and Control Survey. Organization survey findings for 2024.
- CISA, Phishing Guidance: Stopping the Attack Cycle at Phase One. Email-security guidance.
- Federal Trade Commission, Scams and Your Small Business. Small-business scam prevention and response.
- Federal Reserve, FedPayments Improvement: Business Email Compromise. Payment-process risk guidance.
This article uses sources available on September 22, 2026. FBI figures reflect reported complaints, not every incident. AFP findings reflect its respondent population and are not presented as a representative small-business prevalence estimate.
Tags
Ready to put this into practice?
Book a free 15-min match call
Tell us what role you're filling. We'll match you with a pre-vetted virtual assistant - or tell you honestly if we're not the right fit.
Book a free call →