Research/Startup & SMB Operations

Small Business Invoice Fraud Statistics 2026: Losses, Payment Risks, and Controls

9 min read6 sources citedVerified 2026-09-22

$2.77 billion in reported 2024 business email compromise losses

21,442 business email compromise complaints in 2024

79% of surveyed organizations faced attempted or actual payment fraud

63% of payment-fraud respondents reported check fraud activity

Key Takeaways

  • The FBI recorded $2.77 billion in reported business email compromise losses during 2024
  • The FBI's 2024 Internet Crime Report recorded 21,442 business email compromise complaints
  • AFP found that 79% of surveyed organizations experienced attempted or actual payment fraud in 2024
  • Checks remained the payment method most exposed to fraud in AFP's 2025 survey
  • Independent callback verification is a central control when payment instructions change

Small business invoice fraud statistics describe a broad set of payment crimes. A criminal may impersonate a supplier, change bank details on a real invoice, compromise an employee's mailbox, submit a fabricated bill, or alter a check. Public data rarely separates small firms cleanly from larger organizations, so this review distinguishes national crime reports from business surveys.

Invoice fraud statistics at a glance

Measure Finding Scope
Business email compromise complaints 21,442 FBI reports for 2024
Reported business email compromise losses $2.77 billion FBI reports for 2024
Organizations encountering payment fraud 79% AFP survey covering 2024
Respondents reporting check fraud 63% AFP survey covering 2024
Most common contact channel for impersonation scams Email FTC business guidance

Sources: FBI Internet Crime Report 2024, Association for Financial Professionals 2025 Payments Fraud and Control Survey, and Federal Trade Commission business guidance.

Business email compromise remains a costly payment threat

The FBI defines business email compromise as a sophisticated scam that targets businesses and people who make legitimate wire-transfer payments. Its 2024 Internet Crime Report recorded 21,442 complaints and $2.77 billion in reported losses. These figures include organizations of different sizes and only incidents reported to the FBI. They are not a small-business prevalence rate.

Invoice diversion often begins with ordinary operational information. A criminal learns who approves bills, which supplier is expected to invoice, or when a property closing will occur. The criminal then sends payment instructions that appear to fit the normal process. A familiar sender name is not sufficient evidence because the mailbox or a similar-looking domain may be under the attacker's control.

The FBI advises victims to contact the sending financial institution immediately and then report the event to the Internet Crime Complaint Center. Speed matters because a bank may be able to recall or freeze funds before they move through additional accounts.

Payment fraud is wider than fake invoices

The Association for Financial Professionals reported that 79% of surveyed organizations experienced attempted or actual payment fraud in 2024. Checks were the most frequently affected method, with 63% of respondents reporting check fraud activity. The survey is organization-level evidence, not a random sample of all U.S. small businesses, but it shows why an invoice-control program must cover more than electronic transfers.

Each payment method has a different exposure:

  • A check can be stolen, altered, counterfeited, or deposited more than once.
  • An ACH instruction can redirect a recurring vendor payment.
  • A wire can move money quickly and may be difficult to recover.
  • A card can be charged with stolen credentials or used outside policy.
  • A platform account can be taken over even when the underlying invoice is genuine.

The useful question is not whether one method is perfectly safe. It is whether the business uses controls that match the method, dollar amount, supplier history, and speed of settlement.

Why small businesses are exposed

Small organizations often combine duties because there are not enough employees to separate purchasing, invoice entry, approval, and payment. Owners may approve bills from a phone while traveling. Supplier records may live in email, spreadsheets, bookkeeping software, and a bank portal at the same time. Those conditions do not prove fraud, but they create opportunities for an instruction change to bypass review.

Common warning signs include:

  • a request to replace established bank details;
  • an urgent demand to avoid the normal approval path;
  • a reply-to address that differs from the visible sender;
  • an invoice number or purchase description that does not match prior records;
  • a new beneficiary in a familiar supplier's name; and
  • repeated small invoices just below an approval threshold.

Controls that reduce invoice-payment risk

The Cybersecurity and Infrastructure Security Agency recommends phishing-resistant multifactor authentication and user training as part of broader email security. Email controls help, but accounts payable also needs process controls.

Use an independently sourced phone number to verify any change in bank details. Do not use the number contained in the change request. Require a second person to approve sensitive vendor-master changes or high-value payments. Separate the ability to create a supplier from the ability to release payment wherever staffing permits.

A practical control set includes:

  1. Match the invoice to an approved order, contract, or documented service owner.
  2. Check supplier name, invoice number, amount, tax details, and destination account.
  3. Route exceptions and first-time suppliers for additional approval.
  4. Verify bank changes through an independent callback.
  5. Review new beneficiaries and unusual payment timing before release.
  6. Reconcile the bank promptly and investigate unmatched transactions.
  7. Preserve messages, headers, invoices, call records, and approval logs after an incident.

A small-business invoice fraud scorecard

Track attempted fraud as well as successful loss. A blocked instruction change reveals exposure before money leaves the account.

Metric What it shows
Vendor-detail changes Volume of high-risk master-data events
Changes independently verified Whether callback controls are followed
Duplicate invoices blocked Effectiveness of invoice matching
New payees added Expansion of the payment surface
Exceptions approved Frequency of process bypass
Fraud attempts and losses Incident trend and financial impact
Recovery amount Effectiveness of rapid response

An accounts payable virtual assistant can support invoice intake, matching, documentation, and exception queues. The business should retain payment authority, vendor approval, and control design. Outsourcing administration does not transfer responsibility for fraud decisions.

Frequently asked questions

How common is invoice fraud among small businesses?

No single authoritative national statistic isolates invoice fraud across all small businesses. The FBI reports business email compromise complaints and losses, while AFP surveys organizations about payment fraud. Use those as risk indicators, not as an SMB-specific incidence rate.

What should a business do after sending money to a fraudster?

Contact the financial institution immediately, ask whether the payment can be recalled or frozen, preserve evidence, and report the incident to the FBI's Internet Crime Complaint Center and appropriate local authorities. Do not wait for an internal investigation to finish before contacting the bank.

What is the most important preventive control?

Independently verify changes to payment instructions using trusted contact details. Multifactor authentication, separation of duties, invoice matching, and bank reconciliation add important layers.

Sources and methodology

  1. FBI, Internet Crime Report 2024. Complaint and loss data for business email compromise.
  2. FBI, Business Email Compromise. Definition and response guidance.
  3. Association for Financial Professionals, 2025 Payments Fraud and Control Survey. Organization survey findings for 2024.
  4. CISA, Phishing Guidance: Stopping the Attack Cycle at Phase One. Email-security guidance.
  5. Federal Trade Commission, Scams and Your Small Business. Small-business scam prevention and response.
  6. Federal Reserve, FedPayments Improvement: Business Email Compromise. Payment-process risk guidance.

This article uses sources available on September 22, 2026. FBI figures reflect reported complaints, not every incident. AFP findings reflect its respondent population and are not presented as a representative small-business prevalence estimate.

Tags

small business invoice fraud statisticsinvoice fraudbusiness email compromisepayment controlsaccounts payable fraud

Ready to put this into practice?

Book a free 15-min match call

Tell us what role you're filling. We'll match you with a pre-vetted virtual assistant - or tell you honestly if we're not the right fit.

Book a free call →

Related Research

Need Help Applying This to Your Business?

Book a free 15-minute match call. We'll recommend the right virtual assistant for your specific situation - no commitment required.

Book a 15-Min Match Call