Invoice fraud is the quietest crime your practice will ever take part in. There is no ransom note, no encrypted server, no help desk queue. A client pays an invoice they were expecting, for an amount they agreed, against a reference they recognise, into an account that is not yours. Nobody notices for five weeks, and by then the money has been layered through three mule accounts and is gone.
That is the shape of invoice fraud in an accountancy practice, and it is why it barely registers on the usual security dashboards. The controls that stop ransomware do almost nothing here. The attack does not break anything. It borrows your credibility, waits for a payment that was going to happen anyway, and changes one field.
This guide is the accountancy companion to our business email compromise guide for managing agents, and it goes deeper on the invoice fraud mechanics a practice specifically exposes: client money movements, payroll bureau runs, HMRC repayments, disbursements and the trusted position you occupy in every client’s supplier list. For the generic response process, our incident playbook and the Microsoft 365 response plan cover it.
Everything below assumes you already run some form of IT support for accountancy firms, that your tenant broadly follows our Microsoft 365 security checklist, and that certification such as Cyber Essentials is in place or on the plan. Good cybersecurity hygiene is the floor. Invoice fraud is what walks in over the top of it.
Table of contents
- What Invoice Fraud Is, and Why Accountancy Firms Sit at the Centre of It
- The UK Numbers: What Invoice Fraud Costs in 2026
- The Anatomy of Invoice Fraud: Seven Stages From Phish to Payment
- The Four Invoice Fraud Patterns Specific to an Accountancy Practice
- The Mailbox Rules That Hide Invoice Fraud From the Account Owner
- Why Your Practice Sits Outside the Invoice Fraud Reimbursement Safety Net
- The Legal and Regulatory Exposure Invoice Fraud Creates
- AI-Generated Invoices: The 2026 Escalation of Invoice Fraud
- The Microsoft 365 Controls That Actually Stop Invoice Fraud
- Payment Process Controls: The Callback Discipline That Actually Works
- Detecting Invoice Fraud While It Is Still Happening
- Invoice Fraud Incident Response: The First 24 Hours
- Client-Side Controls: What to Tell the People Who Actually Pay
- HMRC, Companies House and Agent Account Hardening
- E-Invoicing From April 2029: What Changes and What Does Not
- What Invoice Fraud Prevention Costs, and the 90-Day Plan
- Frequently Asked Questions About Invoice Fraud in Accountancy Firms
- References
What Invoice Fraud Is, and Why Accountancy Firms Sit at the Centre of It
Invoice fraud is a payment redirection crime. The victim intends to pay a real invoice to a real payee, and a criminal intervenes to convince them to send it somewhere else instead. UK Finance classifies it as an authorised push payment scam, because the victim genuinely authorises the transfer.
The definition decides who absorbs the loss
That single word — authorised — separates invoice fraud from card fraud or account takeover. The bank did exactly what it was told. The instruction was legitimately issued from a legitimate account by a person entitled to issue it. Recovery therefore depends on reimbursement rules rather than on a chargeback, and as later sections show, most accountancy practices fall outside those rules altogether.
Why a practice is a disproportionately valuable target
An accountancy firm is not a rich target. It is a well-connected one. A single compromised mailbox in a mid-sized practice gives an attacker sight of dozens of client companies, their bank details, their payment cycles, their VAT quarters and their payroll dates, along with a writing style everyone downstream already trusts.
Attackers are rarely stealing from you directly. They are using you as the delivery vehicle for invoice fraud against your clients, and the client will remember whose email address it came from.
The trust asymmetry is the entire mechanism
When a supplier emails a client to say the bank details have changed, the client hesitates. When their accountant emails to say the same thing, they do not. That asymmetry is the economics of invoice fraud in professional services. You have spent years becoming the person whose payment instructions are not questioned, and that is precisely the asset being monetised.
Nothing is broken in the way people expect
There is rarely malware. In most invoice fraud cases the attacker holds valid credentials or a valid session token, signs in through the front door, reads mail for days or weeks, and sends one message. Endpoint protection sees a legitimate user. The mail gateway sees an internal sender. That is why invoice fraud survives security stacks that comfortably stop far noisier attacks.
Where it sits among the other email fraud families
Invoice fraud is one branch of business email compromise, and the branches need different controls. Grouping them under one heading is how practices end up buying a mail filter and believing the problem is solved.
| Fraud family | Who is impersonated | What the attacker asks for | Control that actually works |
|---|---|---|---|
| Invoice fraud (invoice and mandate) | A real supplier, or your practice | Payment of a genuine invoice to a changed account | Out-of-band callback on every bank detail change |
| CEO fraud | A partner or finance director | An urgent, confidential, one-off transfer | Dual authorisation with no urgency override |
| Payroll diversion | An employee of your client | A change of salary destination account | Change requests only through the HR system, never email |
| Mandate fraud | A regular payee on standing instruction | Amendment of a direct debit or standing order | Periodic re-verification of the standing payee list |
| Account takeover | Nobody — the real account is used | Direct access to banking or accounting systems | Phishing-resistant MFA and conditional access |
The UK Numbers: What Invoice Fraud Costs in 2026
The UK Finance Annual Fraud Report 2026, published in June 2026 and covering calendar year 2025, is the authoritative national dataset. It paints an unusually clear picture, and the headline is genuinely good news wrapped around a hard problem.
The national totals
Criminals stole £1.28 billion through payment fraud in 2025, a 4% increase, across more than 4 million confirmed cases, an 11% rise. Of those, 3.81 million were unauthorised fraud cases. Authorised push payment fraud accounted for £576.4 million, up 19%, across 248,070 cases, up 7%.
Investment fraud drove much of that growth at £221.5 million, a 40% year-on-year increase. Purchase scams made up 71% of all APP cases but only £118.1 million of value. Romance fraud reached £39.2 million, up 23%.
Invoice and mandate scams are falling, and that is the trap
Invoice and mandate scams, the category invoice fraud sits in, caused £41.3 million of losses across 2,305 cases in 2025. Both figures are the lowest ever recorded: value down 4%, cases down 2%. In 2020 there were 4,721 cases, so volume has fallen by 2,416 cases, a drop of just over 51%.
The whole malicious redirection family — invoice and mandate, CEO fraud and impersonation — now accounts for just under a quarter of APP losses, down from more than half in 2020, with case volumes at 11% against 30% over the same period.
Why falling numbers should not reassure a practice
Divide £41.3 million by 2,305 cases and the average invoice fraud loss is £17,918. That is not a rounding error in a small firm. It is a fee earner’s quarterly billing, or a client’s entire monthly payroll run. Invoice fraud has become rarer while staying expensive, which is exactly the profile of a risk that gets deprioritised until the day it lands on your desk.
The global picture confirms the direction
The FBI’s Internet Crime Complaint Center recorded 24,768 business email compromise complaints in 2025 with $3.05 billion in reported losses, up from 21,442 complaints and $2.77 billion in 2024. Complaints rose roughly 16% and losses about 10%. Total reported cyber-enabled crime losses reached $20.877 billion, a 26% increase.
Cumulatively, this class of attack has caused more than $55.5 billion in losses worldwide over the past decade. The average loss per incident now stands at $137,000, up from $74,723 in 2019, an 83% rise. Cases have been reported in all 50 US states and 186 countries, with more than 140 countries receiving fraudulent transfers.
Real losses at real firms
The scale is not theoretical. In April 2026 a UK energy company lost £700,000 to a single redirected supplier payment after criminals altered the bank details on an otherwise genuine invoice. In 2024 an Australian construction firm paid an invoice worth AU$900,000, roughly £480,000, after a legitimate supplier email account was compromised and the account details changed.
The Solicitors Regulation Authority has estimated that email modification fraud costs the legal profession around £10 million a year, with one property buyer defrauded of £640,000 on a single completion. Accountancy occupies exactly the same trust position as conveyancing, and attracts exactly the same invoice fraud attention.
The Anatomy of Invoice Fraud: Seven Stages From Phish to Payment
Every invoice fraud case a practice will ever see follows the same seven stages. Knowing the sequence matters because six of the stages are silent and only the seventh is expensive, so the whole defensive game is about detecting stages two through six.
Stage one: harvesting the credential
The entry point is almost always a credential. A partner clicks a shared-document lure, a manager approves an unexpected authenticator prompt, or an administrator reuses a password that appeared in an unrelated breach. Modern phishing kits proxy the real Microsoft sign-in page in real time, so the victim sees the genuine branding, the genuine domain in the address bar of a lookalike, and a genuine successful login.
Stage two: capturing the session
This is the stage most practices misunderstand. Analysis of Microsoft’s 2025 Digital Defense Report indicates around 80% of breaches that bypass multi-factor authentication involve session token theft rather than password guessing. The attacker does not need the password again. They replay a stolen token and the tenant treats them as an already-authenticated user.
In May 2026 the FBI issued a public service announcement about the Kali365 phishing-as-a-service kit, first observed in April 2026, built specifically to hijack Microsoft 365 session tokens. Kits like it are why “we have MFA” is no longer a complete answer to invoice fraud.
Stage three: quiet reconnaissance
Nothing happens for days. The attacker reads. They learn which clients pay on which dates, which partner signs off disbursements, how your firm words a remittance advice, whether you say “Kind regards” or “Best wishes”, and which supplier relationships are large enough to be worth hijacking.
Reconnaissance is where invoice fraud earns its success rate. By the time a message is sent, it is written in your house style, references a real engagement, and arrives on a date that makes sense.
Stage four: establishing persistence and concealment
The attacker creates mailbox rules so the victim never sees the replies. They may register an additional authenticator method, consent an OAuth application, or add a forwarding address. Persistence means the account stays useful even if the password is changed in the normal quarterly cycle.
Stage five: the pivot
Now the attacker chooses a target. Sometimes they send from your mailbox to your client. Sometimes they register a lookalike domain and send as your firm from outside. Sometimes they simply wait for a genuine invoice thread and reply in it, which is the hardest variant to detect because the thread history is real.
Stage six: the instruction
One email. New bank details, a plausible reason, and a light touch of urgency that never quite crosses into alarm. “We have moved to a new banking provider ahead of year end — please use the details on the attached updated remittance advice for this and future invoices.”
Stage seven: the payment and the silence
The client pays. The attacker’s mailbox rules suppress the confirmation. Funds move through mule accounts within hours. Detection typically arrives weeks later when the real supplier chases an unpaid invoice, or when a bank reconciliation refuses to balance. Every hour of that silence reduces the recovery odds.
| Stage | Typical duration | Visible to the user? | Best detection source |
|---|---|---|---|
| 1. Credential harvest | Minutes | Briefly, then no | Sign-in logs, impossible travel alerts |
| 2. Session capture | Seconds | No | Unfamiliar sign-in properties, token anomalies |
| 3. Reconnaissance | 3 to 30 days | No | Unusual mailbox search and read volumes |
| 4. Persistence | Minutes | No | New-InboxRule audit events, OAuth consent grants |
| 5. Pivot | Hours | No | Lookalike domain registration monitoring |
| 6. The instruction | Seconds | Only to the recipient | Client-side callback discipline |
| 7. Payment and silence | 2 to 8 weeks | Eventually | Bank reconciliation, supplier chasing |
The Four Invoice Fraud Patterns Specific to an Accountancy Practice
Generic guidance describes invoice fraud as a supplier problem. In a practice there are four distinct money flows an attacker can attack, and only one of them is the classic supplier scenario. Map all four before designing any control.
Pattern one: your fee note, redirected
The attacker sends your fee note to your client with their own account details. You have done the work, the client has paid it, and the money is gone. The client believes the debt is settled and will be justifiably unhappy when you chase.
This is the most damaging pattern reputationally because the fraudulent message genuinely came from your domain or a convincing imitation of it. The invoice fraud loss is the client’s, but the relationship damage is entirely yours.
Pattern two: the client’s supplier payment, redirected through you
Where a practice runs a bookkeeping or accounts-payable service, the attacker targets the payment run. A supplier on the client’s ledger emails a change of bank details, your bookkeeper updates the supplier record, and the next run pays the attacker. Because the change lands in the accounting system rather than in a payment approval, it can pass every downstream authorisation cleanly.
Pattern three: payroll diversion through the bureau
Payroll bureau work is a high-value invoice fraud adjacent target because it is date-driven and repetitive. The attacker phishes a partner’s mailbox, watches for messages about pending payroll runs, then emails the client’s HR contact with a last-minute change of employee bank details. Reported UK losses per incident in this pattern commonly sit in the £25,000 to £120,000 range.
Timing is the whole attack. The request arrives while everyone is already thinking about the payroll deadline, and the deadline suppresses the instinct to verify.
Pattern four: HMRC repayments and client money
If you hold client money, or nominate a bank account for HMRC repayments, an attacker can attempt to redirect refunds or draw on the client account. HMRC has confirmed the appetite for this: it disclosed to the Treasury Select Committee on 4 June 2025 that around 100,000 PAYE accounts, about 0.2% of that service’s user base, were compromised through phishing, with £47 million paid out in fraudulent repayments.
HMRC also received more than 170,000 scam referrals in the twelve months to 31 July 2025, down 12% year on year, of which over 47,000 involved bogus tax refund claims.
| Pattern | Whose money is lost | Where the change is made | First realistic detection point |
|---|---|---|---|
| 1. Your fee note redirected | The client’s | The emailed invoice PDF or its body text | Your aged debtors report |
| 2. Supplier payment via your bookkeeping | The client’s | The supplier master record in the ledger | Supplier statement reconciliation |
| 3. Payroll diversion at the bureau | The client’s, then the employee’s | The employee bank record before a run | An employee reporting an unpaid salary |
| 4. HMRC repayment or client money | The client’s, and potentially yours | The nominated repayment or client account | Client account reconciliation, HMRC statement |
The pattern nobody plans for: your own accounts payable
Practices routinely design invoice fraud controls for client work and forget their own supplier ledger. Your practice pays a landlord, a software vendor, a subcontractor and an indemnity broker. Each of those is a change-of-details opportunity, and none of them is covered by a client-facing verification policy. Extend the same discipline inward.
The Mailbox Rules That Hide Invoice Fraud From the Account Owner
Concealment is what turns a compromised mailbox into successful invoice fraud. Without it, the account owner would see the reply, the confusion and the query within hours. Rule creation is also one of the very few stages that leaves a clean, queryable audit trail, which makes it the highest-value detection point in the whole sequence.
What the rules typically look like
An attacker rarely forwards everything, because volume creates noise. They build narrow rules keyed on the words that matter: the client name, the supplier name, “invoice”, “remittance”, “bank”, “payment”, “BACS”. Matching messages are moved to RSS Feeds, Conversation History, Archive or Deleted Items, or marked as read, or both.
Why the folders chosen are always boring ones
RSS Feeds and Conversation History are the classic destinations because almost nobody in a practice ever opens them, they exist by default in every mailbox, and their contents do not appear in the unread count. A rule that files invoice queries there produces perfect silence.
Where to look, precisely
Rule creation is audited. Search the unified audit log for the New-InboxRule and Set-InboxRule operations, review every mailbox for client-side rules, and check message trace for forwarding to external addresses. Mailbox auditing is on by default for most tenants, but confirm rather than assume.
| Rule pattern seen | What it conceals | Where to find the evidence |
|---|---|---|
| Move messages containing “invoice” to RSS Feeds | Client queries about the changed details | Audit log: New-InboxRule; Get-InboxRule per mailbox |
| Delete messages from a named supplier domain | The real supplier chasing payment | Audit log; message trace for the domain |
| Mark as read and move to Conversation History | Everything, without changing the unread badge | Get-InboxRule; folder item counts |
| Forward to an external address, then delete | Ongoing surveillance after remediation | Message trace; remote domain and forwarding reports |
| Rule with a blank or single-character name | Itself, in a crowded rules list | Get-InboxRule output review |
Treat rule creation as an incident, not a curiosity
The single most effective invoice fraud detection control available to a small practice costs nothing: an alert policy that fires whenever any user creates an inbox forwarding or redirect rule. Almost no legitimate user in an accountancy firm needs one. Treat every hit as a suspected compromise until proven otherwise, and you convert a five-week detection gap into a same-day one.
Why Your Practice Sits Outside the Invoice Fraud Reimbursement Safety Net
Most partners assume that if the worst happens, the bank will make it good. For a consumer that is broadly true. For a professional firm it usually is not, and the gap is the single most under-appreciated fact about invoice fraud in accountancy.
What the mandatory reimbursement rules actually say
Since 7 October 2024, the Payment Systems Regulator has required reimbursement for in-scope APP scam victims. Payment service providers must reimburse up to £85,000, normally within five business days, or up to 35 business days where further investigation is needed. Firms may apply an optional £100 excess, which cannot be applied to vulnerable customers, and the cost is split 50/50 between the sending and receiving providers.
The regime covers Faster Payments and retail CHAPS transfers between UK accounts. The regulator has noted that 99.8% of cases fall below the £85,000 cap, so for eligible victims the ceiling is rarely the constraint.
The eligibility test that excludes most practices
Reimbursement applies to consumers, micro-enterprises and small charities only. A micro-enterprise means fewer than 10 employees and a turnover or balance sheet total of no more than €2 million. A small charity means annual income under £1 million.
A 25-partner-and-staff practice is not a consumer, not a micro-enterprise and not a charity. It sits outside the scheme completely. If invoice fraud takes £40,000 out of your firm’s own account, the mandatory reimbursement framework does not apply, and recovery becomes a matter of goodwill, insurance and speed.
| Who is paying | In scope of mandatory reimbursement? | Why |
|---|---|---|
| A sole trader client paying your fee note | Usually yes | Likely a micro-enterprise or consumer |
| A 6-person client company | Usually yes | Fewer than 10 employees, turnover test applies |
| A 40-person client company | No | Exceeds the micro-enterprise headcount test |
| Your own practice, 25 staff | No | Not a consumer, micro-enterprise or small charity |
| A registered charity client, income £600k | Usually yes | Income below the £1m small charity threshold |
| Any payment above £85,000 | Capped | Reimbursement is limited to the £85,000 ceiling |
Even eligible victims recover less from this scam type
Here is the figure that should reframe the risk. Across all APP fraud in 2025, banks returned £354.3 million to victims, 61% of losses, and 89% of in-scope losses were reimbursed under the regulator’s framework. For invoice and mandate scams specifically, only 48% of losses were returned.
That 13-percentage-point gap against the APP average is not an accident. Invoice fraud involves a genuine commercial relationship, a genuine invoice and a business decision, so more cases end up contested on the question of whether the payer took reasonable care.
What this means for how you brief clients
Do not tell clients they will be reimbursed. Tell them the truth: that roughly half of invoice fraud losses come back, that larger companies are outside the mandatory scheme entirely, and that the only reliable control is a phone call to a number they already held before the email arrived.
The Legal and Regulatory Exposure Invoice Fraud Creates
A practice that suffers invoice fraud faces more than the cash loss. Three separate regimes can engage, and two of them ask what procedures you had in place beforehand.
Failure to prevent fraud under ECCTA 2023
The failure to prevent fraud offence in the Economic Crime and Corporate Transparency Act 2023 came into force on 1 September 2025. A large organisation becomes criminally liable where an associated person commits a specified fraud offence intending to benefit the organisation, unless it can show it had reasonable fraud prevention procedures.
Large means meeting two of three tests: turnover above £36 million, balance sheet total above £18 million, or more than 250 employees. Most independent practices fall below that. Many of your clients do not, and the Home Office guidance published on 6 November 2024 sets out six principles that those clients will increasingly push down their supply chain, which includes you. The penalty is an unlimited fine.
The underlying fraud offences
The conduct itself is caught by the Fraud Act 2006. Fraud by false representation under section 2 covers the dishonest misrepresentation of banking details with intent to make a gain. That matters practically because it determines what you report, to whom, and how a police reference number is generated for the insurer.
Data protection consequences
A compromised mailbox in an accountancy practice contains client personal data, and the ICO takes an unsympathetic view of missing basic controls. DPP Law Ltd was fined £60,000, published in April 2025, after attackers brute-forced an infrequently used administrator account with no MFA, moved laterally and stole 32GB of data. The firm only learned of it when the National Crime Agency reported client data on the dark web.
The findings cited infringements of Articles 5(1)(f), 32(1), 32(2) and 33(1) of the UK GDPR. The regulator issued 28 monetary penalty notices in 2025, the highest annual total since UK GDPR came into force, with the average penalty rising from around £150,000 to over £2.8 million, including a £14 million fine against Capita on 15 October 2025.
Client money regulations raise the stakes again
If your practice holds client money, invoice fraud can become a regulatory breach as well as a loss. ICAEW’s Clients’ Money Regulations require money to be held in a bank account in the firm’s name that is separate from the firm’s own accounts and includes the word “client” in its title. The bank must confirm in writing that it has no right of combination or set-off, without which the funds are not properly protected.
Where you expect to hold £10,000 or more for a single client for longer than 30 days, that money must sit in a separately designated account. Money must be held in the currency in which it was received unless the client instructs otherwise in writing. A fraudulent withdrawal from a client account is not merely a theft; it is a shortfall you must make good and report.
Anti-money laundering record keeping
Regulation 40 of the Money Laundering Regulations 2017 requires customer due diligence and transaction records to be kept for five years. Invoice fraud investigations draw directly on those records, so retention discipline and incident response are more connected than they look on an org chart.
| Record type | Retention | Source | Why invoice fraud needs it |
|---|---|---|---|
| CDD and transaction records | 5 years | MLR 2017, regulation 40 | Establishing the legitimate payee identity |
| Identity verification records as an authorised agent | 7 years | Companies House ACSP obligations | Proving who authorised a filing or change |
| Unified audit log events | Tenant-dependent, commonly 90 to 180 days | Microsoft Purview audit configuration | Proving when rules and sign-ins occurred |
| Mailbox contents of a compromised account | Preserve immediately on suspicion | Litigation hold or retention policy | Reconstructing what the attacker read and sent |
| Callback verification evidence | Life of the client relationship | Firm policy | Demonstrating reasonable care was taken |
AI-Generated Invoices: The 2026 Escalation of Invoice Fraud
Something changed in 2026. The tell-tale signs practices were trained to spot — awkward grammar, mismatched fonts, a logo pulled from a website at the wrong resolution — have largely disappeared. ICAEW published guidance in February 2026 on identifying fake invoices, and followed it in March 2026 with specific guidance on spotting AI-generated ones. That sequence, two months apart, tells you how quickly the problem moved.
What generative tools removed from the defence
The old detection advice was fundamentally aesthetic. It assumed a fraudulent invoice would look wrong. Generative tools produce documents that are typographically perfect, correctly formatted for UK VAT presentation, internally consistent on arithmetic, and written in fluent commercial English. The aesthetic layer of invoice fraud detection is finished.
What generative tools did not change
They did not change the bank account. Every invoice fraud attempt, however well produced, must eventually name a destination account that is not the legitimate payee’s. That is the invariant. It is why verification of the account, out of band, is the only control that scales against a threat whose presentation quality keeps improving.
The red flags that still work
Focus on the relational signals rather than the document. A supplier with no prior trading history. A newly incorporated entity. A change of bank details arriving alongside a change of contact email. An invoice that arrives slightly early relative to the usual cycle. A payee name that does not match the account name on Confirmation of Payee. Pressure, however politely expressed.
Train on the process, not the artefact
Rewrite your internal training accordingly. Stop showing staff examples of badly made fake invoices, because that teaches a detection method that no longer works and creates false confidence. Train instead on the single rule that survives: any change to payment details triggers a callback to a stored number, regardless of how convincing the request looks.
The Microsoft 365 Controls That Actually Stop Invoice Fraud
Most practices already own the controls that prevent invoice fraud and have not switched them on. The list below is ordered by the ratio of protection delivered to effort required, which is not the order vendors present it in.
Phishing-resistant authentication, not just any MFA
If around 80% of MFA bypasses involve stolen session tokens, then SMS and app-approval MFA are speed bumps rather than walls. Move partners, anyone with client money authority, payroll staff and every administrator to phishing-resistant methods: passkeys, FIDO2 security keys or Windows Hello for Business. Enforce them with authentication strength policies in Conditional Access rather than trusting per-user settings.
Microsoft began enforcing MFA for admin centre sign-ins on 9 February 2026, so the administrative half of this is happening regardless. Do the fee-earning half deliberately.
Conditional Access with token protection
Conditional Access is where you convert “we have MFA” into “a stolen token is useless”. Require compliant or hybrid-joined devices for mail access, block legacy authentication outright, restrict sign-in to expected countries, and shorten session lifetimes for high-risk roles. Device code flow is blocked automatically after 25 days of non-use, which closes one common token abuse route.
Anti-impersonation, properly configured
Defender for Office 365 anti-phishing policies include user impersonation and domain impersonation protection, and both ship effectively empty. Populate them. Add every partner and every member of the payments and payroll teams as protected users. Add your own domain and the domains of your largest clients and suppliers as protected domains. Enable mailbox intelligence and its impersonation protection so the service learns normal sender patterns.
External sender marking that people actually notice
A native external sender tag helps, but the version that changes behaviour is a mail flow rule that prepends a visible, unmissable banner to any external message whose display name matches an internal user or a known client contact. That is the exact spoof invoice fraud relies on, and a banner in the reading pane beats a small grey chip in the header.
Blocking and alerting on forwarding rules
Disable automatic external forwarding through the outbound spam filter policy. Then create an alert policy that notifies on inbox rule creation, and route it somewhere a human reads on the same day. This single control does more to shorten invoice fraud dwell time than any mail filter.
Auditing that is switched on before you need it
Confirm mailbox auditing is enabled, confirm the audit log search is available to your administrators, and know how to run it before an incident rather than during one. Practices routinely discover on day one of a response that the events they need aged out.
| Control | Business Premium | E3 | E5 | Effort |
|---|---|---|---|---|
| Conditional Access, authentication strengths | Yes | Yes | Yes | Half a day |
| Passkeys and FIDO2 enforcement | Yes | Yes | Yes | One day plus rollout |
| Anti-phishing impersonation protection | Yes | Add-on | Yes | Two hours |
| Safe Links and Safe Attachments | Yes | Add-on | Yes | One hour |
| Inbox rule creation alert policy | Yes | Yes | Yes | 30 minutes |
| Block external auto-forwarding | Yes | Yes | Yes | 15 minutes |
| Anomaly detection on session behaviour | Limited | Limited | Yes | Half a day |
| Attack simulation training | No | Add-on | Yes | Ongoing |
| Privileged Identity Management | No | No | Yes | One day |
One deadline worth diarising
Basic authentication for SMTP AUTH remains available until the end of December 2026. Any practice tax package, scanner or line-of-business tool still relaying mail with a username and password needs a migration plan now, because that credential is a standing invitation to send invoice fraud from your own domain.
Payment Process Controls: The Callback Discipline That Actually Works
Technology narrows the attack surface. Process is what stops the payment. A practice with mediocre tooling and excellent callback discipline loses far less to invoice fraud than one with the reverse.
The one rule that matters
No change to bank details is ever actioned on the basis of an email, a letter, a portal message or an attachment. The only acceptable verification is a voice call to a number held in your records before the change request arrived, made to a named individual, and recorded in the client file.
The number in the email signature does not count. The number on the invoice does not count. The number on the website the email links to does not count. Only the stored number counts.
Why callbacks fail in practice
They fail for three reasons, and all three are cultural rather than technical. The person doing the callback is junior and the person requesting the change is senior. The deadline is today. And nobody has ever seen a real case, so the control feels like theatre. Name those three failure modes in your policy and give staff explicit authority to delay a payment without needing permission.
Build the callback matrix by trigger, not by value
Value thresholds alone are the wrong model, because invoice fraud frequently starts with a small test payment. Trigger-based rules catch more.
| Trigger | Verification required | Who performs it | Evidence kept |
|---|---|---|---|
| Any change of bank details, any value | Callback to stored number | Someone other than the requester | Date, time, number dialled, person spoken to |
| New payee added to a ledger | Callback plus Confirmation of Payee check | Bookkeeper, approved by manager | Callback note and CoP result |
| First payment to any new payee | Small test payment, confirmed received | Payments team | Confirmation from the payee |
| Change of payee contact email | Callback, treat as suspicious in itself | Client manager | File note |
| Urgency or confidentiality asserted | Escalate to partner, no exceptions | Partner | Written approval |
| Payroll bank detail change inside 5 days of a run | Callback plus deferral to the next cycle | Payroll manager | File note and client sign-off |
A worked example of what the discipline costs
Take a practice running payroll for 140 client companies, twelve runs a year, giving 1,680 payroll instructions annually. Assume bank details change on 2% of those instructions, which is 34 changes a year, roughly three a month. At six minutes per callback, the entire annual control costs 3.4 hours of staff time.
Set 3.4 hours against the £17,918 average invoice fraud loss. Even one prevented incident every fifty years would justify it, and the actual incidence is enormously higher than that.
Confirmation of Payee is a signal, not a guarantee
Confirmation of Payee tells you whether the account name matches the name you typed. It is useful, and a mismatch should stop a payment dead. But criminals open accounts in company names that closely resemble the real payee, and a “close match” response is exactly the ambiguity invoice fraud exploits. Treat a close match as a failed check, not a passed one.
Separate the two jobs nobody separates
The person who can amend a supplier’s bank details in the accounting system should not be the person who can release a payment run. In small practices this feels impossible, but it usually only requires one role change and one permissions edit. Where genuine separation is not achievable, add a compensating control: a weekly report of all bank detail changes, reviewed by a partner.
Detecting Invoice Fraud While It Is Still Happening
Detection is a five-week problem compressed into a one-day one. These are the signals in rough order of how early they appear.
Identity signals, day zero
Impossible travel, sign-ins from unfamiliar infrastructure, a new authenticator method registered, an unexpected OAuth application consent, or a sign-in that succeeded with an unusual token. Any of these on a partner or payments account warrants an immediate conversation, not a ticket in a queue.
Mailbox signals, day zero to day three
Inbox rule creation, a spike in mailbox searches, large numbers of messages marked read outside working hours, or new folders in a mailbox that has looked the same for years. These are the highest-fidelity invoice fraud signals you will get.
Communication signals, day three onward
A client asks about an invoice you have not sent. A supplier’s email address gains a character. A long-running thread suddenly has a new participant. Someone replies to a message you never wrote. Staff should have one route to report these instantly and should never be made to feel foolish for using it.
Financial signals, week two onward
Aged debtors showing invoices the client believes they paid. A supplier statement that will not reconcile. Small unexplained payments. By this stage the money has usually gone, but speed still determines partial recovery.
Give staff one number and one sentence
Every invoice fraud response plan should reduce to a single instruction that every member of staff can recall under pressure: “If a payment instruction feels wrong, stop the payment and ring the client on the number in our system.” Nothing else in a training programme matters as much as that sentence being known by everyone.
Invoice Fraud Incident Response: The First 24 Hours
When invoice fraud is suspected, the order of operations decides how much money comes back. Recovery odds fall sharply after the first few hours because funds are layered through mule accounts quickly.
Do the money first, the mailbox second
The instinct is to secure the account. The correct first action is to stop the money. Contact the sending bank immediately and ask for a recall, then contact the receiving bank. Report to Action Fraud and obtain a crime reference number, which the insurer will require. Only then start the technical containment.
Contain without destroying the evidence
Revoke sessions and refresh tokens rather than only resetting the password, because a password reset alone leaves a stolen token valid. Then reset credentials, remove attacker-registered authentication methods, revoke suspicious OAuth grants and delete malicious inbox rules — after exporting them.
Preserve before you clean. Export the rules, capture the audit events and place the mailbox on hold. Practices routinely destroy the record of what happened in the first hour of tidying up.
Work out what was read, not just what was sent
The sent items folder tells you what the attacker did. The reconnaissance tells you what they know. Assume every message and attachment in that mailbox is compromised, including client bank details, tax references, identity documents and correspondence with HMRC. That assessment drives both your data protection obligations and your client notifications.
Notify quickly and specifically
Tell affected clients directly, by phone where money is at risk, and tell them precisely what to check: any payment instruction received from your firm in the exposure window. A vague “we have had a security incident” email causes alarm without preventing the next payment. Assess whether the ICO must be notified within 72 hours, and record the reasoning either way.
| Window | Action | Owner | Evidence to capture |
|---|---|---|---|
| 0 to 60 minutes | Bank recall request, both banks contacted | Partner or finance lead | Reference numbers, times, names |
| 0 to 60 minutes | Revoke sessions and tokens on the affected account | IT or MSP | Sign-in log export |
| 1 to 3 hours | Export inbox rules, then remove them | IT or MSP | Rule definitions before deletion |
| 1 to 3 hours | Report to Action Fraud, obtain crime reference | Practice manager | Crime reference number |
| 3 to 8 hours | Scope the exposure window and affected clients | Incident lead | Audit log, message trace, sent items |
| 3 to 8 hours | Notify clients at risk by phone | Client partners | Contact log |
| 8 to 24 hours | Notify insurer and professional body as required | Managing partner | Notification correspondence |
| 24 to 72 hours | Decide and document the ICO notification position | Data protection lead | Assessment record |
Rehearse it before you need it
The Cyber Security Breaches Survey 2025/2026, published on 30 April 2026, found only 25% of UK businesses hold a formal incident response plan and only 31% have a board member with named responsibility for cyber security. A one-hour tabletop exercise walking through a suspected invoice fraud is the cheapest preparation available, and it reliably exposes the two or three phone numbers nobody can find.
Client-Side Controls: What to Tell the People Who Actually Pay
Half of the invoice fraud risk in your practice sits in mailboxes you do not administer. You cannot configure your clients’ tenants, but you can change their behaviour, and you have more authority to do so than any vendor.
Publish a payment details policy and never deviate from it
Write one paragraph, put it on every engagement letter, every invoice and every email footer: our bank details will never change; if you receive notification that they have, it is fraudulent; call us on this number to confirm. Then honour it absolutely. The moment you make one exception, the policy stops protecting anyone.
Give them the number before they need it
Provide a verification phone number at onboarding, not at the point of payment. A number supplied in the same email as the change request verifies nothing. Ask clients to store it in their finance system against your supplier record.
Explain the reimbursement position honestly
Most client finance teams believe their bank will refund an invoice fraud loss. Explain the eligibility test, and explain that even eligible victims recovered only 48% of invoice and mandate losses in 2025. That single statistic changes payment behaviour more effectively than any amount of security advice.
Tell them what a real change looks like
Because occasionally details do change legitimately. Set the expectation now: a genuine change comes with a phone call from a person they know, initiated by you, referencing something only you would know, and it is never urgent. Anything else is invoice fraud until proven otherwise.
HMRC, Companies House and Agent Account Hardening
Your agent credentials are a distinct invoice fraud target because they reach money and identity at the same time.
HMRC agent multi-factor authentication is now mandatory
HMRC confirmed in Agent Update 141, published on 19 March 2026, that multi-factor authentication applies to web sign-in on GOV.UK for both the agent services account and HMRC online services for agents. It does not affect Making Tax Digital for VAT or PAYE software submissions.
The rollout ran in phases: accounts requesting by 30 June 2026 were switched on 15 July 2026, those requesting by 31 July 2026 on 19 August 2026, and all remaining accounts between 28 September and 15 October 2026. Codes arrive through an authenticator app, which HMRC prefers, by SMS from 60551, or by automated voice call from 01749 608007. Text and voice codes are six digits and valid for 15 minutes.
The shared-login problem this exposes
Practices that share an agent login must distribute the authenticator seed key to everyone who needs access, which is workable but fragile. Every account needs at least two administrators, because nobody can reset their own MFA. Firms that ignored this discovered it at the worst possible moment, mid-filing season.
The better answer is to stop sharing logins. Shared credentials remove all attribution from your audit trail, which is exactly what you need when reconstructing an invoice fraud incident.
Companies House identity verification and ACSP duties
Identity verification became a legal requirement at Companies House on 18 November 2025, with a twelve-month transition for existing directors, PSCs and LLP members closing on 18 November 2026. If your practice files on behalf of clients, you will need registration as an authorised corporate service provider.
ACSPs must be supervised by one of the 25 UK anti-money-laundering supervisory bodies, must keep identity check records for seven years, and must notify Companies House within 14 days of any relevant change, including loss of supervision. Those seven-year records are also the evidence base if a filing is ever disputed as fraudulent.
Report the phishing you receive
HMRC-branded phishing is the most common lure aimed at practice staff. Forward suspicious emails to [email protected] and suspicious texts to 60599. It costs nothing and it feeds the takedown process that removes the infrastructure used for the next round of invoice fraud.
E-Invoicing From April 2029: What Changes and What Does Not
There is a structural fix coming, and it is worth understanding precisely because it will be oversold.
What was confirmed
The government confirmed at Budget 2025 that e-invoicing becomes mandatory for all VAT invoices from April 2029, following the HMRC and Department for Business and Trade consultation that closed in May 2025. On 23 June 2026 the government confirmed the Peppol network as the interoperability framework, using a four-corner model. A detailed implementation roadmap is due at Budget 2026, and in-depth stakeholder engagement began in January 2026.
What it will genuinely improve
Structured, machine-readable invoices exchanged over an accredited network are much harder to alter in transit than a PDF attached to an email. Participants are registered, routing is controlled, and the document is validated rather than merely rendered. That closes the interception and modification variants of invoice fraud fairly effectively.
What it will not fix
It does not close the compromised-account variant. If an attacker controls a legitimate supplier’s system, they can update the banking details at source and the network will faithfully deliver a perfectly valid, perfectly structured, entirely fraudulent invoice. Real-time reporting to HMRC is not included at launch either.
The practical planning point
April 2029 is three financial years away, and it is not a reason to defer anything. Every control in this guide will still be required after the mandate lands. Treat e-invoicing as an improvement to document integrity, and treat callback verification as the control that survives it.
What Invoice Fraud Prevention Costs, and the 90-Day Plan
The economics here are unusually favourable, which is worth stating plainly because security budgets are usually argued the other way.
The cost side
Most of what stops invoice fraud is included in licensing you already pay for. Passkey hardware for a small partner group is a one-off in the low hundreds of pounds. The genuine cost is configuration time and the ongoing discipline of callbacks, which the worked example above put at 3.4 hours a year for a 140-client payroll bureau.
Sequencing the first 90 days
Do the free, fast, high-impact items first. Nothing in the first thirty days requires a purchase or a project.
| Phase | Actions | Cumulative controls | Typical spend |
|---|---|---|---|
| Days 1 to 30 | Alert on inbox rule creation; block external auto-forwarding; audit all existing mailbox rules; publish the payment details policy; brief every client manager | 5 of 12 | £0 |
| Days 31 to 60 | Populate anti-phishing impersonation lists; add the external sender banner; write and issue the callback matrix; separate ledger amendment from payment release | 9 of 12 | £0 to low |
| Days 61 to 90 | Roll out passkeys to partners and payments staff; tighten Conditional Access; run a tabletop exercise on a suspected case | 12 of 12 | Hardware plus time |
Where certification fits
Cyber Essentials does not certify invoice fraud controls, but it forces the underlying hygiene: access control, secure configuration, patching, malware protection and firewalls. The Danzell requirements went live on 26 April 2026 and make missing MFA an automatic assessment failure, with existing accounts covered by the previous requirements until 26 October 2026. Certification and the process controls in this guide are complementary, not alternatives.
The argument to take to the partners
The Cyber Security Breaches Survey found 43% of UK businesses identified a breach or attack in the preceding twelve months, rising by size band from 42% of micro businesses to 46% of small, 65% of medium and 69% of large. An insurer survey of professional firms published on 24 April 2026 found 65% ranked cyber attacks as their main concern, more than three times the 18% who named economic pressures. The risk appetite conversation has already been had. What remains is scheduling the work.
Frequently Asked Questions About Invoice Fraud in Accountancy Firms
Is invoice fraud the same as business email compromise?
Invoice fraud is one outcome of business email compromise, not a synonym for it. Business email compromise describes the access; invoice fraud describes what the attacker does with it. A compromised mailbox can also be used for payroll diversion, CEO fraud or data theft.
Will our bank refund an invoice fraud loss?
Probably not, if the payer is your practice. Mandatory reimbursement covers consumers, micro-enterprises with fewer than 10 employees and turnover or balance sheet up to €2 million, and small charities with income under £1 million. Even where it applies, only 48% of invoice and mandate scam losses were returned in 2025.
Does multi-factor authentication stop invoice fraud?
It stops a large share of the credential attacks that start it, but not the token theft variants that account for roughly 80% of MFA bypasses. Phishing-resistant methods such as passkeys and FIDO2 keys, combined with Conditional Access, are the version that holds up.
How long does invoice fraud usually go unnoticed?
Detection typically comes weeks after the payment, when a supplier chases an unpaid invoice or a reconciliation fails. The reconnaissance phase alone commonly runs from three to thirty days before anything is sent.
What is the single most valuable control for a small practice?
An alert on inbox rule creation, reviewed the same day. It costs nothing, takes about half an hour to configure, and it converts a five-week detection gap into a same-day one.
Are AI-generated invoices really harder to spot?
Yes, on presentation. They remove the grammar, formatting and layout errors that older training relied on. They do not change the underlying requirement for a fraudulent destination account, which is why out-of-band verification remains effective.
Does e-invoicing from 2029 solve this?
Partially. It makes invoices much harder to alter in transit, but it does not stop an attacker who has compromised a legitimate supplier’s system and changed the bank details at source.
Should we notify the ICO after a compromised mailbox?
Assess it properly and document the reasoning either way. A mailbox in an accountancy practice usually contains client personal data, so the threshold for a notifiable personal data breach is often met, and the 72-hour clock starts at awareness.
References
ICAEW: How to identify and deal with fake invoices
ICAEW: How to spot a fake AI-generated invoice
ICAEW: Payment diversion fraud, know the signs
ICAEW: Fraud issues for members in practice
ICAEW: Clients’ Money Regulations
ICAEW: Shared client money accounts, a compliance risk for firms
ICAEW: Clients’ money requirements, avoid these common mistakes
ICAEW: Practice Assurance common pitfalls for firms
ICAEW: Accountancy practices face daily cyber threats
FBI IC3: Business Email Compromise, the $55 Billion Scam
FBI IC3: 2025 Internet Crime Report
Payment Systems Regulator: Authorised push payment scams
House of Commons Library: Fraud and scams research briefing
GOV.UK: Fraud Strategy 2026 to 2029
Economic Crime and Corporate Transparency Act 2023, Part 5
GOV.UK: Economic Crime and Corporate Transparency Act 2023 factsheets
Fraud Act 2006, section 2, fraud by false representation
Money Laundering Regulations 2017, regulation 40
GOV.UK: Anti-money laundering supervision detailed information
ATT: Multi-factor authentication, how can agents prepare
HMRC: Report suspicious emails, texts and phone calls
Companies House: Changes to UK company law
NCSC: Phishing attacks, defending your organisation
NCSC: Phishing scams collection
NCSC: Small organisations guide to cyber security
NCSC: Multi-factor authentication for your corporate online services
NCSC: Cyber Essentials overview
Microsoft Learn: Anti-phishing policies in Microsoft 365
Microsoft Learn: Impersonation insight in Defender for Office 365
Microsoft Learn: Conditional Access authentication strengths
Microsoft Learn: Conditional Access overview
Microsoft Learn: Mailbox audit logging in Exchange Online
Microsoft Learn: Search the audit log in Microsoft Purview
Microsoft Learn: Alert policies in Microsoft Defender XDR
Microsoft Learn: Mail flow rules in Exchange Online
Microsoft Learn: Safe Links in Defender for Office 365
ICAS: Autumn Budget 2025, e-invoicing will go ahead from 2029
LexisNexis: HMRC and DBT publish outcome of the e-invoicing consultation
Peppol: The interoperability framework for e-invoicing
National Crime Agency: Fraud and economic crime