TL;DR:

  • AI tools have made it trivially easy to generate convincing fake contracts, invoices, employment references, and legal documents — the spelling errors and obvious formatting problems that used to give fakes away are largely gone
  • UK small businesses are particularly targeted for fake supplier invoices, fraudulent contract variations, and forged authority documents (Companies House filings, HMRC letters)
  • The most effective defences are procedural, not technical: verify payment details by phone using numbers you already have, not numbers in the document

Document fraud has existed as long as documents have. What AI has changed is the scale, the quality, and who can do it. Generating a convincing fake contract used to require either professional graphic design skills or access to genuinely sophisticated criminal infrastructure. Today, a combination of widely available AI writing tools, document templates, and image editing software means a fraudster who couldn’t previously fake a convincing letterhead can now produce documents that fool trained professionals.

For UK small businesses — which often lack the verification infrastructure of larger organisations — the risk is real and growing.

What AI Document Fraud Looks Like in Practice

The most common attacks targeting UK small businesses fall into a few patterns.

Fake supplier invoice variations: You receive an email from what appears to be an existing supplier, with a PDF invoice that looks exactly like their usual invoices — same logo, same formatting, same signatory name. The email explains that their bank account has changed. The invoice looks professional, the email is convincing, and the sender’s name matches your contact. What you can’t see is that the domain is spoofed or one character off, and the PDF was generated using an AI tool seeded with your supplier’s actual invoice format.

This type of fraud — mandate fraud or invoice redirection fraud — predates AI, but AI has dramatically improved the quality of the fake documents. The tell-tale signs that used to give them away (wrong fonts, misaligned logos, inconsistent spacing) are now largely undetectable by eye.

Forged contracts and variations: A fraudster posing as a client, business partner, or contractor sends a “contract variation” or “purchase order” that looks like it comes from your usual contact. The document is professionally formatted, contains accurate reference numbers from your previous dealings (which the fraudster obtained through reconnaissance or a previous email breach), and requests you to proceed with work or release goods before payment.

Fake authority documents: HMRC letters, Companies House notices, court documents, and regulatory correspondence are being replicated with increasing accuracy. These are typically used to create urgency — “you owe an unexpected tax liability” or “your company registration is at risk” — and drive you toward a phone number or link that isn’t what it claims to be. The documents look official because AI has been trained on the real versions.

Employment and reference fraud: For small businesses hiring, fraudulent CVs and employment references have become much easier to produce. An AI can generate a plausible work history, and fake reference letters from real companies are easy to create. This isn’t a direct financial fraud, but it creates downstream risk when the person you hired misrepresents what they can do.

Why UK Small Businesses Are Targeted

Larger organisations have verification processes: three-way invoice matching, purchase order systems, dual-authorisation for payment changes. Small businesses often don’t. A sole trader or small team where one person handles both the supplier relationship and the payment processing is a much softer target.

UK small businesses also have predictable patterns that fraudsters exploit through open-source intelligence (OSINT). Your supplier relationships are often visible from your website, Companies House filings, social media, or job postings. If an attacker knows you’re working with a specific agency, accountant, or supplier, they can tailor a fake document to that specific relationship with details that make it look far more legitimate.

Action Fraud recorded significant increases in invoice fraud and mandate fraud reports in 2025 and 2026. The businesses most commonly targeted are those in construction, professional services, and creative industries — sectors where large one-off payments to new suppliers or contractors are normal.

How to Spot AI-Generated Fake Documents

The traditional tells — poor spelling, wrong fonts, pixelated logos — are largely gone from AI-generated fakes. What remains:

Verify the sender domain carefully. Fraudulent emails often use domains that are one character different from the real thing: supplier-name.co instead of supplier-name.co.uk, or suppliername-invoices.com instead of suppliername.com. Check the actual sending domain in your email client’s header view, not just the display name.

Look for inconsistencies in document history. Fake invoice PDFs often have creation metadata that doesn’t match claimed dates. Right-click → Properties → Details in Windows, or open Terminal and run pdfinfo document.pdf on macOS/Linux. A document claimed to have been created three weeks ago but with a creation date of yesterday is a red flag.

Unusual urgency or pressure. Legitimate suppliers and solicitors rarely demand same-day payment under threat of consequences. AI-generated fraud documents often include urgency cues because they’re designed to stop you from pausing to verify.

The document references things you’ve never done. Fraudsters sometimes make mistakes in their reconnaissance. A “contract variation” that references work you’ve never commissioned, or a “change of bank details” for a supplier you’ve never paid, is an obvious giveaway if you’re paying attention.

The Defences That Actually Work

Call to verify, using a number you already have. This is the most important single protection against invoice and payment fraud. Before processing any payment to a new bank account, or acting on any document that requires you to send money or provide access, call your contact — not on a number provided in the suspicious document, but on a number you have independently. A two-minute call eliminates almost all invoice fraud.

Set up a purchase order system. Even informal: agree with your team that you will only pay invoices that correspond to a purchase order or approved work order you issued. An unexpected invoice for work you didn’t authorise is a red flag regardless of how convincing the document looks.

Configure DMARC on your own domain. DMARC records prevent fraudsters from spoofing your business’s email domain to send fake documents to your clients. Your IT provider or domain registrar can set this up — it doesn’t stop fraud targeted at you, but it prevents you from being used as the spoofed sender in attacks on others.

Use a dedicated payment authorisation step for bank detail changes. Some businesses require a manager or director to personally verify and approve any changes to supplier bank details before the accounts payable system is updated. This single policy change closes the most common invoice fraud vector.

Check Companies House filings. If you receive a document purporting to be from a company — particularly a legal notice or contract from a company you haven’t dealt with before — verify the company exists and is registered as claimed at companies.gov.uk. Fraudsters sometimes invent company names or use dissolved company names.

Reporting and Recovery

If you’ve been defrauded by a fake document, report to Action Fraud (actionfraud.police.uk) immediately with all documentation. If a bank transfer was made to a fraudulent account, contact your bank’s fraud team immediately — the Payment Systems Regulator’s authorised push payment (APP) fraud reimbursement rules now require banks to reimburse most victims of APP fraud within 5 business days, as long as you weren’t grossly negligent.

Gross negligence is a contested standard, but in practice it means you must have taken reasonable steps — and “the document looked convincing” is not in itself gross negligence, particularly if you had no prior reason to be suspicious of that supplier.

The procedural controls above cost almost nothing to implement. The phone call before the payment is the cheapest fraud prevention measure that exists.