Invoice fraud has been around as long as businesses have paid invoices. What’s changed in 2026 is who’s doing it and how convincingly. Fraudsters who used to rely on badly formatted PDFs and awkward English are now using AI to produce near-perfect replicas of supplier invoices, clone the voice of your MD, and in some cases run live deepfaked video calls impersonating your bank’s relationship manager.
UK businesses lost £49 million to invoice and mandate fraud in 2024. 78 per cent of those losses hit business accounts rather than personal ones, which matters because the Mandatory Reimbursement Scheme protections that cover personal account victims generally don’t apply to business accounts. If you pay a fraudulent invoice from a business account after being deceived, getting that money back is genuinely difficult.
This isn’t something that only happens to large companies with complex payment chains. SMEs are the primary target precisely because they typically lack dedicated finance teams and fraud controls. Here’s what the current attacks look like and what you can do about them.
What AI-enabled invoice fraud looks like now
The basic invoice fraud is still the most common: a supplier’s email account is compromised, and you receive an invoice with updated bank details. The email comes from the right address, the invoice looks right, and you pay — but the money goes to a fraudster’s mule account rather than your supplier. This predates AI and is still happening at scale.
What AI adds is everything around it. Fake invoices used to have telltale signs: slightly wrong fonts, mismatched logos, unusual formatting. AI-generated fakes in 2026 can replicate your supplier’s standard invoice template perfectly, including correct VAT registration numbers, accurate contact details, and the formatting quirks specific to that supplier’s PDF template. There’s no visual signal to catch.
The voice cloning variant targets payment authorisation calls. Your financial controller receives a call from someone who sounds exactly like your MD or one of your directors, asking them to authorise an urgent supplier payment or bank detail change. The voice clone is built from LinkedIn videos, podcast interviews, YouTube content — whatever’s publicly available. It takes maybe 10 minutes of source material to produce a convincing clone.
The most sophisticated version is a deepfaked video call. This has occurred in UK incidents — a finance employee joins what appears to be a Teams or Zoom call with their CFO and a bank representative, both of whom are actually AI-generated video avatars. The employee is instructed to complete a large transfer. By the time anyone realises what happened, the money is gone.
The controls that actually help
You don’t need expensive technology to defend against most of these attacks. The defences are procedural, not technical.
The most important control is a callback policy for any invoice or payment request involving bank detail changes. Before changing stored payment details for any supplier, call them back on a number you already have — not the number on the incoming email or invoice. Do this even if the request came from a convincing-looking email address, even if the voice on the phone sounded right, even if the video call looked real. The fraudster’s control ends the moment you call an independently verified number.
Dual authorisation for payments above a threshold catches a lot of fraud that slips past the first person to see it. Set a sensible limit — perhaps £2,000 or £5,000 depending on your typical payment patterns — above which any payment requires sign-off from a second person. This is a standard control in larger organisations that SMEs often skip because it feels like overhead. It isn’t.
For supplier bank detail changes specifically, introduce a waiting period. Don’t process the change immediately. Wait 48 hours and send written confirmation to the supplier’s existing email address — not the one that requested the change — before updating your records. If it’s a genuine change, your supplier won’t mind waiting two days. If it’s fraud, the fraudster won’t be able to confirm via the original address.
What to report and to whom
If you think you’ve been targeted by invoice fraud — even if you didn’t lose money — report it to Action Fraud (actionfraud.police.uk) online. If you’ve already made a fraudulent payment, call your bank immediately on the number on the back of your card or your account documents. Don’t use numbers from emails or search results. Banks can sometimes recall payments in the first hour or two after transfer if they act quickly, but there’s no guarantee.
HMRC impersonation scams are a related category — fraudulent invoices claiming to be from HMRC for tax refunds or penalties. HMRC will never email or call you asking for immediate bank transfers. Any payment request presented as urgent and from HMRC is fraud.
The NCSC’s Cyber Action Plan (available at ncsc.gov.uk) includes specific guidance on Business Email Compromise, which is the technical category most of these attacks fall into. It’s worth reading if you’re the person in your organisation responsible for financial security controls.
The honest reality
No control eliminates fraud entirely. Fraudsters adapt. The AI tools they’re using are getting better faster than most businesses are updating their defences. But the controls above — callback verification, dual authorisation, 48-hour waiting periods for bank detail changes — stop the vast majority of attacks at the cost of a small amount of friction in your payment process.
That’s a trade-off worth making. £49 million in losses last year, mostly to businesses that didn’t have basic procedural controls in place, makes the friction look very reasonable.