← All resources
Free resource · for finance & CA teams

Vendor invoice fraud: the AP checklist

A known supplier emails to say their bank details have changed, right before a payment run. This is business email compromise (BEC) — India's most common invoice fraud. It does not need malware; it needs a busy AP clerk trusting an email under time pressure.

Red flags on a "bank details changed" email

New account, supplied by email

A request to update a vendor's bank details, with a new account number, IFSC or UPI — timed near a real invoice so it reads as routine.

Free-webmail or lookalike sender

It comes from Gmail/Outlook/Yahoo instead of the vendor's business domain, or a lookalike (acme-corp.co vs acmecorp.com) that reads right at a glance.

Urgency and secrecy

"Process before end of day." "Keep this between us." The pressure exists to stop you calling the vendor to verify.

A reply inside a real thread

The most convincing version replies within a genuine email thread from a compromised mailbox. Everything above the change request is real — which is why the change must be verified another way.

The control that stops it

Add ScamShield AI to your practice.

CA firms use ScamShield AI to protect every SME client from one dashboard — flagging payment-change requests, lookalike senders and vendor fraud before a client acts on them. Ask about the CA Partnership programme: partner pricing, and clients onboarded under your own dashboard.