Invoice Fraud Detector: How to Spot a BEC Scam (2026)
Learn to recognise cloned vendor invoices, payment-detail redirects and lookalike supplier domains before a convincing business email compromise message moves money out of the building.
Business email compromise (BEC) is a targeted impersonation scam: a criminal poses as an executive, supplier, or accounts-payable partner to influence a real payment. Invoice fraud is the document side of that scheme, using a familiar logo, an existing thread, or a genuine purchase-order number to make a false request look routine.
The objective is not always to invent a charge. More often the attacker changes where an already-approved invoice should be paid, then relies on speed and trust to hide the substitution.
The common thread
A believable identity plus a small payment-detail change is more dangerous than an obviously fake invoice. The document looks right because most of it is right.
Three ways invoice fraud arrives
1. A copied vendor invoice
The attacker clones a supplier's branding, line items and payment terms, then attaches a PDF that reads like the next invoice in a real conversation. A familiar amount and a valid purchase-order number lower the chance that anyone questions the new bank details in the footer.
2. An urgent wire or bank-detail redirect
A short email claims a closing date, audit, or shipment delay requires an immediate wire. It asks finance to replace the beneficiary account or use a new remittance address, framing a pause for confirmation as the risky choice. The urgency is not incidental โ it is the attack, because it removes the second pair of eyes.
3. A lookalike supplier domain
The display name says the right company while the sending address uses a one-character misspelling, an extra subdomain, or a domain registered last week. The reply-to address or an embedded link can quietly point somewhere different again, so your reply never reaches the real vendor.
How to spot a BEC scam
- Pause the urgency. Deadline pressure is the mechanism, not a detail. Treat "before close of business" as a reason to slow down.
- Call the vendor independently. Use a number from your approved supplier directory, never a number in the message itself.
- Compare addresses character by character. Check the sending domain, the reply-to address, and where each link actually resolves โ not the text it displays.
- Verify new payment instructions on a second channel. Any change of bank details deserves a callback to a known contact, whoever appears to be asking.
- Keep the normal approval path. Especially when the request seems to come from a senior colleague โ that is precisely the pressure the scam is built on.
- Reconcile against your own records. Match the purchase order, the amount, the delivery, and the bank details you paid last time.
Trust the established payment process, not the confidence or urgency of a single message.
What our document check actually looks at
Upload a PDF, image, or screenshot of an invoice and Document mode returns a manipulation probability โ an estimate of how likely it is the file has been altered. It is not an AI-authorship score, and it does not tell you who or what wrote the document. Three passes contribute:
- Error Level Analysis re-compresses the image and compares compression error across regions. Text pasted in after the original was saved tends to sit at a different error level from the page around it.
- A semantic and visual inspection pass reads the document as a document โ checking typography, alignment, spacing, layout consistency, and whether the numbers agree with each other.
- Structural forensics examines metadata and the file's internal structure: creation and modification history, producing software, incremental-save markers, and the object structure of the PDF.
What a clean result means โ and what it does not
A clean result means we found no detectable signs of manipulation. That is useful, but it is not a guarantee of authenticity. A legitimate invoice that was re-saved, scanned, or exported through a different tool can shift metadata and compression patterns, and a careful attacker who rebuilds a document from scratch leaves little for a forensic pass to find. A high manipulation probability is a reason to stop; a low one is a reason to continue with your normal checks.
Just as importantly, our tool analyses the document itself. It does not inspect sender domains, email headers, reply-to addresses or link destinations, so it cannot see the lookalike-domain half of a BEC attack. Pair the scan with the human verification steps above rather than treating it as a substitute.
A safe payment workflow
Pause on the urgency, verify the supplier independently through a known number, compare the invoice against your purchase records, scan the document for tampering, and obtain the approval your process requires. A clean scan is evidence โ not payment authorisation.
Check an invoice before you pay it
Five detection modes โ text, images, video, speech and documents. Three free checks a day in total across all modes, no signup required.
Try it free