Skip to main content

Invoice fraud: the biggest risk to your NFP's funds

Invoice fraud: the biggest risk to your NFP's funds

A fraudulent invoice can be created in seconds. It arrives looking exactly like one you were expecting, from a supplier you know, for an amount that seems right. The only thing that’s changed is the bank account. Pay it, and the money is gone.

For not-for-profits, this is the single biggest financial risk right now. You handle grant funds, donor money, and participant funds, often with a lean finance function and a lot of trust. That combination is exactly what invoice fraud targets.

I’m the CFO at Budgetly and I’ve been a not-for-profit director for 13 years. I’ve watched this threat change from clumsy fake emails into something far harder to catch. Here’s what’s happening and the simple checks that stop it.

The scale of the problem

The numbers are not small. The Australian Bureau of Statistics estimates 3.2 million Australians, around one in seven, experienced personal fraud in 2024-25. For business, an Australian Institute of Criminology survey found one in four small and medium businesses reported being a victim of cybercrime in the past year. Not-for-profits aren’t exempt. If anything, the structure of an NFP (distributed decision-making, volunteers, grant funds moving between accounts) makes you a softer target.

The reason it works is that the fraud doesn’t look like fraud. It looks like a routine payment.

How invoice fraud actually works

The most dangerous version right now is bank detail alteration. A genuine invoice is intercepted or imitated, and the bank account details are changed to the fraudster’s account. AI makes this trivial. A convincing invoice, matching your supplier’s branding and format, can be produced in seconds.

It usually arrives one of two ways:

  • A changed invoice from a real supplier. The supplier is legitimate and you’ve paid them before. This time the bank details are different. Maybe there’s a note saying they’ve “updated their banking”.
  • A request to change bank details. An email, apparently from a supplier or a staff member, asking you to update the account on file for future payments.

Both exploit the same gap: a payment or a detail change that nobody independently verifies before the money moves.

The three checks that stop it

None of these are complicated. They work because they put a verification step between the request and the payment.

1. Phone-verify bank details for every new supplier

Before you pay a new supplier for the first time, phone them to confirm the bank account. Not the number on the invoice, which may be the fraudster’s. A number you already hold or can independently confirm. A 30-second call prevents the most common and most expensive form of this fraud.

2. Do a test payment first

For a new supplier or a large first payment, send a small test amount and confirm the supplier received it in the right account before you send the full sum. It’s a minor delay against a potentially large loss.

3. Require third-party verification for any bank detail change

This is the one that catches the AI-altered invoice. Any request to change bank details, from anyone, triggers independent verification before you action it. Call the supplier on a known number. Confirm with a second person internally. Never update banking details on the strength of a single email, no matter how genuine it looks.

Make this a rule, not a judgement call. The moment it depends on whether someone “feels” an email is legitimate, it fails. Fraudulent invoices are designed to feel legitimate.

If you want the broader checklist beyond invoice fraud, our guide to fraud prevention for SME finance teams covers the full set of controls.

Why the right system makes this easier

Verification checks work. They work better when the system does some of the watching for you, because a lean NFP finance team can’t manually scrutinise every payment.

Three things reduce your exposure structurally:

  • Approval before the commitment. When spend is approved before money moves, not after the invoice lands, there’s a built-in moment to catch an unusual payment. This is the same principle behind real-time spend control: the check happens before the money leaves.
  • A finance decision log. If you record every decision that commits the organisation to spend, finance has an independent record of what’s genuinely owed. A surprise invoice for something nobody decided is an immediate red flag. (This is one of the practices in our guide to accountable NFP budgeting.)
  • Automated anomaly flagging. A system that flags unusual transactions and keeps an audit trail on every payment means a changed bank account or an out-of-pattern amount doesn’t rely on a tired person noticing it at 4pm on a Friday.

For not-for-profits, spend management built for NFPs brings these together: approvals before spend, a full audit trail, and fraud prompts on unusual payments.

The takeaway

Invoice fraud works because it hides inside your normal process. The fix is to add one verification step the fraudster can’t fake: an independent confirmation, by phone or by a second person, before any payment to a new supplier and before any change to bank details.

Make it a standing rule. Back it with a system that approves spend before money moves and flags anything unusual. For an NFP stewarding grant and donor funds, that’s not bureaucracy. It’s protecting the money you exist to use well.

Why are not-for-profits targeted by invoice fraud?
NFPs combine three things fraudsters look for: distributed decision-making, lean finance functions, and funds moving between accounts (grants, donations, participant money). Approvals are often informal and based on trust. That makes it easier for a fraudulent invoice or a fake bank-detail change to slip through without independent verification. The fix is a standing rule to verify before paying, regardless of how genuine a request looks.
What is the most common type of invoice fraud right now?
Bank detail alteration. A genuine invoice is intercepted or imitated, and the bank account is changed to the fraudster’s. AI makes a convincing fake invoice (matching your supplier’s branding and format) possible in seconds. It often arrives as a changed invoice from a real supplier, or as an email requesting an update to banking details on file. Both exploit payments that nobody independently verifies before the money moves.
How do I verify a supplier's bank details safely?
Phone the supplier on a number you already hold or can independently confirm, not the number printed on the invoice, which may be the fraudster’s. For new or large first payments, send a small test amount and confirm it landed in the right account before paying in full. For any request to change existing bank details, require independent verification by a known phone number or a second internal person before you action it.
Can spend management software prevent invoice fraud?
It reduces exposure rather than removing the need for checks. Approving spend before money moves creates a moment to catch unusual payments. An audit trail on every transaction and automated flagging of out-of-pattern amounts means a changed bank account or odd payment doesn’t depend on a person noticing it. Combined with phone verification and a rule for bank-detail changes, this is far stronger than manual review alone.
How many Australians are affected by fraud?
The Australian Bureau of Statistics estimates 3.2 million Australians (around one in seven) experienced personal fraud in 2024-25. An Australian Institute of Criminology survey found one in four small and medium businesses reported being a victim of cybercrime in the past year. Not-for-profits are not exempt. The structure of many NFPs, with distributed spending decisions and grant funds moving between accounts, can make them a softer target than a typical business.