A fraudulent invoice can be created in seconds. It arrives looking exactly like one you were expecting, from a supplier you know, for an amount that seems right. The only thing that’s changed is the bank account. Pay it, and the money is gone.
For not-for-profits, this is the single biggest financial risk right now. You handle grant funds, donor money, and participant funds, often with a lean finance function and a lot of trust. That combination is exactly what invoice fraud targets.
I’m the CFO at Budgetly and I’ve been a not-for-profit director for 13 years. I’ve watched this threat change from clumsy fake emails into something far harder to catch. Here’s what’s happening and the simple checks that stop it.
The scale of the problem
The numbers are not small. The Australian Bureau of Statistics estimates 3.2 million Australians, around one in seven, experienced personal fraud in 2024-25. For business, an Australian Institute of Criminology survey found one in four small and medium businesses reported being a victim of cybercrime in the past year. Not-for-profits aren’t exempt. If anything, the structure of an NFP (distributed decision-making, volunteers, grant funds moving between accounts) makes you a softer target.
The reason it works is that the fraud doesn’t look like fraud. It looks like a routine payment.
How invoice fraud actually works
The most dangerous version right now is bank detail alteration. A genuine invoice is intercepted or imitated, and the bank account details are changed to the fraudster’s account. AI makes this trivial. A convincing invoice, matching your supplier’s branding and format, can be produced in seconds.
It usually arrives one of two ways:
- A changed invoice from a real supplier. The supplier is legitimate and you’ve paid them before. This time the bank details are different. Maybe there’s a note saying they’ve “updated their banking”.
- A request to change bank details. An email, apparently from a supplier or a staff member, asking you to update the account on file for future payments.
Both exploit the same gap: a payment or a detail change that nobody independently verifies before the money moves.
The three checks that stop it
None of these are complicated. They work because they put a verification step between the request and the payment.
1. Phone-verify bank details for every new supplier
Before you pay a new supplier for the first time, phone them to confirm the bank account. Not the number on the invoice, which may be the fraudster’s. A number you already hold or can independently confirm. A 30-second call prevents the most common and most expensive form of this fraud.
2. Do a test payment first
For a new supplier or a large first payment, send a small test amount and confirm the supplier received it in the right account before you send the full sum. It’s a minor delay against a potentially large loss.
3. Require third-party verification for any bank detail change
This is the one that catches the AI-altered invoice. Any request to change bank details, from anyone, triggers independent verification before you action it. Call the supplier on a known number. Confirm with a second person internally. Never update banking details on the strength of a single email, no matter how genuine it looks.
Make this a rule, not a judgement call. The moment it depends on whether someone “feels” an email is legitimate, it fails. Fraudulent invoices are designed to feel legitimate.
If you want the broader checklist beyond invoice fraud, our guide to fraud prevention for SME finance teams covers the full set of controls.
Why the right system makes this easier
Verification checks work. They work better when the system does some of the watching for you, because a lean NFP finance team can’t manually scrutinise every payment.
Three things reduce your exposure structurally:
- Approval before the commitment. When spend is approved before money moves, not after the invoice lands, there’s a built-in moment to catch an unusual payment. This is the same principle behind real-time spend control: the check happens before the money leaves.
- A finance decision log. If you record every decision that commits the organisation to spend, finance has an independent record of what’s genuinely owed. A surprise invoice for something nobody decided is an immediate red flag. (This is one of the practices in our guide to accountable NFP budgeting.)
- Automated anomaly flagging. A system that flags unusual transactions and keeps an audit trail on every payment means a changed bank account or an out-of-pattern amount doesn’t rely on a tired person noticing it at 4pm on a Friday.
For not-for-profits, spend management built for NFPs brings these together: approvals before spend, a full audit trail, and fraud prompts on unusual payments.
The takeaway
Invoice fraud works because it hides inside your normal process. The fix is to add one verification step the fraudster can’t fake: an independent confirmation, by phone or by a second person, before any payment to a new supplier and before any change to bank details.
Make it a standing rule. Back it with a system that approves spend before money moves and flags anything unusual. For an NFP stewarding grant and donor funds, that’s not bureaucracy. It’s protecting the money you exist to use well.








