Supplier Risk Watch
Invoice Fraud·Global·

Two in Five Businesses Hit by Invoice Fraud, New Research Finds — Averaging US$367,000 in Losses

New industry research from Ivalua and Sapio Research found 40% of 800 procurement decision-makers across the US, UK, Germany and France experienced invoice fraud in the past 12 months, with affected organisations reporting average losses of US$367,000.

Source: Ivalua / Sapio Research · 3 September 2026 · Read original article →

Risk Snapshot

Loss

US$367k

Control Failure

Manual Supplier Controls

Risk

Invoice Fraud

Region

Global

What Happened?

Research commissioned by Ivalua, a source-to-pay software vendor, and conducted by Sapio Research surveyed 800 procurement decision-makers across the US, UK, Germany and France. Published as a press release on 3 September 2026, it found that 40% of respondents' organisations had experienced invoice fraud in the past 12 months. Among the organisations that lost money, the reported average loss was US$367,000.

Fraudulent supplier bank-detail changes were the single biggest concern among affected organisations, cited by 41%. Duplicate invoicing and compromised supplier email accounts followed closely, each cited by 39%, and ghost vendors — invoices from suppliers that don't genuinely exist or no longer trade — concerned 32%.

Only 25% of respondents said their organisation's supplier checks were mostly automated, with standardised workflows and audit trails. The clear majority were still relying on manual review, individual judgement, or processes that vary by team and by supplier.

Where Was the Supplier Risk?

All four leading concerns in the research — bank-detail changes, duplicate invoices, compromised supplier email and ghost vendors — sit at the same point in the process: the supplier record and what's allowed to change it, not the invoice approval step itself.

Where supplier records live in email threads, spreadsheets and fragmented systems rather than a single controlled source, there's no reliable way to know whether a bank-detail change, a new invoice, or a new 'supplier' altogether is genuine — the business is trusting whoever raised it, not verifying it.

This is a structural gap, not an occasional lapse: with 75% of organisations still relying on manual or inconsistent supplier checks, most businesses are exposed at exactly the moment a fraudster would choose to strike — when a detail changes, not when a new supplier is first approved.

What Went Wrong?

As vendor-sponsored research, these figures should be read as industry findings commissioned by a source-to-pay software provider rather than independent regulatory data — but the underlying pattern they describe is consistent with reporting from Scamwatch, the FBI and other independent sources on the same fraud types.

The common thread across all four concern areas is the absence of a standardised, automated workflow with an audit trail. Manual review depends on a person recognising something is wrong — and duplicate invoices, compromised-but-genuine supplier mailboxes and quietly-added ghost vendors are all built to look unremarkable to a person doing a quick check.

Only a quarter of organisations reported the level of automation and audit-trail discipline needed to catch these patterns systematically rather than by chance — leaving the other three in four dependent on manual vigilance for the exact fraud types survey respondents said were hardest to catch.

What Should Businesses Do?

  • Verify suppliers once, control changes forever after

    Approving a supplier properly at onboarding doesn't protect the business if its bank details, contact information or invoicing pattern can change later without the same scrutiny. Re-verification has to trigger on change, not just on entry.

  • Validate bank details independently, every time they change

    Don't accept a new account number because the request looks legitimate — confirm it independently before the next payment goes out, using a channel the requester doesn't control.

  • Build an audit trail for every supplier record change

    When a bank detail, contact, or invoicing detail changes, log who changed it, when, and how it was verified. An audit trail turns a fraud investigation from guesswork into evidence, and its absence is itself a control gap.

  • Treat duplicate invoices and ghost vendors as a data problem

    Catching a duplicate invoice or a vendor that no longer genuinely trades isn't about staff paying closer attention — it's about having systematic checks that compare every invoice and every supplier against a controlled, verified record.

The ArayaPRO Response

How ArayaPRO Helps

This is exactly the type of supplier risk ArayaPRO is built to control.

Explore ArayaPRO

Further Reading

Supplier Risk Watch

Stay ahead of supplier risk

Get the latest supplier fraud, payment risk and third-party incidents — with practical analysis of what went wrong and the controls that could reduce the risk.

Supplier-risk intelligence delivered to your inbox. No noise. Submitting this form subscribes you to Supplier Risk Watch emails — see our Privacy Policy.