Who pays when invoice fraud happens?
The uncomfortable general rule: if you authorised the payment, the loss is usually yours. You instructed your bank to send money to an account, and the bank did exactly what you asked. That the instruction was obtained by deception does not, by default, make it the bank's problem.
This surprises people, and it is worth understanding before it happens rather than afterwards. What follows is general information, not legal or financial advice — for a specific situation, take proper advice.
Your bank
Because you authorised the transfer, this is treated very differently from an unauthorised transaction like a stolen card. The technical term you will hear is an authorised push payment.
Banks will usually attempt a recall, and that is worth pursuing immediately — it is the single most time-sensitive thing you can do. But a recall depends on the money still sitting in the receiving account, which is why hours matter and why very little is recoverable after roughly 72 hours.
Rules in some countries have begun shifting liability toward banks for certain scam payments, and consumer protections are generally stronger than business ones. Do not assume your jurisdiction has done this, and do not assume business accounts are covered where it has.
Your supplier
This gets contentious, because both sides usually feel wronged. The invoice was genuine; the payment went elsewhere; the debt is generally still considered outstanding. Many businesses discover they have to pay twice.
Where a supplier's own compromised mailbox was the source, there is a stronger argument that responsibility is shared — but establishing that requires evidence, and it is frequently a commercial negotiation rather than a legal determination. Preserving the original email with full headers matters enormously here.
Paying a fraudster usually does not discharge the debt. Businesses routinely find they owe the money a second time, to the supplier who never received it.
Your insurer — check this before you need it
This is the item most often assumed and least often verified, and the assumption is frequently wrong.
Many cyber policies exclude losses where an employee was deceived into transferring money voluntarily — which is precisely what happens in this fraud. Cover typically requires a specific social engineering or funds-transfer-fraud endorsement, and often carries a sub-limit far below the main policy limit.
Ask your broker one direct question and get the answer in writing: is funds-transfer fraud arising from a deceptive email covered, and to what limit? Ask before you need it, because the answer sometimes changes what controls you decide to put in place.
Why your controls affect the outcome
Whether you had a verification process, and whether it was followed, tends to influence every one of the conversations above.
Insurers commonly ask what controls existed and may decline where required procedures were not followed. Suppliers negotiate differently when you can demonstrate you did check. And a documented process protects the individual who made the payment from becoming the story.
This is a practical reason to keep records of verification calls, beyond the direct value of making them. A written record of who called, on what number, and what was confirmed is the difference between a defensible position and an argument about what someone remembers.
What to do in the first hour
Call your bank's fraud line and request a recall. Preserve the original email with full headers. Report it — in Australia, ReportCyber at cyber.gov.au and Scamwatch; elsewhere, your national cybercrime service. Notify your insurer promptly, since late notification is itself a common reason claims fail. Then tell the real supplier, because their mailbox may be the compromised one and their other customers are being targeted right now.
Common questions
Can I get the money back?
Sometimes, and it depends almost entirely on speed. If the receiving account is frozen before funds are moved on, recovery is realistic. Once the money has been withdrawn or transferred onward — often within hours — it rarely comes back.
Do I still have to pay the supplier?
Usually yes, because the supplier never received the money and the debt generally stands. Where their own compromised systems enabled the fraud there is more room to negotiate, but that is a commercial conversation and it goes better with evidence.
Is the employee who made the payment liable?
Ordinarily no — this is a business loss, not a personal one, and treating it as personal is actively harmful. The delay that destroys any chance of recovery is almost always someone hoping they are wrong before telling anyone. A no-blame reporting culture is worth real money here.
Related guides
- Is this invoice a scam? Seven checks before you pay
The seven things worth checking on an invoice that doesn't feel right, and the one check that actually settles it.
- A supplier emailed new bank details. What should you do?
The single most common way businesses lose large sums — and a short, repeatable process that stops it.
- You've paid a scammer. What to do in the first hour
If money has already gone, speed decides the outcome. The order of operations that gives you the best chance.