AboutPricing

Vendor Invoice Fraud and BEC: Why Hundreds of One-Off Payees Are an AP Control Failure

August 21, 2026

|

7

minutes to read

Vendor Invoice Fraud and BEC: Why Hundreds of One-Off Payees Are an AP Control Failure
Mário Sérgio Rodrigues

Mário Sérgio Rodrigues

View author profile

Share

74% of organizations were hit by business email compromise in 2025, up from 63% the year before, according to the 2026 AFP Payments Fraud and Control Survey published in April 2026. 

Gigapay is the Merchant of Record for creator payouts: the one vendor that pays your creators on your behalf by taking on the compliance, payouts, and support so you don't have to. 

Invoice fraud is not a malware story. It is a vendor-master story, and every one-off payee your AP team adds for a campaign is a new bank-detail record an attacker can target. 

This article breaks down how vendor invoice fraud and BEC actually work, why hundreds of individual payees make both dramatically worse, and which AP controls close the gap.

Key Takeaways

  • 74% of organizations experienced BEC in 2025, per the 2026 AFP survey.
  • Invoice fraud targets vendor master records, not systems. Each payee is attack surface.
  • One-off campaign payees bypass call-back verification, PO matching, and supplier vetting.
  • Paying creators through personal wallets moves fraud and documentation off the ERP entirely.
  • A Merchant of Record replaces hundreds of bank-detail records with one verified vendor.
Vendor Invoice Fraud and BEC

Invoice Fraud in 2026: What the Latest AFP and FBI Data Shows

The 2026 AFP Payments Fraud and Control Survey, released on April 14, 2026, found that 76% of US organizations experienced attempted or actual payments fraud in 2025. Business email compromise remained the most common vector, affecting 74% of organizations, a sharp jump from 63% in 2024. 

Spoofed emails topped the list of BEC types, hitting 85% of organizations, and more than half of respondents received emails from lookalike domains that differed from legitimate ones by only a letter or two.

The FBI's Internet Crime Complaint Center backs this up with loss data. The 2025 IC3 report logged 24,768 BEC complaints and $3.05 billion in reported US losses, up from $2.77 billion the year before. Microsoft's 2025 Digital Defense Report adds an uncomfortable nuance: BEC represented only 2% of observed threats but 21% of attack outcomes. 

Attackers do not need volume when a single redirected supplier payment can be worth six figures.

The pattern behind these numbers is consistent. AFP has reported BEC as the top payments-fraud vector for years, and the mechanism has barely changed. 

  • Someone emails a new bank account. 
  • AP updates the record. 
  • The next payment goes to the attacker. 

No system was breached, no malware was deployed, and every control on the payment run worked exactly as designed. The failure happened earlier, in the vendor master.

Why the Vendor Master File Became the Primary Attack Surface

Finance teams spend heavily on payment security: dual approvals, positive pay, ACH filters, segregation of duties. The 2026 AFP data shows treasury departments now detect 83% of attempted fraud. What most of that spend protects is the payment run. What attackers target is the record the payment run reads from.

A vendor master record contains everything an attacker needs to monetize a compromise: a legal name, a bank account, an email address AP trusts, and a payment history that tells them how much money moves and when. 

Change the bank details on one record and every future payment to that vendor is redirected until someone notices, which is usually when the real vendor asks where their money went.

This is why vendor master hygiene, not email filtering, determines your real exposure. The number of records in your vendor file is the number of doors an attacker can knock on. 

A company with 40 suppliers has 40 doors. A company running creator campaigns can have 400, and most of those 400 were added in a hurry.

How Vendor Invoice Fraud and BEC Actually Work

Vendor invoice fraud and BEC are two halves of the same scheme, and understanding the sequence explains why one-off payees are so dangerous.

Step 1: Reconnaissance on Your Payees

Attackers identify who you pay. 

  • For traditional suppliers, this takes work. 
  • For creator campaigns, the reconnaissance is public. 

The creators tag your brand in their posts, announce the partnership, and disclose the ad. An attacker can build a list of your current payees from Instagram in an afternoon.

Step 2: The Bank-Change Email

The attacker impersonates the payee, either by spoofing their address or by registering a lookalike domain. More than half of organizations in the 2026 AFP survey received exactly this kind of lookalike-domain email in 2025. 

The message is mundane: "I've switched banks, please use these details for the next payment." 

Generative AI now writes these in the payee's exact tone, which the AFP report flags as a reason fraudulent emails have become more effective.

Step 3: The Update Nobody Verifies

Best practice says AP calls the vendor on a known number to verify any bank change. 

  • For a strategic supplier with a named AP contact, that call happens. 
  • For campaign payee number 63 of 80, invoicing from a Gmail address, with no phone number on file and a campaign launch on Friday, it does not.

Step 4: The Redirected Payment

The next payment run reads the updated record and sends the money to the attacker's account. Recovery windows for fraudulent transfers are measured in hours. Detection, in the one-off payee scenario, typically takes weeks, because a creator chasing a late payment looks identical to normal operations.

Vendor Invoice Fraud and BEC

Why Hundreds of One-Off Payees Make Everything Worse

Every new individual in the ERP is a new bank-detail surface, and one-off campaign payees are the weakest possible version of that surface. The reasons stack.

1. They have no verification anchor

A strategic supplier has a contract, a known office number, and a relationship history. A campaign contractor onboarded last Tuesday has a self-submitted form. There is no trusted channel to call back on, because the only channel you have is the one the attacker may control.

2. They invoice from personal email

Creators and campaign contractors send PDFs from Gmail, Outlook, and iCloud addresses. Personal accounts are compromised at far higher rates than corporate mail behind enterprise security, and a lookalike of a Gmail address is trivial to construct.

3. They change details legitimately, and often

Creators switch banks, move countries, and update handles. Your AP team sees genuine bank-change requests from this population constantly, which trains them to treat the fraudulent one as routine.

4. Volume defeats the process

Call-back verification does not happen when AP is trying to pay 80 people before a campaign goes live. Marketing set the deadline, the creators are posting on Monday, and the control that exists on paper gets skipped in practice. Fraud process design that assumes unlimited time per record fails at exactly the moment record volume spikes.

5. One compromised inbox scales the attack

The payees usually arrive as a spreadsheet from a marketing coordinator. If that coordinator's account is compromised, the attacker does not need to fake 60 bank-change emails. They forward one edited spreadsheet, and AP loads 60 fraudulent bank accounts in a single import.

6. Detection windows stretch

Dormant and one-off records are where fraud hides. A supplier you pay monthly notices a missing payment within days. A creator paid once per campaign may not chase for weeks, and by then the account is empty and the trail is cold.

The AP Controls That Actually Stop Invoice Fraud

Awareness training and email banners help at the margins, but the 2026 AFP numbers show BEC rising despite a decade of both. The controls that work are structural, and they start with a blunt question: why are these people in your vendor master at all?

Stop Adding Individuals to the Vendor Master

The most effective control on a bank-detail record is not creating it. Campaign payees, creators, and affiliates do not belong in the same file as your strategic suppliers. Every record you avoid creating is a record nobody can hijack, a record IT never has to secure, and a record internal audit never has to sample.

One Payee of Record, One Bank-Change Process

Consolidate the entire category into a single payee of record, then protect that one record with the bank-change process you already trust: call-back on a verified number, dual approval, and a change log. Guarding one high-value vendor record well is achievable. Guarding 400 low-value records equally well is not, and pretending otherwise is how audit findings get written.

Self-Billing Instead of Inbound PDFs

Invoice fraud needs an invoice. Under a self-billing arrangement, the paying party generates the invoice from verified campaign data, so there is no inbound PDF to spoof, no attachment to tamper with, and no payment instruction arriving by email. The document AP pays against was created inside a controlled system, not in someone's inbox.

KYC and KYB on the Person Receiving the Money

Verification of the payee's identity and bank-account ownership should be done by the party that pays them, with proper identity checks, not by a marketing coordinator matching a name to a spreadsheet row. If nobody in the flow has confirmed that the account belongs to the person who did the work, you do not have control, you have an assumption.

Payee Support That Is Not Your AP Shared Inbox

When payees email a shared AP inbox with payment questions, every reply teaches attackers your process, your timing, and your language. A dedicated payee support function, run by the payment provider, takes your AP team out of direct email contact with hundreds of individuals and removes the channel most BEC attacks travel through.

Vendor Invoice Fraud and BEC

What "Just PayPal Them" Does to the Audit

The common workaround, when finance refuses to onboard 300 individuals as vendors, is a personal wallet transfer from a marketing card or a PayPal business account. This does not reduce fraud risk. It relocates it somewhere worse.

Wallet payments move the fraud surface and the documentation off the ERP and into a trail finance cannot explain. There is no vendor record to control, no bank-change process to enforce, and no system log to review.

If a fraudulent redirect happens inside a wallet flow, finance often cannot reconstruct who approved what, because nothing was approved in any system finance owns. The compliance gap of wallet payouts is well documented. The fraud gap is the other half of the same problem: you cannot audit a control environment that does not exist.

How a Merchant of Record Closes the One-Off Payee Gap

A Merchant of Record restructures the problem instead of patching it. With Gigapay, you pay Gigapay, and Gigapay pays your creators, affiliates, and other campaign payees as their formal counterparty. The structural consequences map directly onto every failure mode above.

1. Your vendor master shrinks to one record

Bank details for 400 individuals never live as 400 rows in your vendor file, because the individuals are Gigapay's payees, not your vendors. Your ERP holds one vendor, one contract, and one consolidated invoice per campaign, and you protect that record like any high-value supplier.

2. The spreadsheet attack stops working

A compromised marketing coordinator cannot redirect 60 payments by forwarding one edited spreadsheet, because your AP team no longer loads payee bank details at all. Payees verify their own identity and bank ownership directly with Gigapay through KYC onboarding.

3. Verification happens where it can actually happen

Gigapay performs identity checks on every payee it pays across 65+ markets, which means the party moving the money is the party that verified the recipient. Gigapay is ISO 27001 certified, and finance and procurement teams can request the audit documentation the way they would for any supplier handling payment data.

4. The invoice surface disappears

Payees do not send your AP team PDFs. The documentation is generated inside the payment flow, so the classic invoice fraud entry point, a fraudulent attachment in an inbox, has nothing to attach itself to.

5. Support moves off your inbox

Payment questions from creators go to Gigapay's payee support, not your AP shared inbox, which removes both the workload and the social-engineering channel in one move.

The result for AP is a fraud review that covers one counterparty with mature controls, instead of a sampling exercise across hundreds of records that were onboarded under campaign deadlines.

What This Means for Your Approved Supplier List and Fraud Review

Two practical decisions follow for finance teams formalizing this.

First, put the Merchant of Record on the preferred supplier list, and keep individual campaign payees off it. The PSL exists to concentrate spend with vetted counterparties, and a payout MoR is exactly the kind of counterparty it was designed for. Adding each creator to the PSL individually recreates the original problem with extra paperwork.

Second, adjust the fraud review scope. If AP's fraud review keeps tripping on one-off payees, dormant records, and unverifiable bank changes, the finding to write is about vendor count, not awareness. 

The 2026 AFP data shows organizations investing in detection while the attack surface keeps growing. 

Cutting hundreds of records down to one does more for your BEC exposure than another round of phishing posters, because it removes the records the phishing was aimed at.

Vendor Invoice Fraud and BEC

Conclusion

Gigapay is the Merchant of Record for creator payouts, the single vendor that pays creators on your behalf and takes on the compliance, verification, and payee support that come with it. 

The 2026 fraud data is unambiguous: BEC hit 74% of organizations last year, and the vector runs through vendor master records, with one-off campaign payees as the softest targets in the file. 

The controls that work are structural. Keep individuals out of the vendor master, run one bank-change process on one payee of record, replace inbound PDFs with self-billing, and let the party that pays perform the KYC. 

If your vendor file is filling up with campaign payees faster than AP can verify them, book a demo and see what one vendor of record does to your fraud surface.

Read Next:

FAQs:

1. What is vendor invoice fraud? 

Vendor invoice fraud is a scheme where an attacker impersonates a legitimate payee and submits fraudulent invoices or bank-detail changes, so that accounts payable redirects real payments to an attacker-controlled account.

2. Does a Merchant of Record eliminate BEC risk? 

A Merchant of Record eliminates the multi-payee version of BEC risk by removing hundreds of individual bank-detail records from your vendor master, while the single MoR vendor record still needs the same protection as any high-value supplier.

3. Why are one-off payees a bigger invoice fraud risk than regular suppliers? 

One-off payees are a bigger invoice fraud risk than regular suppliers because they invoice from personal email, have no verified call-back channel, change bank details frequently, and arrive in volumes that make per-record verification impossible before campaign deadlines.

4. What is the most effective AP control against invoice fraud in 2026? 

The most effective AP control against invoice fraud in 2026 is reducing the vendor master itself: consolidating one-off payees under a single payee of record, protected by call-back verification, dual approval on bank changes, and self-billing instead of inbound invoices.

5. Is paying creators through PayPal safer than adding them as vendors? 

Paying creators through PayPal is not safer than adding them as vendors, because it moves the payments and their documentation outside the ERP, leaving finance with no vendor controls, no change log, and no audit trail to reconstruct if fraud occurs.

Tipalti, BILL, and Melio vs a Merchant of Record: Who Is Actually the Legal Buyer?

August 20, 2026

Tipalti, BILL, and Melio vs a Merchant of Record: Who Is Actually the Legal Buyer?

AP Automation Software in 2026: What Finance Should Demand When Payees Are People, Not Suppliers

August 19, 2026

AP Automation Software in 2026: What Finance Should Demand When Payees Are People, Not Suppliers

Employer of Record vs Merchant of Record: Which Risk Transfer Fits Contractor Payouts?

August 18, 2026

Employer of Record vs Merchant of Record: Which Risk Transfer Fits Contractor Payouts?