Article
What a $67,000 Fake Invoice Scam Should Teach Every AP Team
A Wisconsin school district paid $67,636 on two fake invoices last fall after someone impersonated its superintendent's email address and told an accounting employee to cut checks for supplies that were never ordered. This is business email compromise invoice fraud: a scammer spoofs or fakes an executive's email, requests a payment through the normal channel, and relies on the request looking routine enough that nobody double-checks it.
The district is the Southern Door County School District in Door County, Wisconsin. The mechanics of how it happened, and the three checks that would have stopped it, apply just as directly to a 40-person marketing agency or a 200-person IT services firm paying subcontractor invoices by email every week.
What is business email compromise invoice fraud?
Business email compromise (BEC) invoice fraud happens when someone impersonates or spoofs a real employee's or executive's email address to convince a company to pay a fraudulent invoice through its own, normal payment process. There's no hacked bank account and usually no malware. The scammer only needs a convincing-looking email and a payment request that doesn't get double-checked. The FBI's Internet Crime Complaint Center has tracked more than $55 billion in reported BEC losses between October 2013 and December 2023, making it one of the costliest categories of reported cybercrime.
What happened in the Southern Door County school district scam
According to the criminal complaint, a woman named Laura Griffin set up an email address designed to look like it belonged to Superintendent Kevin Krutzik. From that address, she forwarded two invoices for "educational services" to a district accounting employee, one for $38,718 and a second for roughly $28,918, and asked the employee to process them. The district said Krutzik was never involved - the only real account touched was the accounting employee's own inbox, which received and acted on a spoofed message. The district paid both invoices, a total of $67,636, before anyone caught that the "superintendent" who sent the request wasn't him.
Griffin was later charged with two felony counts of theft by false representation. She missed her own initial court appearance on July 27, 2026, and a Door County judge issued an arrest warrant the following Monday. The district has since changed its verification process and recovered part of the loss, but the money was already gone by the time anyone questioned the invoices.
Why did two fake invoices pass normal review?
Nothing about this scam was technically sophisticated. There was no malware, no hacked server, no forged signature on a check. Two things did the work:
- The request came from someone with authority. An email that appears to be from the superintendent carries an implicit instruction: don't slow this down, don't ask questions. Most AP review steps are built to catch a wrong dollar amount or a missing approval, not to question a request that already looks approved.
- There was nothing behind the invoice to check it against. "Educational services" is vague enough to plausibly be real, and there was no purchase order, contract, or prior vendor relationship for the accounting employee to compare it to. The invoice was the only document in the loop.
This pattern shows up constantly in fraud data. The Association of Certified Fraud Examiners found that asset misappropriation, the category that includes fake-invoice billing schemes, is the most common form of occupational fraud, appearing in 86% of cases with a median loss of $120,000 per case. A $67,636 loss sits comfortably inside that range.
What three checks would have caught this before payment?
None of the three checks below require new software. They require someone to do them, every time, on every email-initiated payment request.
1. Verify the sender's actual email address, not the display name. A spoofed or lookalike domain is the most common tell in BEC fraud, and it is invisible if you only glance at the name shown in your inbox. The accounting employee in this case was looking at "Kevin Krutzik" in the From field, not the domain behind it.
2. Confirm the request through a second channel. Call the person the request claims to be from, using a phone number you already have on file, not one in the email. This single step breaks almost every BEC scam, because the fraudster does not control that second channel.
3. Match the invoice against a real underlying order. Ask what contract, purchase order, or prior engagement this invoice belongs to. "Educational services" with no PO and no prior vendor record should have stopped the payment on its own, independent of who appeared to send it.
| Check | What it catches | What it misses alone |
|---|---|---|
| Sender/domain verification | Spoofed or lookalike email addresses | A request from a genuinely compromised real account |
| Second-channel callback | Any request faked through email alone, however convincing | The main gap is skipping it under time pressure |
| Match to a real agreement or PO | Invoices for work that was never ordered, over-billed, or outside contract terms | The identity of who sent the request |
The three checks are complementary, not redundant. A callback catches an impersonated sender. Matching against a contract or PO catches a real vendor billing for something never agreed to. A services firm needs both, because either gap alone is enough for a fraudulent invoice to get paid.
How do you verify a payment request that appears to come from an executive?
Treat urgency itself as a signal, not a reason to move faster. Scammers who use this method deliberately reference travel, a closing deadline, or a favor to a superior, because it discourages the recipient from pausing to check. A short, standard script works for any AP team:
- Do not reply to the email that made the request. Start a new message or call using contact information from your own directory.
- Ask one plain question: "Can you confirm you sent this and what it's for?"
- If the requester is unreachable, the payment waits. No invoice is so urgent that it cannot wait for a same-day callback.
This is not about distrusting your own executives. It is about recognizing that anyone's name can be typed into a From field, and that the callback costs five minutes against a $67,636 loss.
What does checking the invoice against a real agreement add beyond email verification?
Email verification answers "did this person actually send this?" It does not answer "should we owe this money at all?" Those are different questions, and a lot of invoice fraud is built to pass the first one while skipping the second.
Matching an invoice against the underlying agreement, whether that is a signed contract, a statement of work, or a standing purchase order, means asking whether the vendor, the amount, and the description of work actually correspond to something the organization agreed to buy. A fake invoice for "educational services" with no PO attached should fail this check immediately, regardless of who appears to have sent it. This is the same gap that shows up in ordinary overbilling, not just outright fraud: a real vendor invoicing above a contracted rate, or billing for work outside the agreed scope, will also fail a real agreement match even though nothing about the email looks suspicious. We cover how to size that leakage in How to Measure AP Leakage at a Services Firm.
Most AP teams that do have a matching step only match to a purchase order, if one even exists. Contract-governed services firms often don't cut a PO for every subcontractor invoice, which means the fake-invoice scam this article opens with would have sailed past a PO match too, simply because there was no PO in the picture at all.
What's a same-day checklist for reviewing an email-initiated payment request?
Use this the day a payment request arrives that didn't come through your normal PO or subcontractor invoicing flow:
- Check the sender's actual domain, not the display name.
- Call the purported requester using a number from your own directory, not the email signature.
- Ask what contract, SOW, or PO the invoice belongs to. No match, no payment, until someone confirms it in writing from a verified channel.
- Check whether the payee's bank details match what's on file. A changed account number on an otherwise-normal-looking invoice is one of the clearest fraud signals there is.
- If any of the above can't be confirmed same-day, hold the payment. A held payment costs a delay. A paid one that shouldn't have gone out costs the money and the time spent trying to get it back.
What does this cost a CFO if it happens at your firm?
$67,636 is a real number for a school district budget, and it is a real number for a 50-person services firm too. The math a CFO should run is not just "what did we lose" but "what would it have taken to catch it." A callback costs a few minutes. A missing invoice-to-agreement match costs nothing to notice if someone is already looking for one. The recovery process after the fact - the police report, the insurance claim, the board or client conversation about what happened - costs far more than either check would have.
This is also where the honest tradeoff belongs: building a habit of second-channel verification and agreement matching doesn't require adding headcount. The right frame is absorbing this check into the review a person is already doing, before the next hire - not replacing that person. For firms processing a high volume of subcontractor and vendor invoices, the economics of automating that match tend to make more sense above roughly 200 invoices a month; below that, a disciplined manual checklist like the one above may be the right-sized answer, and that's a legitimate call for a smaller firm to make. You can read more on how firms size this exposure on the Quittance blog.
FAQ
What is business email compromise (BEC) invoice fraud?
Business email compromise invoice fraud is a scam where someone impersonates or spoofs a real employee's or executive's email address to direct a company to pay a fraudulent invoice through its normal payment process. The FBI's Internet Crime Complaint Center has tracked more than $55 billion in reported BEC losses since 2013.
How common is invoice fraud carried out through business email compromise?
It is common enough to be one of the costliest categories of reported cybercrime. The Association of Certified Fraud Examiners found that asset misappropriation, the fraud category that includes fake-invoice billing schemes, occurs in 86% of occupational fraud cases with a median loss of $120,000.
Should we call a vendor or requester to confirm every invoice?
For any request that arrives only by email, especially one that appears to come from an executive or references urgency, yes - confirm it through a phone number pulled from your own directory, not one in the email itself. This single step defeats the large majority of business email compromise scams because the fraudster does not control your existing contact information.
What's the difference between matching an invoice to a PO and matching it to the agreement?
A PO match confirms an invoice corresponds to a specific purchase order. An agreement match goes further and checks the invoice against the underlying contract, statement of work, or rate card, catching invoices for work that was never ordered at all, not just ones that don't match a PO number. Many services firms don't issue a PO for every subcontractor invoice, so a PO-only check leaves that entire category unverified.
Do we need to hire someone to catch this kind of fraud?
Not necessarily. The checks that would have caught the Southern Door County scam - sender verification, a callback, and matching the invoice to a real agreement - are procedural, not a headcount problem. The goal is to build these checks into the review a person already does, not to add a role. Firms with a high volume of invoices sometimes reach a point where the economics favor automating the match; that threshold tends to sit around 200 invoices a month, and below it, a disciplined manual process is often the right call.
What should we do if we already paid a fraudulent invoice?
Contact your bank immediately to request a recall or hold on the transfer, file a report with the FBI's Internet Crime Complaint Center, and notify your insurer if you carry crime or cyber coverage. Speed matters: recovery odds drop sharply once funds have moved through multiple accounts.