You Just Discovered a Fraudulent Invoice Was Paid via ACH: An Accounting Team's Action Plan

You Just Discovered a Fraudulent Invoice Was Paid via ACH: An Accounting Team’s Action Plan

There’s a specific kind of stomach-drop that comes with this discovery: a vendor calls asking why their invoice still hasn’t been paid, and you pull up the record showing it was paid — weeks ago, via ACH, to a bank account you’ve never sent money to before.

This is business email compromise (BEC), and it’s the most common way accounting teams lose real money to fraud. Someone gets into an email inbox — yours, a coworker’s, or the vendor’s — waits for a real invoice to come due and sends a “quick update” with new bank details. The invoice looks right. The amount matches. The email thread looks legitimate because, in many cases, it is a hijacked real thread. You did everything your process asked of you, and the money still went to the wrong place.

You don’t need to be a security expert to respond well here. You mainly need to move fast, know who to call, and know what to hand off to IT versus what’s yours to run. Here’s the order to work in.

The first hour: call your bank
Do this immediately — before you do anything else, including emailing IT. Call your company’s bank and ask specifically for the fraud or treasury operations department, not general customer service. Tell them you were the victim of payment fraud paid via ACH, and give them:

  • The date and dollar amount of the payment
  • The receiving bank account and routing number from the fraudulent invoice
  • A copy of the invoice and the email(s) that requested the bank change

Ask them to attempt a fraud recall on the transaction. One thing worth knowing going in: ACH doesn’t have as strong a “clawback” mechanism as you might expect. The formal reversal process is really meant for your own mistakes (duplicate payment, wrong amount), and it must happen within five banking days. Because this payment was technically authorized by you — just based on a lie — your bank can’t guarantee it back. But most banks will still reach out to the receiving bank informally on your behalf, and that’s your best shot at getting funds back before they’re withdrawn. Push for it.

Same hour: loop in your manager and file the report that actually has teeth

Tell your controller or CFO right away — they’ll need to know regardless, and they may have relationships or insurance contacts that speed things up.

Then, whoever on your team handles this, file a report with the FBI’s Internet Crime Complaint Center at ic3.gov. This is the step people most often skip, and it’s genuinely one of the more effective ones: reporting within 72 hours of the payment can trigger the FBI’s Recovery Asset Team, which works directly with banks and FinCEN to request an emergency freeze on the receiving account. Companies have recovered real money this way. Include the transaction details, both banks’ information, and the fraudulent email as an attachment.

A local police report is also worth filing — your bank or insurance may ask for one later.

Now bring in IT — here’s exactly how to ask

This is the part accounting teams often get wrong: they either don’t loop in IT at all (assuming it’s “just a banking problem”), or they hand it off vaguely and IT doesn’t understand the urgency. Be specific. Here’s a template you can send or say almost word-for-word:

“We just discovered that we paid a fraudulent invoice via ACH — it looks like someone either compromised an email account or spoofed a vendor thread to send us fake updated bank details. I need your help figuring out if any of our email accounts were actually broken into, since that would mean the attacker may still have access. Can you check sign-in activity and mailbox rules for [name(s) of employee(s) who received or handled the fraudulent invoice] going back to [approximate date the fraudulent email arrived]? I can send you the exact email and headers now.”

What to hand IT, so they don’t have to chase you for it:

  • The fraudulent invoice/email itself, ideally forwarded with full headers (ask IT how they want it — usually as an attachment, not just forwarded inline, so nothing gets stripped)
  • The approximate date range the fraud started
    Names of everyone involved in receiving, approving, or paying the invoice
  • The amount and destination account, in case IT needs it for their own reporting

What IT will likely check on their end — you don’t need to do this yourself, but it helps to know what “the investigation” actually involves so you can ask informed follow-up questions:

  • Whether anyone’s email account was signed into from an unusual location or device
  • Whether any inbox rules were secretly created to hide or forward mail (a common trick — the attacker sets up a rule so replies about the fake invoice never reach the real inbox owner)
  • Whether any app was granted unusual permissions to a mailbox
  • Whether multi-factor authentication settings were changed on any account

Ask IT for a straight answer to one question in particular: “Was any of our accounts actually compromised, or did this happen entirely on the vendor’s side?” That answer determines your next move — if it’s on your side, IT needs to lock the account down (reset the password, kill active sessions, remove any malicious rules) right away. If it’s on the vendor’s side, your job shifts to warning them, since a compromised vendor mailbox is likely being used to scam their other customers too.

Don’t skip your insurance carrier
If your company carries cyber liability or crime/social engineering coverage, call them now, not after you’ve tried everything else. Many policies have short reporting windows, and calling late can jeopardize a claim you’re otherwise entitled to.

Notify the real vendor — carefully

Once you know (or suspect) the fraud originated on the vendor’s side, contact them through a phone number you already have on file — never a number from the suspicious email itself. DO NOT NOTIFY THE VENDOR VIA EMAIL. Let them know their invoice or email thread may have been hijacked. They’ll want to warn their own customers, and you’ll want written confirmation from them of what their actual, correct bank details are before you pay them again.

Once the dust settles: close the gap so it can’t happen again
The uncomfortable truth is that this kind of fraud rarely succeeds because someone on the accounting team was careless — it succeeds because there was no independent check built into the process for verifying bank-detail changes. A few changes are worth pushing for, even if they add a small amount of friction:

  • Callback verification, always. Any time a vendor’s bank details change, call a number you already had on file before this email — never a number provided in the email requesting the change. Make this a hard rule, not a judgment call.
  • A second set of eyes. Require a second person to approve any vendor bank-detail change in your accounting system before it takes effect.
  • A mandatory pause on urgency. Fraudulent invoices almost always come with pressure to move fast — “the vendor needs this today,” “please don’t delay.” Treat urgency itself as a red flag worth a short delay, not a reason to skip verification.
  • A known point of contact with IT before there’s a crisis. Know now, not during the next incident, who on your IT team to call and what information they’ll want from you. It’s the difference between a same-day response and a three-day scramble.

None of this is about assigning blame after the fact — the goal is simply to make sure that the next fraudulent invoice gets caught at the phone-call step, before it ever reaches your bank.

Modo Networks

Experience reliable IT solutions and see real results with our dedicated, expert team.

3010 Lyndon B Johnson Fwy Ste 1415
Dallas, Texas 75234

Phone: (214) 396-9131
Support: (214) 299-8580

Fully Managed IT

Support

Contact

Terms of Service

Mobile Terms of Service

BBB Seal Modo Networks IT Services Dallas
USFCR Verified Vendor

Newsletter

Copyright © 2026 Modo Networks. All Rights Reserved.