Trusted relationships can still be exploited
Supplier fraud happens when criminals exploit an existing supplier relationship to divert payments, obtain confidential information, or manipulate normal business processes.
It's hard to detect because nothing looks unusual at first. The supplier is genuine, the relationship may go back years, and previous payments have gone through without a hitch. The fraud happens because a criminal inserts themselves into a process you already trust — and it's often only discovered when the real supplier chases an unpaid invoice.
How it happens
Sometimes a criminal gains access to a supplier's email account and quietly watches how the relationship works before acting. They learn:
- Who approves payments
- When invoices are usually issued
- Typical payment values
- Which staff are involved
Once they understand the pattern, they introduce what looks like a routine request — a change of bank details, a revised invoice, or an urgent request to settle an outstanding payment. Because it's consistent with previous interactions, it often escapes extra scrutiny.
Why long-standing suppliers are attractive targets
Businesses naturally trust an established supplier more than an unfamiliar one — the longer the relationship, the lower the perceived risk. That's exactly why supplier fraud can be so effective: the employee processing the payment recognises the supplier name, the contact person, the invoice format and the project reference, so they focus on completing the transaction rather than questioning whether anything has changed.
A real-world example
A construction company has worked with the same supplier for years, and several invoices on the current project have already been paid without issue. An email arrives saying the supplier's banking details have changed. It looks professional and includes all the usual details, so nobody suspects anything — the next invoice is paid to the new account.
Weeks later, the supplier gets in touch asking why they haven't been paid. The invoice was genuine. The payment wasn't.
Warning signs to watch for
Supplier fraud rarely comes with obvious red flags — usually it's small changes:
- A different email address than usual
- Banking details changing unexpectedly
- Pressure to pay urgently
None of these automatically means fraud, but each one should trigger extra verification. The fraud is often hiding in the small details.
Building stronger controls
Consistency is one of the most effective controls you have. Verify every change to payment details independently, regardless of who's asking or how long you've worked with the supplier — and never use contact details provided in the request itself. Use the contact information already on file instead. Fraudsters succeed by controlling the communication channel; taking that control back often exposes the fraud immediately.
Why training matters
Most supplier fraud isn't down to weak systems — it happens because staff haven't seen the scam before. Regular awareness training helps your team recognise situations that deserve a second look, and understand why the controls exist in the first place.
Key takeaway
A long-standing supplier relationship should increase your confidence in the relationship, not reduce the need to verify. Every change should be checked independently, no matter who's asking.
Related articles
- What is business email compromise (BEC)?
- What is invoice fraud?
- How can businesses protect themselves from payment fraud?