How to spot invoice and bank-detail fraud
A practical guide for travel businesses: the warning signs, the checks that work and what to do if a payment goes wrong.
Travel Ledger · 7-minute read · Updated October 2026
Why travel businesses are targeted
Fraudsters go where the money moves quickly. Travel businesses pay many suppliers, often in large sums, on tight deadlines, with invoices that arrive by email. That makes the finance inbox one of the most valuable targets in the business.
The tactics have changed too. Banks have become better at stopping unauthorised payments, so criminals now persuade genuine staff to send the money themselves. Authorised push payment fraud losses in the UK rose 19% to £576.4 million in 2025, according to UK Finance's Annual Fraud Report 2026 (opens in a new tab), which also warns that criminals are using AI to make scams more convincing.
The good news: most of these frauds depend on one moment, when someone pays bank details they received by email. Control that moment and you remove most of the risk.
The three common forms
The fake invoice. An invoice arrives that looks like it's from a supplier you know, with familiar branding and a plausible amount. The only difference is the bank account.
The intercepted email. A fraudster gains access to an email account, yours or your supplier's, and watches real conversations. When a genuine invoice is sent, they alter the bank details in the PDF and forward it on. Every name, reference and signature is real.
The impersonation call or message. Someone contacts you claiming to be a supplier, your bank or a senior colleague. They create urgency, ask for the person who makes payments, or ask you to update bank details “before the next payment run”.
Ten warning signs
Any one of these is a reason to pause before paying:
- A request to change bank details, however routine it sounds.
- New bank details in a different country, or at a different bank, from before.
- An account name that doesn't quite match the supplier's trading or legal name.
- Pressure to pay today, or a threat that bookings will be cancelled.
- A request to keep the change quiet or to skip the usual approval.
- An email address that's almost right: an extra letter, a different ending, or a reply-to address that differs from the sender.
- An invoice with small differences from the supplier's usual layout, wording or numbering.
- A payment amount that's unusually large, or split oddly across several invoices.
- A message arriving at a busy moment: month end, peak season, or when key staff are away.
- A caller who knows a lot about your business but won't let you call them back on a number you already hold.
None of these proves fraud on its own. Fraudsters rely on each one looking reasonable in isolation.
The one rule that stops most of it
Never act on a bank-detail change using contact details from the same message.
Verify every change by phoning the supplier on a number you already hold: from your system, a previous contract or their official website. Not the number in the email, the invoice signature or the caller's “direct line”.
If the request is genuine, the supplier will understand. If it isn't, that call is the moment the fraud fails.
A five-step process for bank-detail changes
Write this down and make it the rule for everyone who can pay suppliers:
- Hold. No payment goes to new bank details until the change is verified.
- Call back. Phone the supplier on a number you already hold and confirm the change with someone you know.
- Second pair of eyes. A second person approves any change to supplier bank details, separate from whoever received the request.
- Record it. Note who verified the change, when and how.
- Consider a check payment. For large payments to newly changed details, you may choose to send a small first payment and confirm receipt with the supplier, again using details you already hold.
Use your bank's payee check
Most UK banks now check the name on the account before you pay, through Confirmation of Payee. In Ireland and across the eurozone, Verification of Payee (opens in a new tab) has applied to euro bank transfers since 9 October 2025.
Take these checks seriously. A “no match” or “close match” result is a reason to stop and verify, never to click through. But remember that a match on its own doesn't prove the request is genuine, so the call-back rule still applies.
If you think you've paid a fraudster
Speed matters. In the first hour:
- Call your bank immediately. Use the number on its website or the back of your card, and ask it to try to stop or recall the payment.
- Report it. In England, Wales and Northern Ireland, report to Report Fraud at reportfraud.police.uk (opens in a new tab) or on 0300 123 2040. In Scotland, call Police Scotland on 101. In Ireland, report to your local Garda station.
- Secure your email. Change passwords, turn on multi-factor authentication and check for unfamiliar forwarding rules.
- Warn the real supplier. Use details you already hold, in case their email has been compromised.
- Keep everything. Save emails, invoices, call logs and payment records.
In the UK, mandatory reimbursement rules for authorised push payment fraud cover individuals, microenterprises and charities. Larger businesses may have no automatic right to get their money back, so prevention matters more.
For suppliers: protect your agents
Fraudsters often pose as suppliers, and when an agent pays a fraudster, you still haven't been paid. You can make that harder:
- Tell your agents, in writing, that you will never change your bank details by email alone.
- Give them a known phone number to verify any request.
- Keep the account name your bank holds in line with the name on your invoices, so payee checks return a clean match.
- Act quickly if you think your email has been compromised, and warn your agents.
Here's a message you can send your agents:
“We will never ask you to change our bank details by email or phone. Please pay us through Travel Ledger. If you receive a request to pay us any other way, contact us using details you already hold before paying.”
Removing the risk altogether
Every check in this guide exists to protect one risky step: someone keying supplier bank details from an email into a bank transfer.
Travel Ledger is built so that step isn't needed for connected suppliers. Trade Buyers pay connected suppliers through TL Pay without manually entering, storing or updating supplier bank details, so a doctored invoice has no bank details for a fraudster to change. For eligible suppliers outside the network, TL Virtual Cards give each payment its own card with set limits and validity.
Sources: UK Finance, Annual Fraud Report 2026; City of London Police; Banking & Payments Federation Ireland. This guide is general information, not legal or financial advice.
