Invoice fraud in 2026: when your client pays the wrong bank
The costly failure is not a late invoice. It is a paid invoice where the money went to someone else's account and everyone thinks the job is done.
The Delivvo team· July 24, 2026 8 min read
The worst thing that happens to a freelance invoice is not that it gets paid late. It is that it gets paid, in full, on time, into an account that is not yours.
Both sides then go quiet. The client believes the job is settled. You believe the client is slow. Two or three weeks later somebody asks a question, and the money is already through three hops and gone.
How the scam runs on a one-person business
Big-company fraud stories involve finance departments and eight-figure wires. The version aimed at independent professionals is smaller and much simpler.
The FBI defines business email compromise as a scam "targeting businesses or individuals working with suppliers", carried out "by compromising email accounts and other forms of communication" to conduct an unauthorised transfer of funds, in the 2025 IC3 Annual Report. Read that definition again. Individuals working with suppliers. That is you and every client you have.
Four patterns show up over and over.
The thread hijack. Someone gets into your mailbox, or your client's, and simply waits. They read the project thread. When the invoice goes out, they reply from a lookalike domain with a corrected PDF and an apology about a bank migration.
The quiet forwarding rule. The attacker adds a rule that forwards anything containing "invoice" or "payment" to an outside address and marks it read. Nothing looks wrong in your inbox for months.
The attachment swap. The email is genuinely from you. The PDF was replaced in transit or the account is compromised, and only the IBAN line differs from the one you sent.
Keep reading
The polite phone call. A voice claiming to be from your bank or your client's accounts team confirming "the new details we received". Social engineering does not need to be clever when it arrives at the exact moment a payment is expected.
What the numbers actually say
In 2025, IC3 logged 1,008,597 complaints and $20.877 billion in reported losses. Business email compromise accounted for $3,046,598,558 of that across 24,768 complaints, second only to investment fraud. The same table shows BEC losses of $2,770,151,146 in 2024 and $2,946,830,270 in 2023, so this is not a spike. It is a floor.
Two details from the report matter more to a freelancer than the headline.
First, the money almost always leaves by bank transfer. In the report's breakdown of transaction types, 86 percent of BEC losses moved by wire transfer or ACH. Not cards. Not crypto. The ordinary rail your clients already use to pay you.
Second, speed decides everything. The IC3 Recovery Asset Team ran 3,900 Financial Fraud Kill Chain actions in 2025 against $1,163,919,846 in attempted theft and froze $679,013,183, a 58 percent success rate. That number is only achievable when the victim reports within hours. The report's own instruction is blunt: if you discover a fraudulent transfer, contact your financial institution immediately and request a recall, then file at ic3.gov regardless of the amount.
A finance department has controls that annoy fraudsters: dual authorisation, a supplier master file, a person whose actual job is checking bank details against a record.
You have none of that, and the attacker knows it.
Worse, the window is generous. Xero's US small business data for the March 2026 quarter shows invoices taking an average of 28.8 days to be paid and running 9.0 days late. That is roughly five weeks in which an unpaid invoice is sitting in two inboxes and neither side thinks silence is strange. Five weeks is a long time to notice a swapped IBAN.
Then there is the shape of freelance work itself. New clients arrive by email from people you have never met. Payment details get sent as attachments. Project threads run for months, so a hijacked thread has plenty of context to imitate. Half the invoices are cross-border, where a foreign IBAN raises no eyebrows. And there is no colleague to walk over to and ask whether this looks right.
The countermeasure is not vigilance, because vigilance fails on a Friday afternoon in week nine of a project. It is having one boring rule that removes the decision from the moment entirely.
The clause worth adding to every contract
Two sentences in your terms do most of the work:
Payment details for this engagement are those published in the supplier portal or on the signed contract. Any request to change bank details, from either party, is void unless confirmed verbally on a telephone number held before the request was made.
That second sentence is the one that matters. It pre-commits both sides to a callback, and it means an attacker has to defeat a written contractual rule rather than a busy person's instinct. If your client's finance team pushes back, they will not, because it is the exact control their own auditors ask for.
Close-up of hands typing an email on a laptop keyboard in soft window light
The rail is starting to help, in Europe
For years the payment system did nothing to check that a name matched an account number. That changed in the euro area.
Since 9 October 2025, payment service providers in the eurozone must offer instant euro payments and must run a verification of payee check before a transfer, according to the European Commission. The check compares the beneficiary name against the IBAN. If the IBAN is right but the name does not match, the payment fails. The Commission is explicit that the service must be free of charge, and that banks cannot charge more for an instant transfer than a standard one. Instant euro payments extend beyond the euro area from January 2027.
That is a genuine improvement, and it is also the reason to keep your business name consistent everywhere. If your invoices say one trading name and your bank account says another, your euro clients will start seeing mismatch warnings on legitimate payments, and warning fatigue is exactly what the fraud relies on.
Outside the euro area, assume no check exists at all.
Six changes that actually close the gap
Most advice here is security theatre. These six are not.
1. Publish bank details in one place that is not email. An invoice inside a portal your client logs into cannot be edited in transit by someone who never had access to it. Email attachments can. This is the single largest structural fix available to a one-person business.
2. Make "we changed our bank details" a phone call, always. Both directions. Put it in the contract in one sentence: bank detail changes are confirmed by voice on a previously known number, never by email or by a number contained in the email requesting the change.
3. Turn on phishing-resistant sign-in for the mailbox that sends invoices. The mailbox is the crown jewel, not the bank account. Passkeys and hardware keys are the meaningful step up from SMS codes, and we walked through the practical switch in the passkeys guide.
4. Audit your forwarding rules monthly. It takes ninety seconds. Look for rules you did not create, rules that forward externally, and rules that auto-mark messages as read.
5. Send a payment confirmation request, not a reminder. Two weeks after issuing, ask the client to confirm the invoice was paid and which account it went to. The question that catches this fraud is "which account", and almost nobody asks it.
6. Verify new clients before the first invoice, not after. The same infrastructure that fakes a bank change fakes a whole client. The checklist for vetting suspicious clients covers that side.
The first hour after it happens
Work in this order.
Call your bank, then have the client call theirs, and use the word recall. Ask both banks about an indemnification request. Report it at ic3.gov with full transaction details if any party is in the US, and to your national reporting body otherwise. Preserve everything, including full email headers, before anyone starts deleting messages. Change the mailbox password and revoke active sessions. Then tell the client plainly what happened, because the relationship survives a fast honest report and rarely survives a slow embarrassed one.
Do not spend the first hour deciding whose fault it is. Fault gets sorted after the freeze request, and the freeze request has a shelf life measured in hours.
The IC3 figures make the case for speed better than any advice can. Of the 3,900 kill chain actions run in 2025, the team froze more than half the money at risk. Those are cases reported fast. The cases reported after a polite two-week wait to see whether the payment turns up are not in that statistic, because by then there is nothing left to freeze.
Delivvo puts your invoices, payment details, and delivery record inside one branded client portal, so payment instructions live somewhere a client logs into rather than somewhere an attacker can rewrite in transit. See how it works
The uncomfortable part
If a client pays a fraudster who impersonated you, the legal answer to "who eats it" depends on jurisdiction, on which mailbox was compromised, and on what your contract says. In practice, both sides are out of pocket and both sides lawyer up slowly.
Which is why the fix is process, not insurance. One place for payment details. One rule about changes. One monthly rule audit. One question in your follow-up email. Those four habits cost nothing and remove almost the entire attack surface a fraudster needs. If a dispute does start after money has moved, the payment dispute playbook covers what evidence actually matters.