The most effective way to protect your business from B2B fraud is to build friction into the exact moments money moves: verify every change to vendor banking details out-of-band, require dual approval on payments above a set threshold, and reconcile bank activity daily rather than monthly. Most B2B fraud does not break in through hacked systems. It walks in through a legitimate-looking email, a spoofed invoice, or a "new bank account" notice from a supplier you trust, and it succeeds because one person is allowed to approve and release a payment alone. The controls below are cheap, they are behavioral more than technical, and they stop the categories of fraud that actually drain small-business bank accounts.
Key takeaways
- Most B2B fraud is behavioral, not technical: it exploits urgency and a change in routine, not hacked systems.
- Out-of-band verification (calling a known number to confirm any banking change) defeats the largest-dollar fraud category.
- Dual approval above a set threshold and a three-way invoice-to-PO match stop the majority of AP fraud.
- Positive Pay, ACH debit blocks, and MFA are low-cost bank tools many owners never activate.
- Recovery odds on fraudulent wires drop sharply after the first 24 to 72 hours; call the bank and file with IC3 immediately.
- Revenue-based funding marketplaces underwrite on bank deposits and revenue: from about $10,000, FICO 500+, roughly 24 to 48 hours.
- 'Guaranteed approval' is itself a fraud signal; no legitimate funder promises approval before reviewing your revenue.
The B2B fraud that actually hits small businesses
Enterprise breaches make headlines, but the fraud that empties a small-business operating account is usually low-tech and relationship-based. These are the categories that show up again and again in accounts payable:
- Business email compromise (BEC). A criminal spoofs or hijacks an email account belonging to an owner, a controller, or a vendor, then requests a wire or an ACH change. The email reads normally because it often is coming from a real (compromised) inbox.
- Vendor / banking-change fraud. You receive a notice that a supplier has "updated their remittance details." The new account belongs to the fraudster. The next legitimate invoice you pay lands in their hands.
- Fake or duplicate invoices. Invoices for goods never ordered, services never rendered, or the same invoice submitted twice hoping AP pays without matching to a purchase order.
- Overpayment and refund scams. A "customer" overpays with a bad check or reversible payment, then asks for the difference back before the original clears.
- Card-not-present and chargeback abuse. Stolen cards used against your B2B storefront, or buyers who receive goods and dispute the charge.
- Impersonated authority. Fake collection agencies, fake utility shutoff threats, fake regulators demanding immediate payment.
The common thread is urgency plus a change in the normal routine. Fraud almost always asks you to move faster than your controls, or to bypass them "just this once."
The controls that stop most of it
You do not need an enterprise security budget. You need a short list of non-negotiable procedures that everyone with payment authority follows every time, especially when someone senior says it is urgent.
- Out-of-band verification for any banking change. When a vendor's account details change, call them back on a number you already have on file (never the number in the request email). Confirm the change verbally with a known contact. This single habit defeats the largest dollar-value category of B2B fraud.
- Dual approval above a threshold. No single employee should be able to originate and release a payment over a set dollar amount. Two sets of eyes, two logins.
- Three-way match on invoices. Match the invoice to a purchase order and to a receiving record before paying. No PO, no payment.
- Positive Pay and ACH debit blocks. Ask your bank to enable Positive Pay on checks and ACH filters that only allow debits from pre-approved originators. Most business banks offer this and many owners never turn it on.
- Daily reconciliation. Review bank activity every business day. Fraud caught within 24 hours is far more recoverable than fraud caught at month-end.
- Locked-down email. Multi-factor authentication on every email account, and a rule that no payment instruction is ever executed on email alone.
- Separation of duties. The person who sets up vendors should not be the person who approves payments to them.
A decision framework: how to respond to a suspicious payment request
When a request to move money looks even slightly off, run it through a fixed checklist rather than trusting your gut in the moment. Fraudsters engineer moments where your gut says "just handle it."
Works best when you treat every one of these as a hard stop, in any single request, regardless of who appears to be asking:
- The banking or remittance details are new or changed.
- The request carries urgency, secrecy, or a reason you cannot use the normal process.
- The payment method is a wire, a same-day ACH, gift cards, or crypto.
- The contact is reachable only by email or a new phone number.
- The amount is unusual for that vendor or that relationship.
Avoid the shortcut when the pressure is highest. "The owner needs this wired before the bank closes" is the exact script fraud uses. A real owner will accept a five-minute verification call. So will a real vendor. If verification is treated as an insult, that itself is a warning sign.
The rule is simple: a payment instruction is a request, not an order, until it is verified through a second, independent channel.
Realistic example: three requests, three outcomes
The table below shows how the same controls play out against common scenarios. Figures are illustrative, for example only.
| Scenario | What the fraudster does | Control that catches it | Outcome |
|---|---|---|---|
| Vendor "bank change" email | Emails a real-looking PDF with new ACH details ahead of a routine invoice, for example a $12,000 supplier payment | Out-of-band callback to the known vendor contact | Change is false; payment routed to the correct account; loss avoided |
| CEO wire request | Spoofs the owner's email demanding an urgent wire before end of day, for example $28,000 to a "new partner" | Dual approval + verbal confirmation with the owner | Owner never sent it; request quarantined; email account checked for compromise |
| Duplicate invoice | Resubmits a legitimate invoice a second time under a slightly different number, for example a repeat $4,500 charge | Three-way match against PO and receiving record | No matching open PO; invoice rejected; no double payment |
Notice that in every row the control is procedural, not technical. The tools help, but the discipline is what wins.
Building a culture where staff can slow down
Controls fail when employees feel they will be punished for causing delay. The most fraud-resistant AP teams share one trait: the people releasing money are explicitly authorized, in writing, to pause any payment for verification without needing a manager's permission. Make that authorization real.
- Train against pressure, not just phishing. Teach the team that urgency and secrecy are the signals, more than typos or bad grammar. Modern fraud emails are clean.
- Run occasional internal tests. Send a controlled "urgent change" request and see whether the callback happens.
- Reward the stop. When someone catches a false request, make it visible. That is the behavior you want repeated.
- Document vendor contacts centrally. Keep verified phone numbers in a system, not in individual inboxes, so callbacks use known-good numbers.
Culture is the control that scales. Software blocks a known pattern; a trained employee blocks the pattern you have not seen yet.
If fraud already happened: the first 72 hours
Speed determines recovery. Funds sent by wire or same-day ACH can sometimes be recalled, but the window is short and it shrinks by the hour.
- Call your bank immediately and request a recall or reversal. Ask specifically about a SWIFT recall (for wires) or an ACH return. Do this before anything else.
- File with the FBI's IC3 (ic3.gov). Their Recovery Asset Team can help freeze funds domestically if you act fast.
- Preserve evidence. Do not delete the emails. Save headers, invoices, and payment records.
- Reset and secure accounts. Assume the email account is compromised; force password resets and re-enable MFA.
- Notify affected vendors or customers if their data or invoices were involved.
- Review insurance. Check for crime/social-engineering coverage; many general policies exclude voluntary transfers, so know your terms before you need them.
Then rebuild. A single successful fraud usually exposes exactly which control was missing. Close that gap before you move on.
Protecting cash flow when a loss lands
Even a well-run business can absorb a hit that recovery does not fully reverse. When a fraud loss creates a temporary hole in working capital, the priority is keeping payroll, rent, and legitimate supplier payments on schedule while your controls are rebuilt. This is a cash-flow problem, not a solvency problem, and it calls for cash-flow-based funding rather than slow, credit-heavy term debt.
A revenue-based funding marketplace is often the practical fit here because approval leans on your actual bank deposits and revenue rather than credit score. Typical parameters in this channel: funding from around $10,000, FICO accepted from roughly 500 and up, and decisions in about 24 to 48 hours when bank statements are clean. Because underwriting reads real deposit activity, a healthy top line can carry a business through a short gap even when the calendar is tight. No responsible funder should ever promise a "guaranteed" approval, and you should be wary of any that does, since that language is itself a fraud signal.
Use it as a bridge, sized to the gap, with a clear repayment path from ongoing receipts, not as a substitute for fixing the control that failed. For the full picture on how this financing works, see our guide to revenue-based financing and our overview of business funding options for small businesses.
Frequently asked questions
What is the single most effective control against B2B fraud?
Out-of-band verification of any banking-detail change. When a vendor or executive asks to change where money goes, confirm it by calling a phone number you already have on file, never a number provided in the request. This one habit defeats the highest-dollar category of B2B fraud, business email compromise and vendor-change scams.
How is business email compromise different from regular phishing?
Phishing usually tries to steal credentials with a fake login page. Business email compromise skips that and goes straight for the money, often from a real, hijacked inbox or a convincing spoof. The message reads normally and exploits trust and urgency rather than a malicious link, which is why it slips past spam filters and staff who are only trained to look for bad grammar.
What bank tools should every small business turn on?
Ask your business bank about Positive Pay for checks, ACH debit blocks or filters that only allow pre-approved originators, and multi-user controls that require dual approval on outgoing payments. Most banks offer these, and many owners never activate them. They are among the cheapest and highest-impact protections available.
We got hit by a fraudulent wire. Can we get the money back?
Sometimes, if you move fast. Call your bank immediately to request a wire recall or ACH return, then file with the FBI's IC3 at ic3.gov, whose Recovery Asset Team can help freeze domestic funds. Recovery odds drop sharply after the first 24 to 72 hours, so speed matters more than anything else.
Does business insurance cover fraud losses?
Not automatically. Many general policies exclude losses where an employee was tricked into voluntarily sending funds. Look specifically for crime coverage with a social-engineering or fraudulent-instruction endorsement, and read the conditions, since some require that you had verification procedures in place. Confirm your terms before you need them, not after.
How do I protect cash flow if a fraud loss creates a working-capital gap?
Treat it as a short-term cash-flow problem and bridge the gap with funding that underwrites on revenue rather than credit. Revenue-based funding marketplaces approve based on bank deposits and top-line revenue, typically from around $10,000, accept FICO from roughly 500 up, and can fund in about 24 to 48 hours. Size the funding to the gap and repay from ongoing receipts.
Are 'guaranteed approval' funding offers safe to use after a fraud loss?
No. No legitimate funder guarantees approval, because every responsible lender or marketplace still reviews your bank activity and revenue first. 'Guaranteed approval,' upfront fees before any funding, and pressure to act immediately are classic advance-fee fraud signals, exactly the kind of scam you are trying to recover from. Work only with funders who verify before they commit.
Who on my team should be allowed to approve payments?
Separate the duties. The person who sets up or edits vendors should not be the same person who approves and releases payments to them, and any payment above a set threshold should require two people. Just as important, give AP staff explicit written authority to pause any payment for verification without fear of blame, since fraud relies on employees feeling they cannot slow down.
