Invoice Fraud Prevention: How to Protect Your Organisation

Invoice fraud is one of the fastest-growing threats to Nordic organisations. Nordic authorities reported losses over €50 million to CEO fraud and invoice fraud in 2025 — a 40% increase from the year before. And those numbers only capture what was reported.
The good news: modern procurement systems can stop most fraud attempts automatically. In this article we show the most common fraud types, how Vieri protects against them, and what you can do today.
Key takeaways
- • Nordic organisations lost €50M+ to invoice fraud in 2025
- • The most common attacks: fake invoices, changed bank accounts, CEO fraud, duplicate invoices
- • 3-way matching stops 70-80% of attempts automatically
- • AI + PEPPOL + strict approval rules = near zero risk
The 4 most common fraud types
1. Fake invoice (no delivery)
The scammer sends an invoice for a service or product that was never delivered. Often small amounts that go «under the radar» — €500-2500. Without 3-way matching against order and goods receipt, these often go through.
2. Changed bank account (supplier impersonation)
The attacker sends an email that appears to come from an existing supplier, claiming they've «changed banks». The next payment goes to the scammer's account. This is the most lucrative fraud — single amounts up to €500K-1M.
3. CEO fraud (business email compromise)
A fake email that appears to come from CEO/CFO asks an employee to «urgently pay» an invoice. Uses social tricks. Without an approval flow, individual employees can be manipulated.
4. Duplicate invoice
The same supplier sends the same invoice twice — sometimes with small variations in invoice number. Without a system that checks duplicates, both get paid.
How Vieri stops the fraud
| Fraud type | Vieri protection |
|---|---|
| Fake invoice | 3-way matching — no order = manual approval required |
| Changed bank account | Account changes require verification via another channel + two-person approval |
| CEO fraud | All payments follow approval flow — CEO cannot bypass |
| Duplicate invoice | AI detects duplicates based on amount + supplier + date |
PEPPOL as a fraud shield
An under-reported benefit of PEPPOL is security. An EHF invoice received via the PEPPOL network is cryptographically signed and verified by the supplier's access point. It's extremely hard to forge — unlike a PDF via email, which anyone can create.
10 actions you can take today
- Require PO for all purchases over €500
- Enable 3-way matching
- Introduce two-person approval for bank account changes
- Verify account changes by phone — never based on email alone
- Turn on duplicate alerts
- Set approval limits — no one approves above their limit
- Require PEPPOL/EHF from top-20 suppliers
- Monthly fraud review
- Train employees on CEO fraud
- Have a reporting routine
💡 Did you know?
Competing systems like Medius and Basware market fraud detection as separate products (Medius Fraud & Risk Detection, Basware AP Protect). Vieri has many of the same features built in as standard.
Protect your organisation from invoice fraud
Book a demo and see how Vieri stops fake invoices, account switches and CEO fraud automatically.
Book demo →

