Invoice fraud in the Mittelstand: how to protect yourself
Protect your company against invoice fraud. Learn how CEO fraud and payment diversion fraud work and which controls really do the job.

The risk for the Mittelstand: the invisible danger
The German Mittelstand is in the crosshairs of highly professional economic criminals. Invoice fraud has long since stopped being a purely IT challenge. It is a threat to the very existence of the entire company. Fraudsters use sophisticated psychological tricks and deceptively realistic forgeries to have funds siphoned straight out of your business account. These attacks hit home in mid-sized companies in particular, because lean structures and fast decision making often come at the expense of strict verification processes.
Just how serious the threat is can be seen in current figures from the loss statistics compiled by Allianz Trade. Losses from the so-called Fake President scheme tripled in the Allianz Trade loss statistics in 2024, which corresponds to an increase of 200 per cent, and climbed by a further 81 per cent in 2025. The number of reported cases fell over the same period, by 12 per cent in 2024 and by 13 per cent in 2025. Individual losses are therefore considerably higher than they used to be[1]. Criminals today use readily available, highly precise tools to spy out your working routines, communication channels and internal responsibilities down to the smallest detail. With flawless, tailor-made emails or synthetically cloned voices, they create an extremely high level of trust that even trained employees fall for. As a managing director or IT manager, you therefore have to recognise that digital security and organisational vigilance are inseparable.
There are three key weak points that explain why mid-sized companies in particular are in the fraudsters' sights:
- Direct communication channels: flat hierarchies encourage direct exchange, but under pressure they often mean that instructions from supposed superiors are carried out without being checked.
- Lack of verification: without automated review processes for new bank details or changed invoice data, the fraud goes unnoticed until the next audit.
- Overstretched teams: IT managers are permanently under pressure, so proactive monitoring of anomalies in email traffic falls by the wayside.
Conventional protective measures are no longer enough to counter this invisible danger effectively. If you want to shield your company from such devastating losses in the long term, you need to treat IT security as a matter for the boss and establish both technical barriers and organisational controls. Modern cybersecurity for the Mittelstand combines real-time monitoring with seamless digital verification of documents and communication channels in order to block suspicious patterns immediately, before any damage occurs.
CEO fraud: the scheme with the fake boss
CEO fraud, also known as Fake President fraud, is one of the most dangerous social engineering methods. In this scheme, criminals impersonate your managing director or another senior decision maker in order to pressure staff in the accounting department into making an urgent and supposedly strictly confidential special transfer. A fictitious company acquisition or a secret investment abroad is often used as the pretext. Over a period of days, the attackers deliberately build up psychological pressure in order to bypass your company's established internal control processes.
These attacks are becoming more professional, partly because attackers are deploying AI tools. According to the Allianz Trade loss statistics, the number of CEO fraud cases in Germany rose by 31 per cent in 2023[2]. You should assess the role of AI soberly: in the FBI IC3 Internet Crime Report 2025, business email compromise accounted for 3,046,598,558 US dollars in losses across 24,768 complaints. Only 30,256,592 US dollars across 135 complaints were explicitly recorded as AI-related, which is around one per cent of the BEC loss total. Because those affected often do not even recognise the use of AI, the number of unreported cases is high here. Above all, AI lowers the barriers for attackers, but it is not the proven main driver of the loss totals. Perpetrators use sophisticated AI-supported tools to imitate the writing style of executives perfectly or to generate deceptively realistic emails. Using so-called voice cloning, they can even reproduce your boss's voice on the phone true to the original, which drastically lowers the barriers to successful attacks[2]. For your staff, this makes it almost impossible to spot the forgery by instinct alone.
- Making contact: the attacker usually gets in touch by email for an apparently business-related reason and demands absolute secrecy.
- Building trust and applying pressure: an urgent emergency or a time-critical deal is faked in order to force quick action.
- Verification by deepfake: additional calls with cloned voices confirm the urgency and remove the employee's last doubts.
- Payout: the money is transferred to a foreign beneficiary account and immediately passed on from there through several stations.
Simply trusting in the alertness of your workforce is not enough to protect your mid-sized business effectively against such existential losses. Robust technical protection of your communication channels through modern cybersecurity is indispensable. As a managing director, you also bear the legal responsibility for introducing organisational protective measures in order to avert financial losses and liability risks for your company. With clear approval processes, the four eyes principle (dual control) and targeted training on fraud prevention, you make your business resilient against these manipulative attacks.
Payment diversion fraud: when the invoice is manipulated
While CEO fraud exploits the internal hierarchy, payment diversion fraud, also known as payment redirect, targets the interface with your external partners. Criminals intercept the communication with your service providers or hack their email accounts in order to manipulate real business transactions for financial gain. They inform your accounting department about supposedly new bank details for future transfers. Because the sender and the subject line often look deceptively genuine, the change is frequently entered in the system without being checked. The next regular payment then does not go to your trusted supplier, but straight into an account belonging to the fraudsters.
The typical course of a payment redirect usually unfolds in four discreet phases:
- Infiltration of email traffic: the attackers gain access to the email account of a supplier or register a domain with an extremely similar spelling.
- Monitoring the transactions: they read along quietly for weeks in order to analyse open quotations, invoicing cycles and the partners' communication style in detail.
- The forged payment request: as soon as a genuine invoice falls due, the perpetrators send a manipulated document or a covering letter referring to a supposed change of account due to a tax audit or a change of bank.
- The undetected diversion of funds: your employees transfer the outstanding amount to the new IBAN in good faith, after which the money is immediately moved abroad and laundered.
This fraud is usually only discovered weeks later, when the genuine partner chases the missing payment. For managing directors of mid-sized companies this causes substantial financial losses, because the service that was provided still has to be paid for. Purely organisational guidelines are often not enough to minimise this risk. Robust cybersecurity forms the technical foundation for filtering out manipulated sender addresses and suspicious emails at an early stage, before they reach your accounting department. In addition, raising your employees' awareness through ongoing training protects them from falling for these sophisticated deceptions.
Economic crime in figures: losses in the millions
Economic crime is no longer an abstract risk for the German Mittelstand, but a real threat to your company's liquidity. Losses from cybercrime and social engineering reach new record levels every year. According to the 2025 Wirtschaftsschutz study by the industry association Bitkom, for which 1,002 companies with 10 or more employees were surveyed, the annual total loss from data theft, sabotage and espionage in Germany adds up to 289.2 billion euros. Of that, 202.4 billion euros are attributable to cyber attacks, and 87 per cent of companies were affected. This sum is explicitly not a fraud loss: Bitkom puts the direct outflow of money caused by fraud attempts at 0.9 billion euros. Invoice fraud therefore rarely shows up in the large overall total, but in individual cases it hits your liquidity directly. For context: the payment fraud report by the EBA and the ECB shows 4.2 billion euros of payment fraud across the entire European Economic Area for the 2024 data year, of which 2.5 billion euros related to credit transfers. Germany accounts for 474,164,942 euros of credit transfer fraud.
For you as a managing director or IT manager, this dynamic shows that conventional protective measures are no longer sufficient. Fraudsters exploit increasing digitalisation to hook into communications in a targeted way. Once sensitive financial data is spied out or communication channels are compromised, the step to CEO fraud or payment diversion fraud is a small one. The financial consequences often hit the core capital of SMEs directly, because insurers can refuse to settle claims where internal due diligence was lacking. That is why IT security has to be understood as a matter for the boss, in order to avert losses that threaten the company's existence.
Focusing purely on firewalls falls short if you want to protect your business effectively against these professionalised gangs. Modern protection calls for proactive controls, continuous employee training and automated verification processes for critical financial transactions. With a strong partner at your side who provides specialised cybersecurity for the Mittelstand as well as automatic detection procedures for fraudulent documents and emails, you close the gaps before attackers can exploit them. That is how you establish a reliable barrier against social engineering attacks in day-to-day business.
The underestimated danger: insider perpetrators and internal weak points
When you think about cyber risks for your mid-sized business, professional hacker gangs usually come to mind first. Yet the reality of economic protection paints a different picture: a considerable share of serious security incidents is caused by your own employees, whether through a lack of care with phishing emails, deliberate sabotage or the unauthorised extraction of sensitive data. In the Allianz Trade loss statistics, around 60 per cent of loss events are attributable to insider perpetrators, and in 2025 they were responsible for 65 per cent of the largest losses. These insider perpetrators know your internal processes, hold legitimate access rights in the company network and know exactly where the most sensitive trade secrets are. A clean separation of terms is important here: the ACFE Report to the Nations 2026 measures pure insider wrongdoing and reports a median loss of 104,000 US dollars and a median duration of 12 months until detection. Companies with fewer than 100 employees are hit hardest, with a median loss of 126,000 US dollars. These figures describe embezzlement inside the company and not CEO fraud or invoice fraud from outside.
Why classic security walls often fail internally
Many managing directors and IT managers rely primarily on external defence systems at the network perimeter. Yet genuine cybersecurity for the Mittelstand has to close both technical and organisational weak points. If passwords are shared unprotected within the team, or the four eyes principle (dual control) is missing for financial transactions, even the best firewall is useless. Weak passwords and the absence of multi-factor authentication throw the doors wide open for fraudsters who use refined social engineering tactics such as CEO fraud. A working system of clear control instances and continuous education massively reduces the risk of serious insider scenarios.
- Missing separation of duties in the approval of payments
- Excessively broad user rights in the network (a breach of the principle of least privilege)
- Shared passwords or unprotected administrative accounts without multi-factor authentication
- Insufficient employee awareness of phishing and social engineering tactics
Fixing weak points only selectively is not enough to protect your business effectively against insider perpetrators. It requires a seamless link between Managed IT for proactive monitoring of all endpoints and strict policies for securing your business processes. Only if your employees are made aware through regular training, internal controls are firmly anchored in everyday work and technical anomalies are noticed immediately will you create a stable security foundation against attacks from inside and outside.
Technical controls: how cybersecurity and IT structures protect you
Technical barriers are the most important line of defence against fraudulent access to your digital infrastructure. Before an attacker can even confront your employees with manipulated messages for CEO fraud or payment diversion fraud, IT systems have to block forged senders. A central lever here is consistent email authentication via SPF, DKIM and DMARC. The Bundesamt für Sicherheit in der Informationstechnik (BSI, the German Federal Office for Information Security) officially recommends these protocols in order to prevent the spoofing of domain senders effectively and to secure the integrity of your email communication.
Alongside email protection, all access points to your systems have to be secured without gaps. Stolen credentials are still the main entry gate for criminal takeovers of mailboxes and accounts. Comprehensive multi-factor authentication (MFA) is therefore indispensable for every mid-sized company. It ensures that even if a password is compromised, no unauthorised access to your internal data or mailboxes succeeds. Combined with proactive endpoint management, you fend off attacks before they can do any damage.
- Email protection through standards: automatic validation of mail servers via SPF, DKIM and DMARC protects your business domains against misuse and spoofing.
- Strict access control: every login to critical systems and communication channels is reliably verified via a second, independent factor.
- Proactive patching: security vulnerabilities in your applications and operating systems are closed as standard and immediately, so that attackers are given no way in.
Configuring and monitoring these defence mechanisms professionally does, however, require specialised expertise. This is exactly where the services of CAVRIX come in. Through our integrated Cybersecurity and Managed IT services, we establish these technical controls as standard and without any administrative effort for your team. We monitor your IT infrastructure continuously in order to detect anomalies early, so that you as a managing director or IT manager always retain full control.
Procedural controls: the four eyes principle and verification
Technical defences form the foundation of your cybersecurity, but only consistent procedural controls fully close the entry point for skilful social engineering. Fraudsters deliberately use emotional triggers such as artificial time pressure or supposedly confidential special assignments from management in order to bypass established rules. That is why the Bundesamt für Sicherheit in der Informationstechnik (BSI, the German Federal Office for Information Security) explicitly recommends clear organisational rules for all critical approval processes alongside technical hardening. Only once your team has internalised fixed workflows do such manipulations fizzle out without effect.
The most important pillar against CEO fraud and invoice fraud is strict enforcement of the four eyes principle (dual control) for all financial transactions and master data changes. If an IBAN is adjusted in the system or an unusual payment is instructed, this must never be approved by a single person. This principle is complemented by a reliable verification chain that also directly addresses the risk of supply chain security.
- Out-of-band verification (OOB): if a supplier changes its bank details, this change has to be confirmed via a second communication channel. Call your contact on the telephone number you already know and that is stored in the system, instead of using the contact details from the current change notification email.
- Strict amount thresholds: define clear financial thresholds. Payments above a certain sum mandatorily require written countersigning by management, which in turn is validated by a call back.
- Secure approval process: integrate these approvals directly into your ERP and banking infrastructure. Avoid accepting payment data by email or chat message as a work instruction without checking it.
These procedural hurdles can be linked ideally with your technical systems. With intelligent role and permission concepts in identity and access management, you make sure that administrative privileges in ERP and banking systems remain strictly separated. Close coordination between your finance managers and your IT department ensures that organisational guidelines are enforced technologically. That is how you effectively protect your mid-sized company against losses that threaten its existence caused by fake invoices or forged instructions from the boss.
Frequently asked questions
What is the difference between CEO fraud and payment diversion fraud?
In CEO fraud, criminals pose as the managing director in order to pressure employees into making urgent transfers. In payment diversion fraud, they forge invoices or notifications about changed bank details, so that you transfer regular payments straight into the fraudsters' accounts.
How high are the losses from CEO fraud in the Mittelstand?
According to the Allianz Trade loss statistics, losses from Fake President attacks tripled in 2024 and rose by a further 81 per cent in 2025, while case numbers fell slightly in both years. Average losses are in the single-digit millions, while major losses reach the high double-digit millions.
What role do insider perpetrators play in invoice fraud?
Your own employees are an often underestimated danger. According to the Allianz Trade loss statistics, insider perpetrators cause around 60 per cent of loss events and were responsible for 65 per cent of the largest losses in 2025. Insider wrongdoing is, however, something different from CEO fraud or payment diversion fraud, which come from outside. Both risks need their own controls.
How does an out-of-band confirmation protect against payment diversion fraud?
An out-of-band confirmation requires you to verify every change of payment data or bank details via a separate communication channel. To do so, call the supplier on the telephone number you already know, instead of using the contact details from the new and possibly forged email.
Which technical controls should my company introduce immediately?
You should enforce phishing-resistant multi-factor authentication (MFA) for all accounts without delay. Verified email signatures, AI-based filters and a zero trust architecture also help to detect and block suspicious activity in the network at an early stage.
Are employees liable for losses caused by CEO fraud?
As a rule, employees are not fully liable for the resulting loss in cases of ordinary negligence. Employment law often provides liability privileges, which is why companies have to secure their protection primarily through technical and organisational processes instead of relying on liability.