Invoice Fraud: What Should Your Contracts Say?

Alex Solo
byAlex Solo10 min read

A customer receives an invoice from your business, pays it and moves on, thinking everything has been settled. A few days later, you send them a gentle reminder that payment is still outstanding - only for them to tell you they’ve already paid.

When you check, the money has been sent - just not to your account.

This can happen through invoice fraud or business email compromise (BEC), where a scammer interferes with legitimate payment communications and redirects the customer’s payment to a different bank account.

It’s a stressful situation for everyone involved. Who is responsible for the missing payment? What happens next? And, more importantly, what can your business do to reduce the risk of it happening in the first place?

Who Is Responsible If The Payment Goes To A Scammer?

Unfortunately, there isn’t one simple answer.

If your customer pays an invoice using fraudulent bank details, it doesn’t automatically mean they need to pay you again. On the other hand, the fact that your business never received the money doesn’t necessarily mean your business will always have to absorb the loss either.

In the US, the answer can depend on the law that applies to the transaction, what your contract says, how the fraud happened and what each party did before the payment was made.

A useful example is Beau Townsend Ford Lincoln, Inc. v. Don Hinds Ford, Inc., 759 F. App’x 348 (6th Cir. 2018).

In that case, one Ford dealership agreed to buy vehicles worth more than $736,000 from another. A hacker had accessed the seller’s email account and, once the conversation moved to payment, sent fraudulent wire instructions. The buyer followed those instructions and transferred the money, believing it was paying the seller.

The seller had never received the payment and argued that the buyer still owed the money. The district court initially agreed, but the Sixth Circuit reversed that decision and sent the case back for further fact-finding. Applying Ohio law, the court said the circumstances needed closer consideration, including each party’s conduct and which party was in the better position to prevent the fraud.

Beau Townsend was an unpublished Sixth Circuit decision applying Ohio law, so it shouldn’t be treated as a rule that automatically decides invoice fraud disputes across the US. It does, however, demonstrate why these situations can become much more complicated than simply asking whether the money reached the right account.

More recently, the Sixth Circuit considered another payment fraud case in Schultz Excavating & Asphalt of Ludington, LLC v. Smyrna Ready Mix Concrete, LLC, No. 25-1038 (6th Cir. 2025). A fraudster convinced a business to change the payee and mailing address for payments, resulting in more than $267,000 being sent to the wrong party. Applying Michigan law, the court upheld a finding against the paying business after it made the significant change without verifying it with the other party.

Importantly, the court also found that questionable cybersecurity practices on the other side were not enough on their own to shift responsibility. For those practices to affect the allocation of the loss under the law being applied in that case, they needed to have actually contributed to the loss.

The takeaway for businesses isn’t that one side will always be responsible. It’s that clear payment processes, sensible security measures and properly drafted contracts can all matter when something goes wrong.

Reduce The Risk Before A Payment Is Made

Ideally, your business never gets to the point where it needs to work out who should bear the loss.

Contracts are an important safeguard, but they shouldn’t be your only one. Businesses should also have sensible processes in place to protect the accounts and systems used to communicate with customers and process payments.

For example, email accounts used to send invoices should have appropriate security measures in place. Depending on your business, this might include multi-factor authentication, appropriate access controls and limiting who can change financial or payment information.

Your payment process matters too.

If your bank details change, there should be a consistent way of communicating that change to customers. Unexpected changes to payment instructions can also be verified through another trusted channel rather than relying solely on the message requesting the change.

The FBI recommends multi-factor authentication and specifically advises businesses to verify payment requests and changes to account numbers or payment procedures, including by independently contacting the person making the request.

The same thinking should apply internally. If several employees can send invoices, update bank details or communicate with customers about payments, they should understand what the correct process is and what to do if something looks unusual.

That doesn’t mean turning every invoice into a ten-step security exercise. It simply means treating unexpected changes involving money with an appropriate level of caution.

Protect The Information Behind The Payment

Invoice fraud can also expose a broader issue: how well your business protects the information it holds.

A compromised inbox may contain much more than an invoice. Depending on your business, it could contain customer names, email addresses, contracts, account information or other personal information.

That makes data security something to think about before a breach occurs, rather than only once you need to work out whether anyone needs to be notified.

There isn’t one single US privacy and data security law that applies to every business in exactly the same way. Federal, state and sector-specific requirements can all come into play depending on your business and the information you handle.

For example, California Civil Code § 1798.81.5 requires businesses that own, license or maintain personal information about California residents to implement and maintain reasonable security procedures and practices appropriate to the nature of that information.

New York’s SHIELD Act also requires businesses maintaining covered private information to have administrative, technical and physical safeguards. The New York Attorney General identifies measures such as assessing foreseeable risks, training employees, assessing systems and information handling, detecting and responding to attacks and regularly testing key controls.

At the federal level, the Federal Trade Commission has also used Section 5 of the FTC Act, which prohibits unfair or deceptive acts or practices, in privacy and data security enforcement. Businesses should therefore be careful that any representations they make about how customer information is protected reflect what actually happens in practice.

The FTC also recommends that businesses understand what personal information they hold, how it moves through the business and who can access it, rather than collecting and storing sensitive information without considering the security implications.

Your legal documents form part of that wider picture too. If your business collects personal information, a properly tailored Privacy Policy can explain how that information is collected, used and handled. Your actual security and data practices still need to match what those documents say. Sprintlaw’s guide to a Privacy Compliance Review looks more closely at how US businesses can review their data practices, notices and state privacy obligations.

If personal information is compromised despite those safeguards, separate state or sector-specific breach notification obligations may also apply. That is a different question from who bears the loss of the fraudulent payment, and businesses shouldn’t assume resolving the payment issue resolves any privacy or data security obligations as well.

What Should Your Contracts And Payment Terms Say?

Once you have sensible payment and security processes in place, your contracts should support them.

Depending on how your business operates, your customer contract might explain which payment methods you accept, how customers should make payments, how legitimate changes to payment details will be communicated and what steps should be followed if payment instructions unexpectedly change.

For a service business, for example, a well-drafted Service Agreement can establish clear terms around fees and payments alongside the other rules governing the customer relationship. You can also read our Service Agreement Checklist For US Small Businesses for a broader look at what these agreements can cover.

Payment provisions might also address when payment is treated as made or received, how changes to account details are authenticated and what parties should do if they suspect that a payment communication or account has been compromised.

The aim, however, shouldn’t simply be to write a clause transferring every possible fraud loss onto your customer.

Clear payment terms can also help prevent fraud. If customers know your business follows a particular process whenever bank details change, an email asking them to follow a completely different process is more likely to stand out.

Your legal documents should match what happens in practice too.

If your contract says that bank details will only ever be changed through a particular verification process, but your team regularly changes them informally by email, the safeguard becomes much less useful.

Similarly, if customers transact with you online, your online terms need to properly reflect the customer journey and how payments actually work. Our article on Website Terms Of Service looks at some of the broader mistakes US businesses can make when their online terms don’t match how they operate.

There also isn’t a one-size-fits-all payment clause that will suit every business. A consulting company sending five-figure invoices by bank transfer faces different risks from an ecommerce store accepting card payments at checkout.

This is why your contracts and payment terms should be tailored to the way your business actually operates. Rather than relying on generic wording, having a legal expert assist with Contract Drafting can help make sure the clauses reflect your customers, payment process, business model and relevant legal requirements. Sprintlaw’s Contract Drafting service specifically takes into account the parties, commercial terms, workflow and practical risks involved.

If you already have agreements in place, a Business Contract Review can also help identify whether your existing payment provisions and other commercial terms are doing what you expect them to do.

The important thing is to get those safeguards in place before a payment disappears, rather than discovering afterwards that your contract and actual payment process tell two different stories.

What If Invoice Fraud Has Already Happened?

Even businesses with strong safeguards can still be targeted.

If you discover that a payment has been redirected, acting quickly and sensibly is important. The FBI recommends contacting the relevant financial institution immediately, as well as reporting BEC incidents to the FBI’s Internet Crime Complaint Center where appropriate.

From your business’s perspective, you’ll also want to establish what happened. That can include securing potentially compromised accounts, preserving relevant records and checking whether your business systems or customer information were affected.

If personal information was accessed, that may raise separate privacy, security or breach notification obligations under applicable laws. For example, New York’s SHIELD Act includes both reasonable safeguard requirements and notification obligations for qualifying breaches involving covered private information.

You should also review your contract and agreed payment procedures before making assumptions about the legal position.

Where there is uncertainty about your business’s rights or obligations, legal advice can help you understand what the contract requires and what other laws may be relevant. The answer will depend heavily on the particular circumstances, so this is one area where a generic rule is unlikely to be very helpful.

There’s Also The Customer Relationship To Consider

The legal issues surrounding invoice fraud don’t necessarily stop with the missing payment.

If your business systems or customer information were compromised, applicable privacy and data security laws may need to be considered. As we’ve seen, some state laws expressly require reasonable safeguards for certain personal information, while the FTC can take action against unfair or deceptive privacy and security practices under Section 5 of the FTC Act.

It’s also worth looking at what your business has told customers. If your Privacy Policy, customer terms or other communications make particular statements about security or payment processes, your actual practices should be consistent with them.

Then there is the commercial side.

If a customer genuinely believed they were following payment instructions from your business, it generally makes sense to understand what happened before immediately treating the situation as an ordinary unpaid invoice.

That doesn’t mean your business is automatically responsible for the loss, nor does it mean a customer can never be required to make another payment. As Beau Townsend and Schultz demonstrate, the legal position can depend heavily on the particular facts and applicable state law.

It simply means there may be several things to consider at once - your contractual rights, any privacy or security obligations, what actually contributed to the fraud and the ongoing customer relationship.

Having clear processes and properly drafted legal documents in place beforehand can make all of those questions easier to navigate.

Key Takeaways

Invoice fraud can turn an ordinary customer payment into a surprisingly complicated legal problem.

There isn’t one clause that can make the risk disappear, and contracts shouldn’t be treated as a way to simply push responsibility onto your customers.

Businesses are better protected when sensible security measures, clear payment procedures and properly drafted contracts all work together. Protect the accounts and information your business relies on, make unusual payment changes easy to verify and ensure your contracts, payment terms, online terms and privacy documents accurately reflect the way your business actually operates.

Most importantly, these documents should be tailored to your business rather than copied from a generic template. Having them prepared or reviewed by a legal expert can help make sure your legal safeguards do what you expect them to do.

That way, your contracts aren’t simply there to work out who takes the blame after fraud happens. They form part of a broader system designed to reduce the risk in the first place and protect both your business and your customers.

If you need help putting the right safeguards in place, Sprintlaw can help with contract drafting, contract reviews, customer agreements, online terms and privacy documents. You can reach us at 1800 730 617 or team@sprintlaw.com.au for a free, no-obligations chat

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw's co-founder and a legal technology leader. He holds law and media degrees from the University of Sydney and has been recognized by Australasian Lawyer, Lawyers Weekly and the Sydney Young Entrepreneur Awards for his work building Sprintlaw and improving access to business legal support.

Need legal help?

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Keep reading

Related Articles

Joint Venture Clauses US Businesses Should Understand

Joint Venture Clauses US Businesses Should Understand

Joint ventures offer US businesses a way to collaborate, but missing or unclear contract clauses can lead to disputes or unexpected liabilities. This guide explains the essential joint venture clauses, practical examples, and state-law caveats to help you avoid common mistakes.

Aug 21, 2026
Read more
Joint Venture Checklist For Startups And Small Businesses

Joint Venture Checklist For Startups And Small Businesses

Considering a joint venture? This guide provides a detailed checklist, practical examples, and key legal points for US startups and small businesses before entering a joint venture agreement.

Aug 21, 2026
Read more
Joint Venture Agreement: What To Review Before Signing

Joint Venture Agreement: What To Review Before Signing

Before signing a joint venture agreement, US founders should check the purpose, contributions, profit-sharing, liability, and dispute resolution terms. This guide details what to review, state law caveats, and practical steps to avoid common mistakes.

Aug 21, 2026
Read more
Joint Venture Agreement Negotiation Points For Growing US Companies

Joint Venture Agreement Negotiation Points For Growing US Companies

Joint venture agreements help US businesses combine strengths for new projects, but unclear terms can lead to disputes. This guide explains key negotiation points, state law differences, and practical steps for founders and operators.

Aug 21, 2026
Read more
Common Manufacturing Agreement Mistakes That Create Contract Risk

Common Manufacturing Agreement Mistakes That Create Contract Risk

Manufacturing agreements often expose US startups and small businesses to hidden risks if not carefully reviewed. This guide covers the most frequent mistakes, state law caveats, and practical steps to help you avoid costly contract errors.

Aug 21, 2026
Read more
Common Marketing Service Agreement Mistakes That Create Contract Risk

Common Marketing Service Agreement Mistakes That Create Contract Risk

Many US businesses make preventable mistakes in their marketing service agreements, leading to unclear deliverables, payment disputes, and regulatory headaches. This guide breaks down practical contract errors, state law caveats, and how to protect your business.

Aug 21, 2026
Read more
Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.