The most dangerous invoice your business will see this year looks exactly like the most boring one. That’s the whole problem, and the H1 2026 numbers show how well it’s working.
Invoice fraud has been getting harder to catch for a while, and this year the data shows just how far it’s come. Trustmi analyzed the deliberate, intent-driven attacks of H1 2026 to see how they’re built: which documents show up, how often, and what they’re paired with. A few patterns came up again and again, and two were consistent enough that we named them. Here’s what the numbers reveal.
Invoice Fraud Statistics at a Glance (H1 2026)
- ~5x year-over-year growth in intent-driven payment fraud incidents
- 7 of 9 tracked attack patterns included a fake invoice
- 1 in 6 incidents paired a fake invoice with a fake W-9
- 193 incidents combined a fabricated email thread with a fake invoice, the single most common pattern
- ~250 incidents involved a faked executive approval (Ghost Executive)
- ~97 incidents used a false deadline to force payment (Deadline Deception), up from near-zero a year ago
- ~2 in 3 attacks graded at the highest sophistication tier
Volume Is Just Part of the Story
Across the first half of 2026, intent-driven payment fraud attempts rose roughly 5x year-over-year, from 119 incidents in H1 2025 to 597 this year. Those 597 aren’t everything we saw, they’re the deliberate attacks we tracked closely, the ones built to succeed, not the far larger volume of low-effort spam. That distinction matters, because it means the jump isn’t more junk mail hitting inboxes. It’s fraud good enough to move through real payment workflows.
What changed underneath the surge is that the fraud got harder to detect because it’s buried in paperwork.

Methodology: Based on Trustmi’s analysis of 597 intent-driven payment fraud attempts tracked in H1 2026 (January 1 to June 30). Figures reflect deliberate, targeted attacks, not high-volume, low-effort spam.
Invoice Fraud in Context
The jump didn’t come out of nowhere. Our last benchmark already showed fraud shifting toward using documents to blend into the payment process. H1 2026 is that same trend, accelerating. What’s different now is the AI-enabled scale.
These findings track with a broader shift. The Chartered Institute of Internal Auditors reports that chief internal auditors now rank AI and digital disruption as the fastest-rising risk category for business. The H1 2026 numbers are what that shift looks like inside real payment workflows, measured rather than predicted.
The Fake Invoice as a Constant
Of the nine attack patterns tracked in H1 2026, seven included a fake invoice. That’s the single most important number here, not because it’s dramatic, but because it marks a shift. A year ago, a fake invoice was one signal among many. Now it’s the closest thing payment fraud has to a constant.
It rarely travels alone. In roughly 1 in 6 incidents, the fake invoice arrived paired with a fake W-9, and the W-9 is where the story gets sharper. Normally it’s a routine onboarding document. This year, it increasingly showed up in compromised-vendor attacks, used to quietly change the bank details of a vendor a company already trusted, redirecting familiar payments to an attacker.
The takeaway isn’t “watch out for invoices.” It’s that the most ordinary paperwork in the building has become the most reliable place fraud hides.
Most Common Pattern: Half Invoice, Half Conversation
The single most common pattern in the data, 193 incidents, paired a fabricated email thread with a fake invoice. The invoice made the ask; the thread made it look already agreed.
Why does a fake conversation work so well? Because a thread reads as history. A recent survey of 1,000 employees found that 81% would trust a payment request that arrived inside an existing email thread. Attackers are building exactly what employees are most primed to trust, a conversation that looks like the decision was already made.
Two Attacks Behind the Numbers Earned Names
Enough of the H1 2026 activity clustered into two recognizable shapes that we named them.
Ghost Executive fraud fakes an executive’s approval, so a payment looks like a decision that’s already been made. It was the larger of the two, appearing in roughly 250 incidents, more than four in ten of the attempts analyzed.
Deadline Deception fraud pairs fraudulent paperwork with a false deadline to collapse the time anyone has to verify. It was virtually absent a year ago and surged to roughly 97 incidents by mid-year, the fastest-growing pattern we tracked.
We’re keeping the definitions short here on purpose. For the full breakdown of how each attack is built, and how to recognize one, see the Ghost Executive and Deadline Deception threat alert
The Takeaway: Fraudulent Paperwork Is a Problem
The pattern underneath every number is the same: fraud now hides in ordinary documents that clear a routine review. (We’ve covered how to identify fake invoices before.) What H1 2026 makes clear is that spotting these one document at a time no longer works. The signals that give an attack away, a first-seen bank account, a vendor with no history, a request that breaks pattern, only surface when a document is read against the full payment behind it.
And it isn’t crude work. Nearly every attack analyzed graded medium-to-high sophistication, with about two in three at the highest tier. That’s the real shift: the same fraud that was once easy to spot is now polished enough to pass. The full report is built around this: how to read a document in context, not in isolation.

Behavioral AI-powered security
Protection on day one
10-15x ROI