Purchase Order Fraud: Anatomy of a Fake PO
Invoice fraud targets the buyer; purchase order fraud targets the supplier. An illustrative look at how a fake PO ships goods on credit that will never be paid for — and where it breaks.

In this case study
Invoice fraud gets all the attention, but there's a mirror-image scam that targets the supplier instead of the buyer, and it's grown up alongside e-commerce and net-terms selling. It's purchase order fraud: a fraudster poses as a trusted organization, sends a legitimate-looking PO, and walks away with goods shipped on credit that will never be paid for. The following is an illustrative scenario — no real company — that shows how the scheme runs and where it breaks.
The challenge
Imagine a mid-sized electronics distributor that sells on net-30 terms to businesses, schools, and government buyers. One morning a purchase order arrives by email, apparently from a well-known university, ordering roughly $40,000 of laptops. Everything looks right: the university's logo, a plausible PO number, a real-sounding procurement contact, a shipping address, and net-30 terms — standard for an institution like this.
The distributor's sales team is thrilled. A big order from a reputable buyer, on the terms that buyer would normally get. The pressure is to ship fast and lock in the sale. And that pressure is exactly what the scheme is built on. Because if the PO is fraudulent, the goods ship to an address the fraudster controls, the net-30 clock runs out with no payment, and the real university has never heard of the order. The distributor is out the product and the money.
The distributor's problem isn't that they can't read a PO. It's that a fraudulent PO and a real one look identical at the moment of decision — and the decision is being made by people incentivized to say yes.
The approach
The fix wasn't to distrust every order. It was to make a few verifications mandatory before goods ship on credit to a new or unusual buyer — turning "the PO looked official" into "we confirmed it independently."
Authenticate the document. The PO is the fraudster's main instrument, and a forged one carries tells. The team started running incoming purchase orders — especially large ones on credit — through a document check that flags a logo pasted at the wrong resolution, fonts that don't match across the form, a PO whose metadata shows it was authored in a PDF editor rather than exported from a real procurement system, and templates reused across supposedly unrelated buyers.
Verify the buyer out-of-band. The single most important step: confirm the order using contact details obtained independently — the institution's real, published procurement office — not the phone or email on the PO itself. Fraudsters put their own "verify here" contact right on the document. A call to the real buyer ends the scam instantly, because the real buyer never placed the order.
Match the shipping and billing story. Legitimate institutional orders usually ship to the institution, not to a residential address, a freight forwarder, or a newly rented unit. A mismatch between a reputable buyer and an odd delivery destination became an automatic hold.
Scrutinize new-buyer credit. First-time buyers requesting net terms on a large order got extra verification before any credit shipment — the same discipline as vendor onboarding, applied to the buying side.
The results
In this illustrative case, the change didn't slow down legitimate business in any way customers noticed — real buyers confirm easily, ship to expected addresses, and send POs that pass a document check. What it stopped was the specific, expensive failure mode: shipping goods on credit against a document nobody had verified.
The economics are lopsided in the defender's favor, which is the whole point. A verification call and a document check cost minutes. A single successful PO fraud costs the entire order — product gone, no payment coming, and often a chargeback or clawback fight on top. Stopping even a handful of these a year pays for the process many times over.
Lessons learned
- The PO is a claim, not a credential. An official-looking purchase order proves nothing on its own; it's the easiest part of the scheme to fake.
- Out-of-band verification is the whole defense. Confirm large or first-time credit orders with the buyer using contact details you found independently — never the ones printed on the document.
- Watch the shipping address. A reputable buyer with an odd delivery destination is one of the most reliable tells.
- Put the checks before the ship, not after. Once goods leave on credit against a fake PO, recovery is unlikely. The verification has to gate the shipment, not follow it.
- Match effort to exposure. Small, established, prepaid orders don't need the full treatment. Large credit shipments to new or unusual buyers do.
Purchase order fraud works because it points a business's own eagerness to sell against it. The counter is unglamorous and completely effective: treat a PO as a document to authenticate and a buyer to verify, especially when the order is large, the buyer is new, and the terms are credit.
Put it to the test
Scan a document and get a plain-English verdict in seconds. Free to start.
Keep reading
The Padlock Lies: What HTTPS Actually Proves
The padlock is the most misunderstood symbol on the internet. It certifies the pipe, not the shop — and almost every phishing page you will ever see has one.
9 Invoice Fraud Red Flags Every AP Team Should Check
The nine warning signs accounts-payable teams see over and over in fraudulent invoices — and the two-minute checks that catch each one before payment goes out.
How to Verify a Notarized Document (and Spot a Fake Stamp)
A notary seal is an ink impression, and ink is easy to fake. The trust belongs to the commission record, not the stamp. How to check whether a notarization really happened.