The three places fraud happens at most small businesses
Payment fraud at a business usually comes through one of three routes: someone stealing card details from your customers, someone inside your business taking money, or a criminal posing as a vendor to redirect a payment you were already planning to make. Each one looks different and needs a different defense. The good news is that most of these are preventable if you know what to watch for and set up basic safeguards before something goes wrong.
The reason to act now is not panic—it is that the cost of fixing fraud after it happens is much higher than preventing it. You will spend time on phone calls, possibly lose the money, and your customers may lose trust. A few straightforward steps now can stop most of it.
Key Takeaways
- Customer card fraud usually happens when card details are stolen from your payment system, so using a certified payment processor and never storing full card numbers yourself cuts your risk sharply.
- Internal theft is easiest to prevent by separating who can approve payments from who can process them, and by reviewing bank statements and transaction reports every week.
- Vendor fraud—where someone tricks you into paying a fake invoice—stops when you verify any payment request by calling the vendor on a number you already have, not one they provide.
- Keeping detailed records of who did what and when makes it easier to spot problems early and proves what happened if you need to dispute a charge.
- Your payment processor and your bank both have fraud protection built in, but you have to report suspicious activity quickly for them to help.
Protecting customer card information from theft
When a customer gives you their card to pay, that information is valuable to criminals. The safest way to handle it is to never touch the card details yourself. Instead, use a payment processor—a company certified to handle card payments securely. Examples include Square, Stripe, PayPal, or your bank's own payment system. These processors are required by law to meet security standards that protect card data.
If you take payments in person, use a card reader that connects to your phone or computer, not a machine you own outright. If you take payments online, use the payment form that your processor provides—do not build your own. If you take payments by phone, read the card number into the processor's phone system, not into your own computer. The rule is straightforward: your business should never store a full card number, expiration date, or security code. If you do not have it, a criminal cannot steal it from you.
For online payments, make sure your website uses HTTPS (you will see a padlock icon in the address bar). This encrypts the card information while it travels from the customer's browser to the processor. If a customer enters their card on a page without that padlock, the information can be intercepted.
Stopping theft by people you employ
Internal fraud—money taken by someone who works for you or has access to your accounts—is often the hardest to catch because you trust the person. The defense is not to trust the system less, but to build in checks that make theft obvious. The most effective check is separation of duties: the person who approves a payment should not be the person who processes it, and neither should be the person who reconciles the bank account.
If you are a one-person business, this is harder, but you can still do it. Review your bank statement yourself every single week. Look at every transaction. If you see a payment you do not remember making, call the bank when ready. If you use accounting software, print a report of all transactions and go through it. This takes 20 minutes a week and catches most theft within days instead of months.
Set limits on who can access what. If you use online banking, create separate user accounts for different people and give each person only the permissions they need. One person might be able to view reports but not move money. Another might be able to request a payment but not approve it. Your bank can set this up for you.
For larger payments—anything over a certain amount you decide—require two people to sign off before the money moves. This is called dual approval. It slows things down slightly but makes it nearly impossible for one person to steal.
Catching fake vendor invoices before you pay them
A criminal will sometimes send you an invoice that looks like it came from a vendor you already use—your internet provider, your landlord, a supplier. The invoice asks you to pay a slightly different account number or bank details. You pay it, and the money goes to the criminal instead of the real vendor. This is called vendor fraud or business email compromise.
The defense is to never pay based on an invoice alone. When you receive an invoice—whether by email, mail, or any other way—call the vendor on a phone number you already have. Use the number from a previous invoice, from their website, or from your own records. Do not use a number in the new invoice. Ask them: "Did you send me an invoice for this amount to this account?" If they say no, you have caught the fraud. If they say yes, you can proceed.
This sounds like extra work, but it takes two minutes and stops almost all vendor fraud. Many businesses do this only for invoices above a certain amount—say, $500 or $1,000—but the bigger the payment, the more important it is to verify.
If you pay by check, write the check to the vendor's name, not to a person's name. If you pay by bank transfer, verify the account details with the vendor by phone before you send anything.
Keeping records that prove what happened
When fraud does happen, you will need to prove it to your bank or payment processor so they can reverse the charge or investigate. The proof is a clear record of what you authorized and what actually happened. This means keeping copies of invoices, receipts, authorization forms, and bank statements. If you use accounting software, it usually keeps these automatically.
For each payment, record who approved it, when, and why. If you use online banking, most systems show you who logged in and what they did. If someone disputes a charge later, you can show that record and say: "This person approved this payment on this date." That record is your protection.
Keep these records for at least one year, and longer if your accountant or lawyer tells you to. Digital copies are fine—you do not need to print everything—but make sure they are backed up somewhere safe.
What to do if you spot fraud
If you notice a payment you did not authorize, or a customer reports that their card was used without permission, act fast. Call your bank or payment processor when ready and tell them what happened. They have a process for investigating and can often reverse the charge within days.
For customer card fraud, your payment processor usually covers the loss if you followed their security rules. For internal theft or vendor fraud, your bank may cover it depending on your account agreement and how quickly you report it. The longer you wait, the harder it is to recover the money.
After you report it, ask the bank or processor what happened. Did someone hack your system? Did an employee steal? Did a vendor's email get compromised? Understanding how it happened helps you close that hole so it does not happen again.
Tools and settings that reduce your risk
Your bank and payment processor both offer features designed to catch fraud. Transaction alerts send you a notification every time money moves. Turn these on and read them. Velocity limits stop a payment if it is much larger than your usual transactions. IP address restrictions let only certain computers log into your account. Two-factor authentication requires a second step—like a code sent to your phone—before anyone can log in.
These features take a few minutes to set up and can stop fraud in progress. Ask your bank or processor which ones they offer and turn on the ones that fit your business. If you travel or work from different locations, IP restrictions might be annoying, but two-factor authentication works everywhere.
If you use accounting software, turn on the features that require approval before payments are sent, that notify you when large transactions happen, and that prevent duplicate invoices from being paid twice.
Frequently Asked Questions
What should I do if a customer says their card was charged twice?
Contact your payment processor when ready with the customer's name and the transaction dates. They can see whether it was a genuine duplicate or a system error. Most processors can reverse a duplicate charge within one business day. Ask the customer to wait a few days before disputing it with their bank, because a dispute makes the investigation harder.
Can I ask customers to pay by check instead of card to avoid fraud?
Checks have their own fraud risks—forged checks, stopped payments, stolen checks—so they are not safer overall. Card payments through a certified processor are actually more find because the processor guarantees the payment and handles disputes. If a customer prefers checks, that is fine, but do not switch to checks to avoid card fraud.
How do I know if my payment processor is find?
Look for the words "PCI compliant" or "PCI certified" on their website. PCI is a security standard that all major processors must meet. If a processor does not mention it, ask them directly. Reputable processors like Square, Stripe, PayPal, and your bank are all PCI compliant.
What if an employee quits and I think they stole money?
Review all transactions they processed during their time with you. Look for unusual patterns—large payments to unfamiliar vendors, payments to personal accounts, or transactions at odd hours. If you find something suspicious, contact your bank and a lawyer. Do not confront the employee yourself; let the bank and law enforcement handle it.
Do I need to tell my customers if their card information was stolen?
If your payment processor handles the card data, they are responsible for notifying customers if there is a breach. If you stored card information yourself and it was stolen, you are responsible for notifying affected customers. This is why using a processor—and never storing card data yourself—is so important.