Business Fraud: Types, Red Flags, and Consequences

Business fraud generally sorts into three occupational categories committed from inside an organization — asset misappropriation, corruption, and financial statement fraud — plus a fast-growing set of external cyber schemes led by business email compromise, and understanding these types, their red flags, and the legal consequences that follow is essential because the same conduct can trigger criminal prosecution, civil suits, SEC penalties, IRS fraud penalties, and mandatory restitution all at once. The Association of Certified Fraud Examiners estimates that organizations lose roughly 5% of annual revenue to fraud, with a median loss of more than $1.5 million per case.1Association of Certified Fraud Examiners. ACFE Report to the Nations: Organizations Lost an Average of More Than $1.5M Per Fraud Case

The Three Categories of Occupational Fraud

Forensic accountants classify occupational fraud into three buckets, and each has a distinct profile. Asset misappropriation shows up in 89% of cases with a median loss of $120,000. Corruption appears in 48% of cases with a median loss of $200,000. Financial statement fraud accounts for only 5% of cases but causes a median loss of $766,000, making it by far the most expensive per incident.1Association of Certified Fraud Examiners. ACFE Report to the Nations: Organizations Lost an Average of More Than $1.5M Per Fraud Case

Asset Misappropriation

Asset misappropriation is the theft or misuse of company resources, and it takes several recognizable forms. Cash schemes include skimming, where an employee pockets a payment before it hits the books, and larceny, where cash is taken after being recorded, such as pulling money from a deposit or register. Skimming leaves no paper trail; larceny shows up as a discrepancy between recorded amounts and what is actually on hand.

Fraudulent disbursement schemes trick the company into issuing a payment it should not have made. Billing schemes involve a fake vendor invoicing for goods or services that were never delivered. Check tampering involves forging signatures or altering the payee name on a legitimate company check. Expense reimbursement fraud is submitting personal meals, trips, or purchases as business expenses. Payroll fraud ranges from inflating hours on timesheets to creating “ghost employees” whose paychecks are redirected to the perpetrator.

Inventory theft rounds out the category. An employee diverts physical goods for personal use or resale, or manipulates receiving records to show that goods were delivered when they were not. In warehouse-heavy businesses, this can go undetected for years without regular physical counts.

Corruption

Corruption schemes involve someone misusing their position or influence to benefit themselves or a third party at the company’s expense. They are harder to detect than asset theft because they often leave no clear paper trail. The four main types are bribery, conflicts of interest, illegal gratuities, and economic extortion.

Kickbacks are the most common form of bribery in a corporate setting. A vendor pays an employee a percentage of a contract’s value in exchange for steering business their way, and the company ends up overpaying because the choice was driven by personal profit rather than price or quality. Conflicts of interest work similarly but without a direct payment: an executive might approve a contract with a supplier owned by a relative without disclosing the relationship.

Illegal gratuities differ from bribery in timing. They are payments made after a favorable decision, as a reward rather than an inducement. Economic extortion flips the dynamic, with the perpetrator using threats to extract money or business advantages. When any of these schemes involve payments to foreign government officials, they fall under the Foreign Corrupt Practices Act, which makes it a federal crime for U.S. companies and individuals to bribe foreign officials to obtain or retain business.2U.S. Department of Justice. Foreign Corrupt Practices Act Unit

Financial Statement Fraud

Financial statement fraud is the intentional misstatement or omission of material information in a company’s financial reports. It is the rarest type but causes the largest losses because it typically runs for years and inflates apparent value by hundreds of millions of dollars. The usual goal is to mislead investors, prop up a stock price, or satisfy lender requirements.

Revenue manipulation is the most common method. A company books sales before products ship, records sales to customers who never actually ordered, or holds the books open past the end of a reporting period to pull future revenue into the current quarter. The SEC targets these practices aggressively. In fiscal year 2024, the agency filed 583 enforcement actions and obtained $8.2 billion in financial remedies, the highest amount in its history.3Securities and Exchange Commission. SEC Announces Enforcement Results for Fiscal Year 2024

Concealing liabilities works from the other direction. Instead of inflating revenue, the company hides debts, warranty obligations, or operating expenses so that reported profit looks higher than it actually is. A related tactic is capitalizing costs that should be expensed immediately, spreading a one-time hit across multiple years. Improper asset valuation does the same on the balance sheet by inflating the recorded value of inventory, receivables, or equipment. All of these manipulations violate Generally Accepted Accounting Principles.

Under the Sarbanes-Oxley Act, the CEO and CFO of a public company must personally certify that their financial statements are accurate. A knowing false certification carries up to $1 million in fines and 10 years in prison. A willful false certification raises that to $5 million and 20 years.4Office of the Law Revision Counsel. 18 USC 1350 – Certification of Periodic Financial Reports

Business Email Compromise and External Cyber Fraud

Business email compromise, or BEC, has become one of the most financially devastating fraud types facing organizations. The FBI’s Internet Crime Complaint Center reported $2.77 billion in BEC losses in 2024 alone.5Federal Bureau of Investigation. 2024 IC3 Annual Report Unlike occupational fraud, BEC comes from outside the company and exploits human trust rather than system vulnerabilities.

The most common tactic is executive impersonation. A fraudster sends an email that appears to come from a company’s CEO or CFO, instructing an employee to wire funds urgently. The email address is either spoofed or comes from a compromised account, and the urgency is designed to bypass normal approval procedures. Vendor invoice hijacking is equally effective: an attacker intercepts a legitimate vendor relationship and sends a convincing email with “updated” bank account details, and the company pays the next invoice into the fraudster’s account.

Spear phishing is the entry point for most BEC attacks. Some criminals go further, deploying malware that gives them access to legitimate email threads about upcoming invoices, sitting inside the system for weeks before striking at the right moment. Verifying any payment change through a second communication channel, such as a phone call to a known number, is the single most effective countermeasure.

Payroll Tax Diversion and Personal Liability

One fraud type catches many business owners off guard because it pierces the corporate form. When a company withholds income taxes and FICA contributions from employee paychecks, that money is held in trust for the federal government. Using those funds to cover other business expenses is a federal offense, and the IRS enforces it through the Trust Fund Recovery Penalty.6Internal Revenue Service. Employment Taxes and the Trust Fund Recovery Penalty (TFRP)

The penalty equals 100% of the unpaid trust fund taxes and can be assessed personally against any individual who was responsible for collecting or paying those taxes and willfully failed to do so.7Office of the Law Revision Counsel. 26 USC 6672 – Failure to Collect and Pay Over Tax, or Attempt to Evade or Defeat Tax The IRS reads “responsible person” broadly to include corporate officers, directors, shareholders, and even bookkeepers or payroll service providers with authority over disbursements. “Willfulness” does not require evil intent. Choosing to pay other creditors while knowing payroll taxes were outstanding is enough.6Internal Revenue Service. Employment Taxes and the Trust Fund Recovery Penalty (TFRP)

Once the IRS asserts the penalty, it can pursue the individual’s personal assets through federal tax liens and levies. This is one of the few fraud-related penalties that pierces the corporate veil by default, putting a business owner’s home, bank accounts, and personal property at risk even when the business itself is an LLC or corporation.

Red Flags That Fraud Is Happening

Fraud schemes rarely appear from nowhere. They follow predictable patterns and leave behavioral, operational, and financial traces. The longer a scheme runs, the more it costs, so catching it at six months rather than three years often decides whether the loss is recoverable.

Behavioral Signs

An employee living visibly beyond their salary is the most obvious warning, but it is not the only one. Refusing to take vacation is a classic indicator because many schemes require the perpetrator’s daily involvement to avoid detection by a temporary replacement. Excessive control over records, an unusual insistence on handling specific vendor relationships personally, and resistance to management oversight all suggest someone protecting a scheme.

Financial pressure on the individual is the most common motivator. Gambling debts, divorce, medical bills, and addiction create the desperation that pushes otherwise honest employees toward theft. Not every stressed employee is a fraud risk, but when financial pressure combines with unusual behavior around records or transactions, the combination warrants a closer look.

Operational Signs

Missing or altered documents are among the most reliable indicators, especially when the employee responsible cannot explain the gaps. A pattern of management overriding established approval processes creates exactly the kind of gap fraud exploits. Unusual transactions near the end of a reporting period, particularly large round-number entries on the last day of a quarter, are a hallmark of financial statement manipulation.

Inventory counts that do not match perpetual records suggest asset theft. Transactions recorded without proper authorization or outside normal business patterns deserve immediate attention. Vendors with no physical address, a single point of contact within the company, and invoices always just below the approval threshold are the fingerprints of a billing scheme.

Financial Signs

Profit or asset growth that dramatically outpaces industry trends should raise questions, not celebration. A rising days-sales-outstanding figure alongside growing sales revenue may signal fictitious revenue being booked that never actually gets collected. Significant unexplained variances between budgeted and actual results need investigation, not just a footnote in the quarterly review.

Transactions involving multiple related-party entities or overly complex structures can be a deliberate attempt to obscure what is actually happening. Cash flow that does not track with reported net income is another red flag. A sudden change in external auditor, particularly if the previous auditor raised concerns, is one of the most serious warning signs a company can display.

Criminal, Civil, and Regulatory Consequences

Business fraud exposes individuals to prison time and organizations to penalties that can dwarf the original theft. The consequences come from multiple directions at once: federal prosecutors, state authorities, civil plaintiffs, and regulatory agencies can all pursue the same conduct independently.

Criminal Prison Time

Federal fraud statutes carry severe sentences. Mail fraud and wire fraud each carry a maximum of 20 years in prison.8Office of the Law Revision Counsel. 18 USC 1341 – Frauds and Swindles9Office of the Law Revision Counsel. 18 USC 1343 – Fraud by Wire, Radio, or Television When the scheme affects a financial institution, both statutes increase the maximum to 30 years and a $1 million fine. Bank fraud carries up to 30 years and $1 million as a baseline.10Office of the Law Revision Counsel. 18 USC 1344 – Bank Fraud State-level charges for embezzlement, theft, and forgery are often pursued alongside the federal case. Sentencing takes into account the total dollar loss, the number of victims, and the perpetrator’s role. A conviction produces a permanent criminal record that effectively ends a career in finance, management, or any position of trust.

Mandatory Restitution

Federal courts do not just have the option to order restitution in fraud cases. Under the Mandatory Victims Restitution Act, a court sentencing someone convicted of an offense involving fraud or deceit must order compensation to every identifiable victim who suffered a financial loss.11Office of the Law Revision Counsel. 18 U.S. Code 3663A – Mandatory Restitution to Victims of Certain Crimes “Victim” is defined broadly and includes corporations and other business entities, not only individuals. The restitution obligation survives bankruptcy, so a convicted fraudster cannot discharge it by filing Chapter 7.

Civil Lawsuits

The victimized company can pursue a separate civil suit to recover its losses, and the burden of proof is lower than in a criminal case. A civil claim requires showing the fraud by a preponderance of the evidence rather than beyond a reasonable doubt. The company can seek the stolen funds plus punitive damages, and may obtain asset freezes or liens on the perpetrator’s personal property to ensure any judgment can actually be collected.

When financial statement fraud inflates a public company’s stock price, shareholders who suffered losses may file derivative lawsuits against directors and officers. These suits seek to hold management personally accountable for oversight failures and can result in clawback of executive compensation.

SEC Penalties

Publicly traded companies face a separate layer of SEC enforcement. The SEC imposes civil monetary penalties on a tiered system. For fraud-related violations involving substantial losses to others, the maximum penalty reaches $236,451 per violation for an individual and $1,182,251 per violation for a company.12Securities and Exchange Commission. Civil Penalties Inflation Adjustments – January 2025 Those per-violation figures add up fast. A company that misstated financial results in quarterly and annual reports sent to thousands of investors can face penalties calculated across every misleading statement made to every investor, producing theoretical maximums in the billions. On top of penalties, the SEC routinely requires disgorgement of all profits gained through the violation.3Securities and Exchange Commission. SEC Announces Enforcement Results for Fiscal Year 2024

IRS Fraud Penalties

When business fraud involves tax evasion, the IRS imposes a civil fraud penalty equal to 75% of the portion of the tax underpayment attributable to fraud.13Office of the Law Revision Counsel. 26 USC 6663 – Imposition of Fraud Penalty The burden of proof on fraud falls on the IRS, but once it establishes that any portion of the underpayment was fraudulent, the entire underpayment is presumed fraudulent unless the taxpayer can prove otherwise. The IRS can also pursue criminal tax evasion charges separately, and regulatory monitoring of the business often follows for years after a fraud finding.

Whistleblower Protections

For publicly traded companies, federal law prohibits retaliation against employees who report suspected securities fraud. An employer cannot fire, demote, suspend, or threaten an employee for reporting a violation to the SEC, federal regulators, or Congress.14Office of the Law Revision Counsel. 18 USC 1514A – Civil Action to Protect Against Retaliation in Fraud Cases Tips from employees, customers, and vendors are the single most effective fraud detection method, accounting for 43% of all discovered cases according to the ACFE.1Association of Certified Fraud Examiners. ACFE Report to the Nations: Organizations Lost an Average of More Than $1.5M Per Fraud Case

What to Do When You Discover Fraud

The first 48 hours after discovering fraud determine whether the case will be strong or compromised. Reacting emotionally by confronting the suspect, announcing the discovery, or rushing to fire someone can destroy evidence and eliminate recovery options. Preservation comes first, investigation second, action third.

Restrict the suspect’s access to documents, computer systems, email, and physical assets before they realize they are under scrutiny. Have IT forensics create a forensic image of the workstation and email account rather than looking through files, which can alter metadata. Secure ledgers, invoices, and vendor files and catalog them to prevent alteration. Document every step with dates and names to establish a chain of custody that will hold up in court.

While evidence is being preserved, stop the bleeding. Freeze bank accounts associated with the suspect or suspicious vendors, revoke system passwords and access codes, and cancel any unauthorized wire transfers or vendor payments before they clear. If physical assets are involved, conduct an immediate inventory count.

Notify internal legal counsel and the board’s audit committee first. Confidentiality at this stage protects both the investigation and the company from defamation claims if the suspicion turns out to be wrong. The company’s outside auditor and fidelity insurance carrier should follow. The decision to involve law enforcement should be made with counsel’s input, since early police involvement can help preserve evidence but may complicate civil recovery negotiations. For public companies, the loss may be material enough to trigger disclosure obligations under SEC Regulation FD.15Securities and Exchange Commission. Selective Disclosure and Insider Trading

Complex cases benefit from external forensic accountants and legal specialists who bring independence and expertise internal staff may lack. The investigation should quantify the financial loss, identify everyone involved, and pinpoint the control failures that allowed the scheme to succeed. Interviews with the suspect and witnesses should happen only after consulting counsel, since poorly conducted interviews can create legal exposure for the company. The final written report becomes the foundation for termination decisions, insurance claims, and regulatory filings.

Mandatory Fraud Reporting for Regulated Businesses

Some businesses have a legal obligation to report suspected fraud to the federal government, but this obligation is limited to specific industries. Financial institutions and money services businesses must file a Suspicious Activity Report with the Financial Crimes Enforcement Network when a transaction of $2,000 or more appears to involve funds from illegal activity, is structured to evade reporting requirements, or serves no apparent lawful purpose.16FinCEN. Money Services Business (MSB) Suspicious Activity Reporting

The SAR must be filed within 30 days of detecting the transaction, and supporting documentation must be retained for five years. The business and its employees are prohibited from telling the person involved that a report has been filed. Violating SAR filing requirements is itself a federal offense, so a covered business that fails to report suspected fraud can face liability even when it was not part of the underlying scheme. Companies outside the covered industries have no equivalent federal reporting duty, though state law, contractual obligations, and SEC disclosure rules may still apply.