MF

Matthew Fornaro

Business Litigation Attorney · Coral Springs, FL

Matthew Fornaro is a Florida business law attorney serving Coral Springs, Parkland, and Broward County. He represents small businesses in commercial litigation, contract disputes, and business torts. Schedule a consultation →

Key Takeaways

  • Florida business law protects companies from unfair competition, contract breaches, and partner disputes.
  • Acting early saves time, money, and business relationships.
  • An experienced business attorney helps you assess risk and choose the right legal strategy.

Business fraud is any intentional act or omission designed to deceive another party for personal or organizational gain, causing loss to the victim. That definition comes directly from the Association of Certified Fraud Examiners, and it covers everything from an employee skimming cash to a vendor submitting fake invoices to a business partner falsifying financial statements.

If you suspect fraud right now, these are your first four moves:

  • Secure your systems. Change credentials, revoke access for the suspected party, and preserve all logs.
  • Preserve evidence. Do not delete emails, bank statements, or documents. Screenshot anything digital.
  • Limit access. Remove the suspected individual’s authority over accounts, payments, and records immediately.
  • Contact counsel or file a complaint. A business attorney can guide preservation steps; for internet-enabled crimes, file at Ic3.

The most common types of business fraud include asset misappropriation (cash theft, expense padding), financial statement fraud, business email compromise (BEC), payroll and invoice fraud, and corruption or bribery. Each is covered in detail below.


Key Takeaways

Business fraud is an intentional act of deception that causes financial loss, and small businesses face the greatest risk because they typically have the fewest controls in place to catch it early.

Point Details
Definition and scope Business fraud is any intentional deception for gain causing loss, covering asset theft, BEC, payroll fraud, and more.
Costliest fraud type Financial statement fraud produces a median loss of about $766,000 per case, per the ACFE’s 2024 data.
First response priority Limit access and preserve evidence before confronting anyone; the sequence protects your legal options.
Core prevention controls Segregation of duties, MFA, callback verification for payment changes, and regular reconciliations address the highest-risk schemes.
When to call a lawyer Engage counsel before terminating an employee, filing a complaint, or making any public statement about a suspected fraud.
Fornarolegal Provides fraud response, contract review, and commercial litigation for South Florida SMBs, with over 20 years of court-tested experience.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Table of Contents

What is business fraud, and which types hit small businesses hardest?

Most small business owners picture fraud as something that happens to large corporations. The reality is the opposite. Smaller organizations have fewer controls, less oversight, and often one person handling both bookkeeping and payments, which makes them easier targets. Here are the main categories you need to recognize.

  • Asset misappropriation. The most common form of occupational fraud by far, according to the ACFE’s 2024 Report to the Nations. It includes cash skimming before it hits the books, petty cash theft, inflated expense reimbursements, and outright inventory theft. A bookkeeper at a 10-person landscaping company who writes checks to a fictitious vendor is a textbook example.
  • Financial statement fraud. Less frequent (roughly 5% of cases in the ACFE data) but far more damaging, with a median loss of about $766,000 per case. It involves deliberately misstating revenues, hiding liabilities, or inflating assets, often to secure a loan or attract investors.
  • Business email compromise (BEC) and payment diversion. A fraudster impersonates a vendor, executive, or attorney via email and convinces someone in accounts payable to redirect a wire transfer. The FBI consistently ranks BEC among the costliest internet-enabled crimes. The mechanism is simple: a spoofed email address, a plausible story, and urgency.
  • Payroll and timesheet fraud. Ghost employees, inflated hours, unauthorized raises, or falsified commissions. A manager who adds a family member to payroll without authorization is committing payroll fraud, and it often runs undetected for months.
  • Invoice and vendor fraud. Submitting duplicate invoices, billing for services not rendered, or creating shell vendors. Payroll fraud detection and prevention resources note that vendor and payroll schemes share a common thread: they exploit weak approval processes.
  • Cyber-enabled fraud. Account takeover, ransomware, and data theft all qualify as business fraud when they involve deception. Ransomware operators often use phishing emails to gain initial access, then encrypt business data and demand payment.
  • Intellectual property (IP) theft. A departing employee who takes a client list, proprietary formula, or source code is committing fraud with potentially severe long-term financial consequences.
  • Corruption and bribery. Kickbacks to a purchasing manager from a preferred vendor, or a contract steered to a relative’s company, fall here. These schemes are harder to detect because both parties benefit and neither reports it.
  • Insurance and tax fraud. Inflating insurance claims or underreporting revenue to reduce tax liability. Both carry criminal exposure beyond civil liability.

Pro Tip: Each fraud type has a natural control that disrupts it. Asset misappropriation is stopped by segregation of duties; BEC is stopped by a callback verification policy for payment changes. Map your controls to your highest-risk schemes before you do anything else.


Warning signs and red flags you should watch for

Fraud rarely announces itself. It shows up as small, explainable-seeming anomalies that accumulate over time. The goal is to catch the pattern before the losses compound.

Bookkeeping and vendor records:

  • Unexplained reconciling items that appear repeatedly in the same account
  • Invoices with no purchase order, missing vendor addresses, or P.O. boxes that match employee addresses
  • Duplicate payments to the same vendor within a short window
  • Vendor bank account changes requested by email with no follow-up phone confirmation
  • Round-dollar amounts on expense reports (real expenses rarely come out to exactly $500)

Behavioral and operational signals:

  • An employee who handles finances and refuses to take vacation or cross-train anyone else
  • Lifestyle changes (new car, expensive vacations) that don’t match salary
  • Resistance to audits, new software, or any change that adds oversight
  • Approvals that bypass the normal chain, especially for payments above a certain threshold

IT and communications warning signs:

  • Unexpected requests to change a vendor’s email address or bank details
  • Login attempts from unfamiliar locations or at unusual hours
  • Emails that look like internal addresses but have a one-character difference in the domain
  • Altered payment instructions arriving just before a scheduled wire

Pro Tip: When you spot a red flag, document it in writing immediately: date, what you observed, who was involved, and where the record is stored. Do not confront the suspected person yet. That documentation becomes critical evidence if you later need to pursue a legal claim or cooperate with law enforcement.


How much does business fraud actually cost?

The numbers are sobering. According to the ACFE’s 2024 Report to the Nations, asset misappropriation is the most prevalent category of occupational fraud, while financial statement fraud, though less frequent, produces a median loss per incident.

$766,000 — the median loss per financial statement fraud case, per the ACFE’s 2024 Report to the Nations. For most small businesses, a single incident at that scale is existential.

The direct costs are obvious: stolen cash, diverted payments, inflated invoices paid. The indirect costs are often larger. A fraud investigation costs money. Replacing a trusted employee takes time. Customers and lenders who learn about an incident may pull back. Legal fees for civil recovery or criminal cooperation add up fast. And the reputational damage in a local market, where word travels quickly, can outlast the financial hit.

Detection time matters enormously. The longer a scheme runs, the more it costs. Schemes caught within the first six months tend to produce far smaller losses than those that run for a year or more. That single fact is the strongest argument for regular reconciliations and periodic third-party reviews, not annual audits alone.

Small businesses face a compounding disadvantage: they often lack the internal controls that would catch fraud early, so schemes run longer and losses grow larger before anyone notices.


Practical prevention controls every small business can implement

Prevention does not require a large budget. It requires consistent habits and a few structural changes that make fraud harder to commit and easier to detect.

Hands configuring MFA security token

The COSO Fraud Risk Management Guide places ultimate responsibility for fraud risk on boards and top management, and recommends periodic fraud risk assessments paired with preventive and detective controls tailored to the organization. For a small business, that translates into three tiers of action.

Immediate (this week):

  1. Enable multi-factor authentication (MFA) on all financial accounts, email, and cloud software.
  2. Establish a callback verification policy: any request to change a vendor’s bank details or payment instructions requires a phone call to a known number before the change is processed.
  3. Separate the person who approves payments from the person who processes them, even if that means the owner reviews and approves every payment above a set threshold.

Short-term (next 30–90 days):

  1. Implement a reconciliation cadence: bank accounts reconciled weekly, not monthly.
  2. Set up role-based access in your accounting software (QuickBooks, Xero, or similar) so no single employee can both create a vendor and approve payment to that vendor.
  3. Enroll in Positive Pay with your bank, which flags checks that don’t match your issued-check register before they clear.
  4. Create a simple whistleblower channel, even a dedicated email address reviewed by the owner, so employees can report concerns without fear of retaliation.

Longer-term (next 6–12 months):

  1. Conduct a formal fraud risk assessment: list your most likely schemes, estimate their probable impact, and map existing controls to each.
  2. Draft a written fraud policy that defines prohibited conduct, reporting procedures, and consequences.
  3. Schedule an annual or semi-annual review by an outside accountant or forensic accounting specialist who can spot patterns your internal team might miss.

The FTC’s cybersecurity guidance for small businesses covers the technical side: patching software, limiting admin accounts, and protecting customer data. Pair those steps with the financial controls above and you’ve addressed the two biggest attack surfaces.

Pro Tip: An educated, skeptical workforce is one of the most cost-effective defenses available. A 30-minute team meeting on BEC and invoice fraud, run once a quarter, costs almost nothing and can prevent a six-figure wire transfer mistake.


How to respond when you suspect fraud

Speed matters. Every hour of delay gives a fraudster more time to move money, destroy records, or build a cover story. Here is the order of operations.

Immediate steps:

  1. Limit access. Revoke the suspected individual’s access to financial accounts, email, and systems before you say anything to them.
  2. Preserve digital evidence. Take screenshots, export logs, and save email threads. Do not forward, print, or alter anything.
  3. Snapshot financial records. Pull current bank statements, the general ledger, and any recent invoices or payment records.
  4. Do not confront the suspect yet. A premature confrontation can trigger evidence destruction or a hostile response.

Short-term steps:

  1. Engage a forensic accountant to trace transactions and document the scheme in a format that will hold up in court or an insurance claim.
  2. Conduct controlled interviews with witnesses, starting with people least likely to be involved, and document every conversation.
  3. Preserve chain of custody for all physical and digital evidence. Label, date, and store documents securely.

Reporting and next steps:

  1. Notify your bank immediately if funds were diverted. Banks can sometimes reverse wire transfers if contacted within 24–72 hours.
  2. File with IC3 for any internet-enabled crime: BEC, account takeover, ransomware, or phishing.
  3. Contact the FBI for major business fraud, investment fraud, or schemes crossing state lines.
  4. Report to your state Attorney General for consumer fraud or state-law violations.
  5. Consult a business attorney before making any public statements, terminating the employee, or deciding between civil and criminal routes. See the step-by-step legal guide for a detailed walkthrough.

Evidence checklist:

  • Bank statements and wire transfer records
  • Emails and attachments related to the suspected scheme
  • Vendor contracts, invoices, and purchase orders
  • System access logs and login records
  • Employee records for anyone involved
  • Any altered documents (keep originals; do not correct them)

Business fraud carries both criminal and civil exposure, and the two tracks can run simultaneously.

On the criminal side, federal charges under 18 U.S.C. § 1341 (mail fraud) or § 1343 (wire fraud) carry penalties of up to 20 years per count. State-level theft and fraud statutes add their own penalties. Convicted individuals face incarceration, fines, and restitution orders. The business itself can face liability if it failed to implement reasonable controls or if a principal was involved.

Civil remedies run parallel. A defrauded business can sue for compensatory damages, punitive damages in egregious cases, and equitable relief such as asset freezes or injunctions. Civil claims often move faster than criminal prosecutions and give the business more control over the outcome.

Reporting channels and when to use each:

  • IC3: Internet-enabled crimes. BEC, ransomware, account takeover, phishing. File here first for any cyber-related fraud.
  • FBI: Major business fraud, investment fraud, Ponzi schemes, and schemes crossing state lines. The FBI also handles BEC cases that exceed IC3’s scope.
  • SEC: Public-company fraud, securities fraud, and investment adviser misconduct. Not relevant for most SMBs unless you have publicly traded securities or deal with registered investment advisers.
  • IRS: Tax fraud, unreported income, payroll tax evasion. File Form 3949-A to report suspected tax fraud by another party.
  • State Attorney General: Consumer fraud, deceptive trade practices, and state-law violations. Florida’s AG office handles a wide range of business fraud complaints.
  • Local law enforcement: Employee theft, check fraud, and other crimes where the perpetrator is local and the amount is below federal thresholds.

Whether to pursue criminal reporting, civil litigation, or arbitration depends on your goals. Criminal reporting can result in restitution but you don’t control the timeline. Civil litigation gives you more control but costs more upfront. Arbitration can be faster and cheaper when the fraud involves a contract with an arbitration clause.

Pro Tip: Contact a corporate fraud attorney before you file any report or terminate any employee. The sequence of actions in the first 48 hours affects your legal options for months afterward.


Why small businesses are especially vulnerable, and what to do about it

Small businesses are not just smaller versions of large corporations when it comes to fraud risk. They have a structurally different profile. A single owner-operator often handles bookkeeping, approvals, and payments. There may be no IT department, no internal audit function, and no formal fraud policy. Employees wear multiple hats, which makes segregation of duties nearly impossible without deliberate effort.

The most common SMB weak points:

  • Single sign-off on payments. One person who can both create and approve a payment is a single point of failure.
  • Owner-managed books. When the owner is also the bookkeeper, there is no independent check on their own transactions.
  • No offsite backups. Ransomware is far more damaging when there is no clean backup to restore from.
  • Shared login credentials. When multiple employees use the same account, you cannot trace who made a specific change.
  • Minimal vendor verification. Paying any invoice that arrives without confirming the vendor is legitimate is an open door for billing fraud.

Affordable countermeasures that make a real difference:

  • Use cloud accounting software with role-based permissions so no single employee has unrestricted access.
  • Require a second approver for any payment above a threshold you set (even $500 is a reasonable starting point for a very small business).
  • Call vendors directly on a number from your own records, not one provided in the invoice, to verify any change to payment details. UNCITRAL’s commercial fraud guidance specifically flags supplier bank-detail changes as a high-risk moment requiring independent verification.
  • Maintain offsite or cloud backups updated at least daily.
  • Limit admin-level access to one or two named individuals and review that list quarterly.

Pro Tip: A periodic outsourced review by an external accountant, even once or twice a year, costs far less than hiring a full-time controller and catches the patterns an insider would miss. Think of it as an annual physical for your finances.


When should you hire a business attorney, and what happens first?

Not every fraud suspicion requires immediate legal action, but some situations demand a lawyer before you take any other step. Knowing the difference protects both your legal position and your business.

Triggers for immediate legal engagement:

  • You have evidence of employee embezzlement or a forged contract
  • A significant sum has been diverted and you need to act quickly to freeze assets or reverse a transfer
  • You are considering terminating an employee and want to avoid wrongful termination exposure
  • Law enforcement has contacted you, or you are considering filing a criminal complaint
  • A business partner may be involved, which raises fiduciary duty and partnership law issues (see what happens when a business partner commits fraud)

What a business attorney typically does first:

  • Advises on evidence preservation to protect the chain of custody
  • Coordinates with forensic accountants to document the scheme
  • Communicates with your bank to explore recovery options
  • Evaluates whether a civil claim, criminal referral, or both is the right path
  • Advises on employment law implications before any termination

What to bring to the first meeting:

  • A written summary of what you suspect and when you first noticed it
  • Copies of relevant bank statements, invoices, and emails
  • A list of employees with access to the affected accounts or systems
  • Any contracts with the suspected party
  • Your current insurance policies (crime and cyber coverage may apply)

Pro Tip: Ask your attorney at the first meeting whether your commercial crime insurance or cyber liability policy covers the loss. Many SMBs have coverage they never use because they don’t know it applies.


Authoritative U.S. resources for reporting and guidance

These are the primary places to go for reporting, frameworks, and practical tools.

  • ACFE (Association of Certified Fraud Examiners): The leading source for fraud research, statistics, and professional standards. Use for definitions, the annual Report to the Nations, and training resources.
  • IC3 (Internet Crime Complaint Center): The FBI’s online portal for reporting internet-enabled crimes. File here for BEC, ransomware, account takeover, and phishing.
  • COSO Fraud Risk Management Guide: The authoritative framework for building a fraud risk management program. Use for governance structure, risk assessment methodology, and control design.
  • FBI Business and Investment Fraud: Descriptions of common schemes, warning signs, and reporting options for major fraud cases.
  • SEC (Securities and Exchange Commission): For public-company fraud and investment adviser misconduct. Report at sec.gov/tcr.
  • IRS: For tax fraud and payroll tax evasion. Use Form 3949-A to report suspected tax fraud by another party.
  • FTC Cybersecurity for Small Businesses: Practical, plain-language guidance on protecting your business online. Use for basic cyber hygiene, data protection, and account security steps.
  • FAU Center for Forensic Accounting: SMB-specific scheme examples and prevention resources from an academic forensic accounting center.
  • Investor.gov: For businesses evaluating investment opportunities or concerned about investment-related fraud.
  • How to prevent fraud — Ready Accounting: Practical prevention steps and forensic accounting perspectives for small businesses.

For incident documentation, a basic incident log should capture: date and time of discovery, what was observed, who was involved, what records were preserved, and who was notified. A vendor verification checklist should include: vendor name, address, phone number confirmed via independent source, bank details confirmed via callback, and the name of the person who completed the verification.


The cost of waiting is always higher than the cost of acting

The pattern I see most often in fraud cases is not that business owners missed the red flags. It is that they saw something that felt off, told themselves there was probably a reasonable explanation, and waited. Six months later, the loss is three times what it would have been.

Early detection is not about distrust. It is about structure. When you build controls that make fraud harder to commit and easier to spot, you protect your employees as much as your finances. Most people do not commit fraud because they are bad people. They do it because an opportunity presented itself and no one was watching. Remove the opportunity, and you remove most of the risk.

Hand locking office door deadbolt

If something feels wrong, preserve the records, limit access, and get advice before you do anything else. The sequence matters more than the speed.


Fornarolegal helps South Florida SMBs respond to fraud and reduce risk

When fraud hits a small business, the first 48 hours determine how much you recover and how much legal exposure you carry. Fornarolegal provides court-tested business law representation for entrepreneurs, startups, and established companies across South Florida, with over 20 years of experience handling fraud response, contract disputes, and commercial litigation.

Fornarolegal

Matthew Fornaro advises clients on evidence preservation, coordinates with forensic accountants, evaluates civil claims against perpetrators, and handles the employment law side of terminations that follow a fraud discovery. For businesses facing a suspected fraud right now, the firm offers a focused initial consultation covering your immediate preservation steps, your reporting obligations, and your options for recovery. Use the pre-litigation checklist as a starting point, then call to discuss your specific situation. Fornarolegal serves clients throughout South Florida and provides local counsel support for out-of-area matters.


Sources

Facing a business dispute in Florida?

Get a straight answer from an attorney who understands small business.

Schedule a consultation