Recovery Files: A One-Digit Typo and a One-Way Ticket to Mexico
To an Accounts Payable department, it can all start to look like just data. Rows and rows of vendor numbers, invoice numbers, and amounts. You process the batch, you move to the next one. But every one of those rows is real money leaving the building, and sometimes a single digit is the difference between a routine payment and a $249,000 disaster.
This one is from early in my career, back when I was first learning to analyze AP data. It has stuck with me ever since.
It surfaced on a duplicate invoice report
We were running a client’s payments through a duplicate-invoice analysis when a pair of transactions lined up in a way that didn’t sit right. Two invoices. Same invoice number. Same date. Same amount: $249,000. Everything identical, except a single field: the vendor number, and only by one digit.
Here’s why that matters. Most systems key their duplicate check on the vendor number. So when the vendor differs, even by one digit, the two invoices look like two completely separate, perfectly legitimate payments. The standard control never flags them. But two near-identical invoices pointing at two almost-identical vendor numbers is exactly the pattern our routines are built to catch. So we pulled the thread.
What actually happened
The $249,000 was a real invoice, owed to a real vendor. It got entered twice. Once correctly, routed to the vendor who was actually owed the money. And once with the vendor number mistyped by a single digit, which sent an identical $249,000 payment to an entirely different vendor. The company paid it twice.
One transposed number was all it took.
The photographer
The vendor who caught that second payment was a photographer.
He’d been hired once, a single engagement, to take pictures at the manufacturing facility for the company’s annual report. He invoiced $2,000 for the work. That was the only time that vendor number was ever used, before or since. No PO, no history: just a dormant vendor record sitting one digit away from an active one.
So a photographer who had once been paid $2,000 received a check for $249,000.
Four days
Here’s what he did with it. He deposited the check. It cleared. And four days later, he moved to Mexico.
By the time anyone connected the dots, the money was gone and so was he. The company got the police involved, but it didn’t matter: he’d skipped town, and as far as I know he never came back and the $249,000 was never recovered. A dormant vendor one digit off, a payment large enough to change someone’s life, and a control that was never designed to see it, and it walked straight out the door.
What this one teaches
I tell this story because it’s the perfect illustration of a few things we see over and over:
- “It’s just data” is a dangerous mindset. Behind every vendor number is real cash that can leave the building in days. The moment AP stops seeing the money behind the rows is the moment these slip through.
- Standard duplicate controls key on the vendor number. Change the vendor by a single digit and a true duplicate looks like two clean payments. Catching it takes a routine that compares the other fields, invoice number, date, amount, and flags near-duplicates even when the vendor doesn’t match.
- Dormant and one-time vendors are a risk category of their own. A rarely used vendor record sitting one digit from an active one is a landmine, and a large payment to a vendor with almost no history should be verified before the check goes out, not discovered later.
- No PO means no net. For spend that doesn’t run through purchase orders, the data-entry step is the control. If nothing double-checks it, a single digit is all it takes.
- Speed is everything. Once a payment clears and the payee is gone, recovery goes from difficult to nearly impossible.
Most wrong-vendor payments aren’t this dramatic. They’re small, and they sit quietly. But the mechanism is identical, and it’s running in every AP department: a keystroke, a gap in controls, and money going somewhere it shouldn’t. The only question is whether you’re looking closely enough to catch it.
Wonder what’s hiding in your payment history? Start a no-cost Proof of Value. We only get paid a percentage of what we recover.

