PanicStation.org
us Work & employment crises

What to do if…
you suspect someone is using your name to approve purchases or invoices at work

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy USA guide

Short answer

Ask Finance or Accounts Payable and IT/security, in writing, to pause approvals under your name, hold any related payments, and preserve audit logs.

Do not do these things

  • Do not confront the person you suspect or accuse anyone in chat, email, or a meeting.
  • Do not re-approve, backdate, edit, void, or “fix” records yourself unless the system owner tells you to do that in writing.
  • Do not delete emails, approval notices, invoices, login alerts, or system notifications.
  • Do not send invoices, vendor banking details, screenshots, or internal records to your personal email or phone unless your employer’s policy allows it.
  • Do not wait until you can prove who did it if a payment may still be pending.

What to do now

  1. Contact Accounts Payable, Finance, or Procurement and ask them to pause any payment tied to approvals under your name until the approvals are reviewed.
  2. Contact IT/security or the helpdesk and ask them to temporarily disable your approval access, require a second approver, or block approvals from your account while they check the issue.
  3. Send one factual written report to your manager, Finance or Accounts Payable, and IT/security. Include invoice numbers, vendor names, amounts if known, dates, times, and where you saw your name attached.
  4. Ask IT/security to preserve logs for your work account, approval system, email account, sign-ins, connected apps, mailbox rules, forwarding rules, and delegated access.
  5. Save the approval emails, notices, and screenshots in an approved work location if your policy allows it. Do not alter the original records.
  6. Ask Finance or Procurement to check for recent vendor bank-detail changes, duplicate invoices, split invoices, rush-payment requests, and approvals routed through a shared role or delegated queue.
  7. Reset your work password through the normal company process and ask IT/security to confirm multi-factor authentication is active.
  8. If your employer has an ethics, compliance, fraud, or whistleblowing channel, use it if you are worried your manager may be involved or you fear retaliation. Keep the report factual and save any case number.
  9. If money has already been sent to a suspicious account, ask Finance to contact the company’s bank immediately and ask whether the payment can be held, recalled, or traced. Also ask Finance, legal, or compliance whether the company should file an IC3 complaint.
  10. If you also see signs that your personal identity is being misused outside work, such as new accounts, credit inquiries, collection notices, missing mail, or tax notices, use IdentityTheft.gov and consider a fraud alert or credit freeze.

What can wait

  • You do not need to decide now whether to quit, confront anyone, or hire an attorney.
  • You do not need to prove who did it before reporting the concern.
  • You do not need to investigate vendors yourself.
  • You can wait on personal credit steps unless there are signs your personal identity is being used outside the workplace system.

Important reassurance

This is alarming, but reporting it quickly and factually is a protective step. A proper review should look at system logs, approval routing, delegated access, and payment controls, not just the name shown on an invoice.

Scope note

These are first steps to limit damage, preserve records, and protect you from being wrongly tied to approvals. Later decisions may need help from your employer’s finance, security, compliance, HR, or legal teams.

Important note

This is general information, not legal, financial, cybersecurity, employment, or professional advice. Follow your employer’s policies where they apply, and use documented internal channels when you are asked to approve or explain records you do not understand.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us