28 May 2026 · Gumshoe Team

Case Study: How a National Retailer Caught a Ghost Supplier Scheme

A major Australian specialty retailer discovered a network of fictitious suppliers after running Gumshoe verification on their accounts payable backlog. Here is what the checks found — and what human review alone had missed for three years.

Background

A specialty retail chain operating 140 stores across Australia had grown rapidly through acquisition. Their accounts payable function was split across two finance teams in different states, each managing roughly 600 active suppliers. The fragmentation meant no single person had a complete view of the supplier base.

A new CFO, appointed after the latest acquisition, requested a full supplier audit as part of standard post-merger due diligence. The internal team had used a spreadsheet-based process for years — ABN lookups were done manually, one by one, using the ABR website. The process was time-consuming and inconsistently applied. With 1,200 suppliers to review, they needed something faster.

What Gumshoe Found in the First Batch

The finance team uploaded their supplier list and ran the first batch of 300 verifications. Within minutes, the report flagged three entities with the same pattern:

  • ABN registered within the past 8 months
  • No website found across 12 domain permutations
  • No ASIC company registration — sole trader structure only
  • State/postcode inconsistency on one (a Queensland postcode registered as NSW)
  • Email domain registered 6 weeks before the first invoice

The assurance scores: 31%, 28%, and 34% — all in the High Risk band. All three had been set up as active suppliers and had received payments ranging from $18,000 to $67,000 over the preceding six months.

The Pattern Emerges

Cross-referencing the three entities, the team noticed the bank account details on file had been changed within days of each other, all routed through the same BSB. The registered business names were variations on legitimate-sounding trade services: cleaning contractors, maintenance supplies, IT consumables. None had verifiable physical addresses. None appeared in any industry directory.

When the team ran a deeper search on the ABN registration dates against invoice dates, they found a consistent pattern: the ABN was registered, a creditor account was created within days, and invoices began arriving before any formal supplier onboarding was completed.

The investigation was escalated to the company's forensic accounting partner. The three suppliers were traced to a single individual — a former employee who had left the business 14 months earlier — operating through nominee arrangements. Total losses: approximately $180,000.

What the Checks Caught That Humans Missed

The previous manual process checked one thing: whether an ABN existed and was active. Gumshoe's verification ran eight simultaneous checks. The decisive signals were:

  • ABN age — all three were registered less than 6 months before the first invoice. This is a well-documented fraud indicator and the single most reliable early warning sign.
  • Domain age — the email domains were registered weeks before invoicing began. Without WHOIS/certificate transparency checking, this is invisible to manual review.
  • No web presence — legitimate trade service businesses almost always have some online footprint, even minimal. Zero presence across all candidate domains is a strong negative signal.
  • DMARC missing — all three email domains had no DMARC record, meaning the domains could be spoofed freely. This is common in hastily-created fraudulent identities.

Outcome and Process Changes

Following the investigation, the retailer implemented mandatory Gumshoe verification for all new supplier onboarding. Existing suppliers above a payment threshold were re-verified on a rolling quarterly basis. The finance team established a policy: no supplier with an assurance score below 60% could be activated without dual-manager sign-off and a phone call to a verified landline.

The new process added approximately 3 minutes per supplier for new onboarding (versus the previous 15–25 minutes of manual ABN lookups and cross-referencing). For the quarterly re-verification cycle, the entire active supplier base could now be reviewed in an afternoon rather than across several weeks.

Twelve months after implementation, the team identified two further anomalous suppliers — both were legitimate businesses that had been deregistered without notifying the retailer, creating potential GST compliance issues. Neither was fraud, but both would have created problems at audit without remediation.

VERIFY A SUPPLIER
Run a free check in seconds

Search by business name, ABN, or ACN. Get a real-time PASS/WARN/FAIL report across 8 verification checks.

Start verifying →

Contains data sourced from the Australian Business Register and ASIC, © Commonwealth of Australia, licensed under CC BY 3.0 AU.