S.M.M.

Stop Manipulating Me · A Field Guide to Psychological Influence

ENTRY No. T14.12
CATEGORY Social Engineering
CLEARANCE Public / Essential
EDITION 01
Dossier · Manipulation Tactic

Fake Invoices

Financial Vector · Invoice / Billing Fraud · High
Red Flag
How It WorksSEC 01

Fake invoicing is a fraud in which a fabricated or altered bill is submitted to an organization or individual to induce payment for goods or services never ordered, never delivered, or already paid — or to redirect a legitimate payment to an attacker-controlled account. It exploits the fact that accounts-payable functions are built to pay, not to doubt: a professional-looking invoice triggers routine compliance rather than scrutiny, especially in busy departments processing hundreds of bills.

Several patterns recur. Phantom-vendor billing submits an invoice from a supplier the organization never used, banking on it slipping through as one of many. Directory and renewal scams send official-looking notices for business-listing “renewals,” domain or trademark “registrations,” or supplies never ordered. Invoice-redirection — the most damaging variant, overlapping with Business Email Compromise — mimics a genuine vendor relationship and submits a real-looking invoice with altered bank details, so a legitimate payment lands in the fraudster’s account. Duplicate-invoice fraud resubmits a bill already paid.

The unifying logic is that the fraud hides inside a normal process. Unlike a phishing email that must overcome suspicion, a fake invoice arrives where invoices are expected, handled by staff whose job is to clear the queue. The tell is almost always a mismatch — no purchase order, an unfamiliar payee, changed banking details, a duplicate number, or an amount that doesn’t reconcile — that surfaces only when someone checks against the organization’s own records rather than trusting the document.

Warning SignsSEC 02
  • No matching purchase order or delivery record behind the bill.
  • An unknown or slightly misspelled vendor name or address.
  • Changed or unexpected bank details on an otherwise-familiar vendor's invoice.
  • A duplicate invoice number or amount already paid.
  • Round or oddly specific amounts just below an approval threshold.
  • "Past due / final notice / service suspension" urgency on a first-seen bill.
Frequently Paired WithSEC 03
  • Business Email Compromise · T14.10
    Parent/overlap — BEC delivers the fake invoice
  • Payment-Redirection Scams · T24.7
    Invoice/billing internet-scam home
  • Trust Exploitation · T14.21
    Abuses established vendor trust
  • Inoculation / Awareness · T25.17
    AP-staff training on the mismatch tells
How the Attack UnfoldsSEC 04
  • Stage 01 · Arrival
    A professional-looking bill — often with "final notice" urgency — lands where invoices are expected.
  • Stage 02 · Routine Compliance
    Busy AP staff process on heuristics ("looks like an invoice, pay it"); the fraud hides among many, getting seconds of attention.
  • Stage 03 · Payment
    With no PO-match check, funds go to the fraudster — or a genuine, expected payment is diverted by the altered bank details.
Counter-ProtocolSEC 05
Defense: Check your own records, not the document — three-way match every bill.
  • Enforce three-way matching. Pay only when the invoice reconciles against a valid purchase order and a goods-received record.
  • Verify vendor and bank changes out-of-band. New vendors and any bank-detail change need independent confirmation on a known number, with a cooling-off delay.
  • Flag duplicates and unknown payees. A duplicate number/amount or an unfamiliar vendor is a stop-and-verify trigger.
  • Segregate duties. No single person can create a vendor and pay it; add approval thresholds.
  • Report suspected redirection to the bank and IC3 fast to improve recovery odds.