Fake invoicing is a fraud in which a fabricated or altered bill is submitted to an organization or individual to induce payment for goods or services never ordered, never delivered, or already paid — or to redirect a legitimate payment to an attacker-controlled account. It exploits the fact that accounts-payable functions are built to pay, not to doubt: a professional-looking invoice triggers routine compliance rather than scrutiny, especially in busy departments processing hundreds of bills.
Several patterns recur. Phantom-vendor billing submits an invoice from a supplier the organization never used, banking on it slipping through as one of many. Directory and renewal scams send official-looking notices for business-listing “renewals,” domain or trademark “registrations,” or supplies never ordered. Invoice-redirection — the most damaging variant, overlapping with Business Email Compromise — mimics a genuine vendor relationship and submits a real-looking invoice with altered bank details, so a legitimate payment lands in the fraudster’s account. Duplicate-invoice fraud resubmits a bill already paid.
The unifying logic is that the fraud hides inside a normal process. Unlike a phishing email that must overcome suspicion, a fake invoice arrives where invoices are expected, handled by staff whose job is to clear the queue. The tell is almost always a mismatch — no purchase order, an unfamiliar payee, changed banking details, a duplicate number, or an amount that doesn’t reconcile — that surfaces only when someone checks against the organization’s own records rather than trusting the document.