Chorus Pro Invoice Email EXPOSED: Fake Payment Notices Steal Logins

A new invoice from a public sector portal is the kind of mail a supplier already opens, because French administrations collect their bills on a platform instead of a paper tray. The subject sitting in the list is [Chorus Pro] Nouvelle facture, which is short enough to survive the few seconds between the inbox row and the reading pane.

The body is written in French and talks like a portal that already knows you, because it says a new invoice has arrived together with a payment default notice. It then asks you to use a single control to view the payment details, and it warns that the document will remain accessible for only seventy-two hours. A footer identifies the note as automated mail and asks you not to reply, which is the kind of line a real system notice already uses on a Monday morning.

If you need to know whether a public invoice is actually waiting, you open the e-invoicing service the way you already do, or you check the thread you already keep with that administration. A surprise payment button inside a cold letter is a poor substitute for that door, and the file will still be there after you leave this note alone.

Outlook view of a Chorus Pro invoice email with a payment button

Overview

The letter wants you to treat a public invoice plus a payment default as homework you must finish before the file expires, then it uses a view-payment button to choose the next page for you. That next page copies a Microsoft identity check, often dressed as OneDrive, and asks for the password you already use at work, which is the harvest the invoice story was written to hide.

What they take first is the login for the inbox you are sitting in, and after that they take the inbox itself. That includes the threads with public buyers, the reset codes that land an hour later, and the people who already answer when your name is on the From line. The new-invoice story is costume for that harvest, because a payment default that might stall a public contract is the kind of errand a tired desk will finish before asking whether Chorus Pro actually sent the note.

Chorus Pro remains a real French government e-invoicing service used by businesses that bill public sector entities, and that fact is why the name is useful on a From line. Anyone can type Chorus Pro into a display name, which means a tidy heading does not prove that a new invoice was filed or that a payment default is waiting inside the real portal. People who steal inboxes borrow letterhead from platforms that already sound like invoices, administrations, and money moving, because they want you to treat the note as a chore you already meant to finish.

Official invoicing lives inside the portal after you type chorus-pro.gouv.fr yourself, on a page you already use rather than on a page a cold letter chose for you. A surprise invoice is a poor substitute for that door, because the real service does not collect a mailbox password in order to show you a payment default. If a later page also asks for a code from your phone, they will take that too, since the login is what they designed the invoice around.

The payment click used to open a page parked on Instawp, a site-building service that lets people stand up ordinary looking pages in a hurry. While it was up, it carried Microsoft and OneDrive branding and told visitors they had received a secure file that required identity verification before it would open. The same screen showed logos for Outlook, Yahoo, and several French internet providers, which is how the costume can change once you type an address and then present the login that matches that mailbox.

A dead tab today does not make a password typed yesterday harmless, because a harvest page can finish collecting before it goes quiet. Do not reopen the letter to see whether the invoice then appears, and do not paste the button into a search so a coworker can try it.

The Federal Trade Commission describes this shape in ordinary language in How To Recognize and Avoid Phishing Scams, where it says scammers use email to steal passwords, account numbers, or Social Security numbers. A common story, the Commission adds, is a problem with an account when there is no problem, or a document you must confirm when you do not. The Commission advice is to contact the company with a phone number or website you already know is real rather than with the information in the email. A view-payment button that arrived inside an unexpected Chorus Pro notice is information in the email, which is why it is a poor place to start a public invoice.

CISA says the same thing from the systems side on Avoiding Social Engineering and Phishing Attacks, where it tells people not to reveal personal or financial information in email. It also tells people not to follow links sent in email when a message asks for that information. On Teach Employees to Avoid Phishing, CISA tells staff that if a message feels off, they should verify it without using any phone number or link in the message. That means using a number you already have and a site you already type, which is the opposite of fetching a payment file from a letter you did not request.

The invoice and the default

Read the subject the way a tired supplier reads it between two other alerts, because Nouvelle facture already sounds like a bill that landed in a portal you were supposed to watch. The body has already done the payment default, the seventy-two hour line has already done the clock, and Chorus Pro has already done the government name, so by the time your eye hits the rectangle the errand feels mostly finished.

A payment default is doing extra work that a quiet invoice cannot do, because a bill can wait until after lunch while a default feels like a contract that is already slipping. Public buyers, hospitals, and local authorities really do sit on that kind of clock, which is why the lure borrowed it instead of inventing a prize. Nobody is asking you to investigate a stranger here, because the ask is to keep a public payment from going late, which is a much softer request than a threat and a much harder one to ignore.

A real Chorus Pro file, when one exists, is still sitting in the envelope you already use after you open the portal yourself. It does not need a surprise button in a cold letter to keep existing, and it will still be there after you leave Consulter le paiement alone. Matching the French wording to a real invoice is work the letter hopes you will skip because the subject already looks like a filing.

A government name is cheap to copy

Keep the names straight, because the campaign depends on mixing them up: Chorus Pro exists, French businesses already use it to bill the public sector, and a payment default is a believable thing to put next to a public contract. Bonjour, a claim that a new invoice has arrived, and a notice of default are doing the work a real portal usually does. A finance person can picture a prefecture waiting without checking whether anyone at the real service issued that file.

Those details can be typed by anyone who has seen a public invoice notice, and matching them to a real filing is work the letter hopes you will skip because the heading already looks official. Display names are cheap, and anyone can set a From line to read Chorus Pro, just as anyone can stamp an automated footer under a blue bar and date the whole thing on a Monday morning. Microsoft guide to spotting phishing tells you to treat mismatched senders as a warning and to slow down when a message wants an immediate click. A footer that hurries you toward a vanishing payment file is that kind of immediate click, so do not reply to ask whether the invoice is real, because a reply teaches them the inbox is live and it lands wherever they pointed the return path.

Seventy-two hours is the clock they added

An ordinary invoice can still lose to a busy morning, so a document that remains accessible for only seventy-two hours is the extra clock the letter added on purpose. A signature on paper can wait, and a bill in a portal can wait, which is why the letter does not lean on paper at all. A payment file that might disappear while you hesitate feels like a problem that grows, which is why the letter puts the timer next to the only button that works.

Accounts payable teams live on that kind of clock, because public buyers send reminders, controllers ask for dates, and a late default that posted without a conversation is a real kind of afternoon. The lure is borrowing that afternoon, and it does not need a long pitch when it can offer a new invoice, a default notice, and a seventy-two hour window that a tired person can already imagine matching to last week. A hospital order, a local authority contract, a state agency payment, and a filing that legal already asked for are all stories the subject can invent in a few seconds.

How The Scam Works

1. A Chorus Pro invoice lands

It arrives in the same Outlook or Gmail you already trust, wearing a subject that reads [Chorus Pro] Nouvelle facture, which is how a public portal talks when it thinks you already know the file. The display name presents itself as Chorus Pro, the body is written in French, and the whole note is built to fit on a phone screen as a courtesy a supplier already expected rather than as a midnight threat to delete the mailbox.

If you are already signed in to webmail, the folders on the left and the search bar on the top make the fake note feel native, and you are not visiting a strange site yet because you are only reading mail. The letter only has to survive the few seconds between the subject and Consulter le paiement, and a new invoice next to a payment default is enough to buy those seconds inside a finance folder that already lives on public contracts.

There is no long story and no demand for a wire in the first line, which is on purpose because a short official notice is easier to believe than a letter that asks for a routing number before you have had coffee. The CISA warning about surprise messages is aimed at exactly those few seconds, which is why the useful move is to slow down before the card chooses the next page for you.

2. The name copies a government portal

Chorus Pro belongs to a real platform that businesses already use to bill French public entities, and that fact is the load-bearing detail in a letter that only has a few seconds to look like a government notice. When you have ever deposited an invoice, tracked a status, or seen the name on a closing checklist, you fill in the rest yourself. Even if you have never opened the product, the phrase payment default still sounds like a public bill that someone is waiting on.

The people who wrote the letter did not need to sit inside the real service to borrow a Nouvelle facture heading. They also borrowed a payment-default line and an automated footer that would survive a five-second glance from a tired payable clerk. The thief is only inside your inbox if the payment click works, which is why the name on the letter is doing borrowed work rather than proving a file was shared. A Bonjour that never uses your company name is a cheap leftover from the same kit, not proof that a clerk already knew who you were.

The vagueness is useful, because the notice does not name the buyer, the SIRET, or an invoice number you can match to paper from last week. You supply the faces, which is how a blast becomes personal without the sender knowing anything except your address. Delivery proves they knew the mailbox, and it does not prove they sit on the invoice they announced or that a living public buyer will answer if you call a number you already have.

3. Seventy-two hours is the hurry

Seventy-two hours is doing the work a late public payment usually does, because money that might stall is a Monday a finance person already fears. A quiet invoice can wait until after lunch when it is only paper, which is why the letter does not lean on paper at all. A document that remains accessible for only seventy-two hours feels like a problem that grows while you hesitate, which is why the letter puts the timer next to the only button that works.

Payroll and payable teams live on that kind of clock, because vendors send reminders, controllers ask for dates, and a default that posted without a conversation is a real kind of afternoon. The lure is borrowing that afternoon, and it does not need a long pitch when it can offer a filename in French, a default line, and a window that a tired person can already imagine matching to last week. Direct deposit, a public hospital order, a local authority job, and a filing that legal already asked for are all stories the timer can invent in a few seconds.

4. View payment is the handoff

You click Consulter le paiement, or whatever view-payment label the card is using this week, because that is what a payment notice is for. A file that expires in seventy-two hours makes a public bill feel like an errand you should finish before lunch. Then the next page asks you to prove your identity as if you were opening a secure Microsoft file instead of showing an invoice with a payment default in the title bar.

That request is the tell, because you are already in mail, and a real invoice would open inside the portal after you typed it yourself. It would not ask you to prove you are you so you can see a file the sender already claimed was waiting. CISA tells people not to follow a link in a message that then asks for that kind of information. View payment is the detour, because the button is a handoff from a letter you trust to a page you should not.

On a phone, where hovering is awkward, many people never see the real destination before the next page fills the display. There is no honest reason for a public invoice and a payment default that need your review to live on a surprise page you reached from an unexpected letter. If the files were real, they would already be sitting in the portal you already use, or in the thread with the administration you already have, without a cold button carrying you somewhere else so the paper can continue.

5. The page copies Microsoft identity

The page that follows is dressed as a Microsoft identity check, often with OneDrive branding and a claim that a secure file is waiting once you verify who you are. Your address may already be sitting in the box, the colors look familiar, and the language is the language you see every morning, which is how a careful person finishes a login they never meant to start. The costume can change with the mailbox, because the same kit showed logos for Outlook, Yahoo, and French internet providers and then adapted the door to match the address you typed.

A padlock in the browser does not fix that, because encryption only means the path is private and does not mean the person at the other end is Microsoft, OneDrive, or the French state. HTTPS can wrap a stolen password as neatly as a real one, and an accurate logo is not a certificate, so you trust the complete domain and the way you reached it rather than the artwork inside the page. Do not finish that form to see whether an invoice then appears, because a copied identity page does not become safer when you only wanted to confirm a public payment.

Do not send the live button to a coworker so they can check the file; if you need a second pair of eyes, send a screenshot with the link unclicked, or send the raw message as an attachment to a person you already know. A padlock, a government name, and a seventy-two hour warning you already feared are not a reason to type the secret that opens the rest of the week.

6. They want the mailbox password

If you type the password they have the first key, and if a text, an authenticator prompt, or an email code arrives while that tab is still open they want the second key too. The story will sound helpful, asking you to confirm so the secure file can load, or to enter the code to verify your work account. Each of those lines is the same request for access to the mailbox you were already sitting in when the invoice arrived. The Chorus Pro invoice was never sitting behind that box, because the mailbox was, and the people who wrote the letter designed the payment-default line so you would not notice the swap.

The Microsoft phishing page tells you to change the password on every affected account if you think you typed it on the wrong site, and to turn on multifactor authentication if it is not already on. That is the same advice the FTC gives in consumer language when a password may already be sitting with someone else. Once they can open the account, the public invoice is no longer the hunt, because they are reading the last bill you sent, the last bill you received, and the thread with a public buyer who pays on a schedule, and then they write the next message in your voice. A compromised mailbox is not a nuisance in that setting, because it is a way to move a payment without ever calling you again.

Do not reuse the typed password on a screen that promises to unlock the invoice or to stop the default, because the bill was never locked and it was never there. Treat the password as burned and treat the code as burned rather than testing them on the next page, then open the real mail product yourself in a tab you type.

7. A second crew sells recovery

The last move is often social, and it may not even be the same people, because a day later you can get a call, a text, or a fresh email that already knows you opened a Chorus Pro invoice. They will offer to lock the portal, pull the payment file, or stop a default you never approved, and then they will ask for a code, a remote-access session, a second password, or a cleanup fee. Hang up, because a stranger who found you is not your incident responder, and a Chorus Pro security desk that called you after Consulter le paiement is not the real service.

Stolen passwords get bundled and sold, and a second crew buys the access or the address and comes back as help. They may write as support, as a finance desk, or as a cleanup team that offers to restore the invoice, freeze the account, or walk you through a refund for a public bill that never existed. The subject is softer and the form is the same, whether they want another password, another code, another remote session, or another fee to undo a theft they are still running.

That is why a quiet admission that you already clicked, even if you did not pay anyone, is not the end of the story, because you may not have paid while the person who trusts you might. Tell the people who send you money and the people you pay, and tell a real coworker, if you actually share a public filing, on a number you already have rather than on a number that arrived after the payment button. A thirty second call from you is cheaper than a week of wires that look like your week, and the second crew is counting on shame to keep you quiet long enough for the first crew mail to land.

What To Do If You Have Fallen Victim to This Scam

If you only opened the email and closed it, you are not finished, but you are not doomed, and if you pressed the payment button and then typed, treat the account as touched and move in this order. Speed beats waiting to name the exact kit they used, because the goal is to take the mailbox back before someone else sends the next invoice in your name. Write down what you remember before the details fade, then stay on official pages you open yourself rather than on anything that arrived inside the Chorus Pro letter.

  1. Write down what you typed, including the time and the subject [Chorus Pro] Nouvelle facture, then stop using that tab. Write down whether you entered a password and whether you approved a code or an app prompt, then close the payment page. Do not keep checking it to see if a public invoice appears, and do not forward the live button to a friend so they can look. Send a screenshot with the link unclicked, or send the raw message as an attachment to a person you already know.
  2. Open your real mail yourself in a new tab you type, then change the password to one you have not used anywhere else. Use the official site or the app you already trust, and do not return to the invoice letter for a reset link. If this is a Microsoft account, follow the Microsoft steps published to recover a hacked or compromised Microsoft account. If you cannot sign in, use the official reset path, and if this is Gmail or a workplace portal, open that product the same way, from an address you typed.
  3. Sign out of other sessions everywhere you can, then turn multifactor authentication back on before you do anything else with the mailbox. Review recent activity on a page you opened yourself and sign out of sessions you did not start. If you approved a prompt you did not begin, assume that session is not yours until you kill it, and remove recovery phones and recovery addresses you did not add. A password change that leaves an old session running is only half a change, so finish the sign-out before you treat the mailbox as yours again. If you reuse that password on banking, payroll, or the real invoicing portal, change those on their own sites too, after you type those sites yourself.
  4. Look for inbox rules, automatic forwarding, and mail that left without you, because those are the quiet ways a stolen mailbox keeps working after a password change. Check the Sent folder and look for a new mailbox delegate, a new app that can read mail, or a filter that hides replies. Delete what you did not create, and search for other Chorus Pro invoice notices you did not expect. If this is a work account, call IT before you spend an hour hunting, because they can dump sessions and pull the audit faster than you can.
  5. Call the people who pay you and the people you pay, using a number from last year invoice, a card in the drawer, or a listing you already trust. Tell them a fake Chorus Pro invoice tried to take the mailbox, so they should not honor a new account number or a rushed updated-wiring note that arrives this week. If you actually share a public filing or a supplier file, say that out loud on a number you already have, because the lure picked a government invoice name for a reason. A coworker who already paid according to this letter still needs a human check in the real portal.
  6. Tell the bank the same day if invoices, payroll, or deposit files live in that inbox, and ask them to watch for a change-of-account request. Call any payroll or processor vendor as well, because a charge you did not make and a transfer you approved because a message looked like you are different problems, and time still matters on both. Do not invent a dollar figure for a loss you have not seen, and report what you actually typed and what you actually see on the statement. If you use the real Chorus Pro service and a real invoice is waiting, open that portal yourself and look there, not in this email.
  7. Report the email through the controls your mail product already publishes, then scan the device if the payment button saved a file or pushed a viewer. In Outlook, use Report and then Report phishing, the path Microsoft publishes on its phishing help page, and in Gmail use Google reporting control from the same phishing help page they publish for this. Forward a copy to the Anti-Phishing Working Group at reportphishing@apwg.org, then file the same facts at the FTC ReportFraud site and, if you want a law-enforcement copy, at the FBI IC3. If a password, a bank account, or a Social Security number went into that page, use IdentityTheft.gov for the next steps. If a file landed, run a full scan with Malwarebytes or the antivirus you already keep updated, remembering that the scan does not get a password back and the password change does that.

If someone forwarded you the note, send them this page instead of the view-payment button, because these invoices travel in office threads when they look like public work, which is part of how they move. Do not install a new cleaner you just searched for because a follow-up email recommended it, since that search is how people add a second problem. The recovery call that already knows the subject line belongs to the same family as step seven above, so hang up and stay on the official path you opened yourself.

If you use Chorus Pro every day, treat this letter as a reminder to open the product from a bookmark you already keep, not from mail, and look at the real invoices waiting in the portal. If the product shows no new file, then no new file was shared, and if something did land, it will still be there after you ignore Consulter le paiement. A fake payment default does not become real because you were waiting on a public bill, and waiting is the opening they wrote the seventy-two hour line for.

The Bottom Line

A note whose subject is [Chorus Pro] Nouvelle facture, writes as Chorus Pro, greets you in French, and offers a view-payment control, is a login behind an invoice. It claims a new bill arrived with a payment default, and it says the document will remain accessible for only seventy-two hours. The product name belongs to a real French e-invoicing service, while the operator of this letter does not. The click is the door they built so you would type a mailbox password instead of opening the portal yourself. After that they use the inbox to write as you, and the recovery call that already knows the subject is the second shift.

Open the mail service you already pay by typing it yourself if you need to know whether anything is wrong. If you need to know whether a public invoice actually landed, open Chorus Pro the same way, from a site you already type. If you already typed the password, change it on the official page for that provider, kill the other sessions, and tell the people who send you money before the next email goes out as you. The invoice was never the point of the letter, because the mailbox was what they came to collect.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Cevile.cc EXPOSED – Fake or Real? Casino Investigation

Next

Corix.cc EXPOSED – Casino or Crypto Trap? Read First