International Payment Scam: How Fake Supplier Invoices Hijack Transfers

The invoice is expected, the shipment is real, and the sender knows exactly when the balance is due. Only one detail has changed: payment must go to a new bank account.

An international payment scam can hide inside an ordinary business conversation until a transfer is already gone. The message does not need to look strange when the criminal has learned how the deal is supposed to look.

Reconstructed international payment scam email replacing supplier bank details

Overview

The fraud may begin long before the invoice changes

Criminals study suppliers, importers, payment schedules, and employees with approval authority. They may compromise a mailbox, imitate an address, or approach a business as a completely fake vendor.

By waiting for a genuine order to reach its payment stage, the attacker can insert believable banking instructions into a conversation that finance staff already trust.

Cross-border transfers give criminals useful friction

Time zones, language differences, freight deadlines, intermediaries, and unfamiliar beneficiary banks can make unusual details seem normal. A request that would look wrong domestically may be excused as an international procedure.

Wire transfers can also move quickly through several institutions. Once the money reaches a controlled account and is dispersed, recovery becomes difficult.

A second channel is the most important control

The FBI advises organizations to verify any change in account number or payment procedure with the person making the request. That check must use contact details already known to the business, not those in the suspicious message.

Warning signs include:

  • A supplier announces new banking details shortly before payment.
  • The beneficiary name does not match the contracting company.
  • The receiving country changes without a documented business reason.
  • The sender insists that verification must remain inside email or chat.
  • A revised invoice has different fonts, spacing, account numbers, or terms.
  • Urgent customs, demurrage, inspection, or release fees appear unexpectedly.
  • The request bypasses the buyer’s normal purchase-order or approval process.
  • A supposed executive demands secrecy and discourages a telephone call.

Seven International Payment Frauds Businesses Encounter

A fake supplier can advertise machinery, electronics, vehicles, fabric, chemicals, or other goods it does not own. Stolen registration documents and polished catalogues make the company appear established.

Business email compromise takes a subtler route. The criminal gains access to a real mailbox or registers a lookalike domain, then changes the destination on a legitimate invoice.

Invoice manipulation can happen through an altered PDF, compromised accounting mailbox, or intercepted message. Every commercial detail remains correct except the bank account.

A fake freight forwarder or customs agent invents port charges, storage costs, inspection fees, insurance, or release payments. The demand arrives when delay feels expensive.

Advance-payment fraud begins with an attractive price and a request for a large deposit. After funds arrive, the supplier disappears, sends false shipping papers, or demands more money.

Chat impersonation moves the conversation to WhatsApp, Telegram, or another messaging service. A copied logo and familiar employee name make the new account feel like a convenient continuation.

A fake escrow or payment platform claims to protect both sides. In reality, the website, support team, and account dashboard are controlled by the same people running the trade scheme.

These categories overlap. A false supplier may also invent shipping fees, while a compromised vendor mailbox can direct the buyer to a fraudulent settlement portal.

The FBI’s business email compromise guidance describes spoofed domains, spearphishing, malware, and payment changes as common paths into this type of theft.

Reconstructed international supplier transfer approval showing recently changed bank details

How the International Payment Scam Works

Step 1: The criminal maps the transaction

Public websites, trade directories, shipment records, social profiles, leaked credentials, and earlier phishing provide names and roles. The attacker identifies who negotiates, who invoices, and who releases money.

A compromised inbox can reveal purchase orders, expected amounts, delivery dates, invoice templates, and writing style. This intelligence turns a generic fraud into a precise intervention.

Step 2: A trusted identity is copied or taken over

The criminal may use the supplier’s real account after stealing its password. Another option is a domain with one substituted letter or a misleading display name.

When an email thread is copied into a fresh message, the quoted history can make the conversation look continuous. A hurried reader may not notice that the address changed.

Step 3: The attacker waits for the right moment

Fraud works best when an invoice is due or goods are waiting at a port. The request then fits an existing obligation rather than asking for an unexplained transfer.

Criminals sometimes create mailbox rules that hide the real supplier’s replies. Both buyer and seller keep writing, but the attacker controls which messages each side sees.

Step 4: New banking instructions are introduced

The sender blames an audit, currency issue, frozen account, tax review, correspondent bank, or temporary collection partner. A revised PDF places the fraudulent beneficiary in an otherwise accurate invoice.

The explanation often sounds administrative and dull. That is intentional because a routine change attracts less scrutiny than an emotional story.

Step 5: Urgency suppresses normal verification

The message says production will stop, storage charges will rise, or the shipment will miss its vessel. Finance staff are asked to prove cooperation by acting quickly.

If someone requests a call, the attacker may say the account manager is traveling or that compliance rules prohibit discussion by telephone.

Step 6: Internal approval is steered toward the wrong evidence

A fake executive email can tell an employee that leadership already approved the change. Altered documents, copied signatures, and a chat message create several pieces of apparent confirmation.

All of those items can still come from one compromised channel. Genuine dual control requires independent people and independently sourced contact information.

Step 7: The transfer is dispersed rapidly

The first recipient may be a money mule, shell company, or account opened with stolen identity information. Funds can then move to additional banks, payment services, or crypto exchanges.

Delaying the buyer with a fake bank review or shipping update gives the network time to move the balance beyond the initial account.

Step 8: The attacker manages discovery

When the real supplier asks about payment, the criminal may send a forged transfer receipt or claim an international banking delay. The buyer waits instead of contacting its bank.

Some operations request a second payment, promising to refund the first after compliance clears it. This turns one compromised invoice into a larger loss.

A Safer International Payment Approval Process

Every supplier should have a verified master record containing its legal name, bank details, trusted telephone number, and approved contacts. Staff should not replace that record from an email alone.

When banking instructions change, pause the payment and call a known supplier contact. Read the existing and proposed account details aloud without telling the caller which values you expect.

Require a second employee to approve beneficiary changes and large transfers. The reviewer should examine the underlying request, not merely click an approval button.

Separate vendor onboarding from payment release when staffing allows. A single compromised account should not be able to create a supplier, change its bank, and send money.

Use a clear call-back rule for urgent freight and customs charges. The team should contact the carrier, broker, port agent, or insurer through the existing contract or official website.

Compare the beneficiary’s legal name and country with the purchase contract. A legitimate third-party collection account should be explained and documented before the due date.

Configure bank alerts and transfer limits that reflect normal trade activity. A new beneficiary, unusual country, round amount, or out-of-hours approval should trigger extra review.

Protect email with multifactor authentication and disable legacy access where possible. Review forwarding rules, delegated access, login history, and recovery settings after any suspicious message.

Train employees with realistic examples based on the company’s own workflow. A finance analyst needs to recognize changes to bank details, while a buyer needs to question an unexpected shipping agent.

Write the exception process down before a crisis. Employees should know who can approve an urgent change, which number to call, what evidence to record, and when the payment must remain paused.

Test those controls with suppliers as well. Agree on named contacts and a verification phrase for sensitive changes, then review that arrangement when personnel or ownership changes.

The goal is not to distrust every foreign partner. It is to make one compromised message insufficient to redirect a valuable payment.

Company, Address, and Fulfillment Checks

The legal supplier must exist independently

Verify business registration, tax details, directors, website history, trade references, and the address through sources the supplier did not provide in a single packet.

Stolen certificates can describe a real company while the person contacting you has no connection to it. Call the registered office through an independently found number.

The operating address should match the promised activity

A seller of industrial machinery should be able to explain where goods are manufactured, inspected, stored, and loaded. A virtual office alone does not support a large physical operation.

For high-value orders, use an independent inspection service selected by the buyer. Confirm the inspector’s identity separately and verify serial numbers or inventory before release.

The bank relationship must make commercial sense

Ask why the beneficiary differs from the contracting entity and why the account is located in another jurisdiction. Obtain written documentation and verify it through the known supplier contact.

Do not accept tax efficiency, agent collection, or internal restructuring as a complete answer. Your bank may also identify regulatory or sanctions concerns.

Shipment evidence must come from real carriers

Check bills of lading, container numbers, booking references, and tracking directly with the carrier or freight forwarder. A PDF and a seller-controlled tracking site can both be fabricated.

Confirm whether the document is original, surrendered, amended, or merely a draft. Shipment paperwork is evidence to verify, not a substitute for verification.

What to Do if You Have Fallen Victim to This Scam

  1. Contact the sending bank immediately. Ask for a wire recall or fraud hold and request that it contact the receiving institution. Minutes matter, so do not wait for the supposed supplier to investigate.
  2. Notify the real supplier through a trusted route. Use the telephone number or contact stored before the disputed email. Determine whether either mailbox was compromised.
  3. Preserve complete records. Export emails with headers, attachments, chat history, invoices, approval logs, bank instructions, telephone numbers, and transfer confirmations. Keep the original files unchanged.
  4. Report the incident quickly. U.S. businesses can file with the FBI Internet Crime Complaint Center. Notify the relevant national cybercrime and financial authorities in every involved jurisdiction.
  5. Contain compromised accounts. Reset passwords, revoke sessions, remove malicious forwarding rules, review delegated access, and require multifactor authentication. Check adjacent mailboxes used by finance and executives.
  6. Search for additional altered transactions. Review recent and pending beneficiary changes, invoices, payroll requests, tax payments, and freight charges. The discovered transfer may not be the first attempt.
  7. Inform insurers and counsel. Follow notification deadlines in cyber, crime, cargo, and professional policies. Legal advice may also be needed for privacy, contract, and regulatory notices.
  8. Pause related payments without abandoning the shipment. Rebuild a trusted communication path with the genuine supplier and carrier before deciding what remains payable.
  9. Scan exposed computers. If an attachment, login page, or remote tool may have started the compromise, isolate the affected device and run a full Malwarebytes scan as part of a broader incident response.
  10. Block repeat phishing infrastructure. AdGuard can help stop access to many known malicious domains and ads, but payment changes still require human call-back controls.
  11. Communicate on a need-to-know basis. Give banks and investigators accurate details while avoiding public posts that reveal internal controls or alert the attacker before accounts are frozen.
  12. Reject private recovery agents demanding fees. No outside contact can guarantee a wire return. Work with banks, insurers, law enforcement, and verified legal advisers.

Frequently Asked Questions

Is every third-party beneficiary fraudulent?

No. Suppliers can use financing, factoring, or collection arrangements. The relationship must be documented and confirmed through an established contact before payment.

Can a signed invoice prove new bank details are genuine?

No. A signature image and complete invoice can be copied or altered. Verify the change through a separate channel and internal approval process.

What if the email came from the supplier’s real domain?

The mailbox itself may be compromised. A correct address increases context, but it does not replace an independent call-back for changed payment instructions.

Should we reply to test whether the sender is legitimate?

A reply stays inside the possibly compromised channel. Contact a known person using a number or system obtained before the suspicious request.

Can a bank always reverse an international wire?

No. A rapid recall and receiving-bank alert may help, but recovery depends on timing, remaining funds, institutions, jurisdictions, and legal process.

Does cyber insurance cover this loss?

Coverage depends on policy language, controls, notifications, and facts. Report promptly to the insurer and follow its evidence and mitigation requirements.

The Bottom Line

An international payment scam succeeds when a believable message becomes the sole authority for moving money. A real invoice and real shipment can still carry fraudulent bank details.

Make every beneficiary change survive an independent call-back, a second approval, and a commercial-reason check. That short pause is far cheaper than trying to recover a cross-border transfer after it disperses.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Avocado Oil Scam: How Misleading Labels Sell Cheap and Adulterated Oil

Next

Messages Failed to Deliver Email Scam: Fake System Delay Alert Exposed