Booking Invoice Email Scam: Fake PDF HTML Attachment Steals Your Login

A booking invoice lands in your inbox, and the attachment seems ready to open. It looks like a routine accounting task you could finish in seconds.

One detail in the filename changes the story. If you have received this message, check that detail before treating the attachment like a document.

Illustration of a booking invoice email with an HTML attachment disguised as a PDF

Overview

What the booking invoice message says

The reported message claims that a booking invoice is attached. It is short, signed as an accounts note, and built to look like ordinary business correspondence.

Its attachment uses a double extension: a name ending in .pdf.html. The PDF-looking middle section is bait. The final extension tells you it is an HTML page.

The image above illustrates that filename trick with fictional details. It is not a screenshot of the original email or a safe copy of its attachment.

Opening the file in a browser displays a document-like page with a password prompt. The page is not a normal PDF reader.

The risk is the password prompt

The reported page places a blurred invoice behind a login box. That visual says the file exists and access requires one last identity check.

The requested credential is the reader’s email password. An invoice from an unfamiliar sender has no legitimate reason to demand it.

A stolen mailbox password can expose messages and reset links for other accounts. It can also let an attacker write to customers as the victim.

  • The file is HTML, despite its PDF-like name.
  • The invoice image is a prop for a login request.
  • The password goes to an untrusted page, not an accounting system.
  • The safe verification route is a known contact, not the attachment.

The conclusion, with one important limit

Treat this booking invoice email as credential phishing. Do not open the attachment or enter a password into its page.

The original attachment was not supplied to us for independent forensic analysis. The reported mechanism is specific; the exact address receiving passwords was not verified here.

That limit does not make the message safe. A supposed invoice requiring your email password is enough reason to stop and verify elsewhere.

Why an Invoice Is a Better Lure Than a Wild Warning

Many suspicious emails threaten account closure or announce a prize. An invoice can be quieter and more effective because accounting teams receive them every day.

The subject may begin with “FWD,” implying the message came through an existing conversation. A recipient scanning quickly might overlook the actual sender.

Booking language also reaches beyond travel. A small business may book equipment, services, rooms, freight, or event space and expect paperwork afterward.

The email does not need to know which kind of booking you made. It only needs to arrive when you have another invoice on your mind.

A brief message can seem more professional than a dramatic one. The absence of a long sales pitch is not an authenticity signal.

An accounts signature gives the email a person to trust. Names and job titles can be typed into a template by anyone.

The attached file creates another small illusion. A reader sees a familiar PDF icon or the letters “pdf” and assumes the computer will open a document.

On some systems, the final extension is hidden or truncated in a narrow mail window. A filename deserves a second look before opening.

The legitimate question is simple: were you expecting an invoice from this exact sender for this exact transaction?

If the answer is no, the attachment should not become the place where you find out. Confirm the booking through a known channel.

Why the PDF-Looking Filename Matters

A true PDF typically ends in .pdf. A file ending in .html is a web page, even if “pdf” appears earlier in the name.

That difference changes the trust model. The attachment can render forms and scripts in a browser rather than merely display a document.

HTML files can be used legitimately, but an unexpected invoice attachment carrying a credential form is not a normal business document.

The browser may show a local file address rather than a familiar website. That can make the page feel private or self-contained.

Local display does not mean a submitted form stays local. An HTML page can send entered information to a remote server when network access is available.

It may also load images or code from external sites. The critical risk here is entering your password, not the visual act of seeing a blurred invoice.

Do not assume that every HTML attachment installs malware. This specimen is described as credential phishing. Other attachments can use different techniques.

That distinction matters after exposure. Someone who only previewed the email needs different steps from someone who entered an email password.

A PDF viewer should not ask for your mailbox password to display a supplier invoice. A password-protected document would use a document password shared separately.

If the prompt is framed as “sign in to view,” ask whose service you are signing into. The attachment cannot become your email provider merely by copying its colors.

How the Booking Invoice Email Scam Works

Step 1: A routine accounts message reaches the inbox

The email presents an invoice reference and a polite note. There may be no obvious threat, which helps it blend with genuine business mail.

The sender can target a broad list without knowing whether anyone made a booking. One person expecting paperwork may be enough.

Forwarded-message styling can add another layer of apparent history. It does not prove that a real colleague forwarded the invoice.

Before opening anything, compare the full sender address with the company you actually dealt with. Display names are easy to imitate.

Step 2: The attachment impersonates a PDF

A filename ending in .pdf.html places the trusted-looking type before the real extension. The final suffix is the one your computer uses.

A hurried reader may see only the invoice number and “pdf.” That is why the exact filename is more informative than the file icon.

If your mail app hides extensions, view the attachment details without opening it. Ask IT for help if the file type remains unclear.

Do not forward the attachment to another coworker as a test. That merely moves the risk to someone else’s inbox.

Step 3: A browser page displays a blurred invoice

The HTML file opens a page that resembles a document viewer. A blurred page suggests the invoice is present but locked behind verification.

That is theater, not proof of a valid booking. The background can be an image placed behind any form.

The fake viewer may borrow familiar colors, icons, or PDF terminology. None of those elements identifies the server that receives the form.

Even if the page shows your email address, it may have read it from the message or file. A prefilled field is not evidence of account ownership.

Step 4: The form asks for an email password

This is the decisive moment. Entering the password can give the operator of the page a credential for your real mailbox.

The page may say verification is necessary to unlock the invoice. An unrelated invoice sender cannot validate your email account that way.

Do not try a “wrong” password to test it. That can still reveal information about your account and may lead to another prompt.

Close the page and use a known contact at the supposed sender if you need to confirm whether a booking exists.

Step 5: Mail access can support a second attack

With access to an inbox, an attacker can search for invoices, payment conversations, and password-reset messages. Business mailboxes are especially valuable.

They may create a forwarding rule so new mail continues to reach them after the password changes.

They could also send a convincing follow-up invoice to a customer who has already corresponded with you. The conversation history makes that message believable.

Those outcomes are risks, not proof they happened in every case. Check actual account activity and mail settings before concluding what was exposed.

How to Verify a Real Booking Invoice

Start with the purchase or booking record you already have. Does its date, amount, and supplier match the email’s claim?

Open the supplier’s website from your own bookmark or type its known address. A real invoice may be available in your account’s billing area.

If a colleague arranged the booking, ask them through your normal work chat or call them. Avoid replying to the suspicious email to ask whether it is real.

Call the supplier using a number from a previous invoice or its verified website. Do not use a phone number supplied only in the new message.

For a business, keep a shared process for unexpected invoices. A second person should approve payments or account changes when the transaction is unusual.

The process should also cover attachments. A document request can be fraudulent even when no immediate payment is requested.

If the supplier confirms an invoice exists, ask them to send it through their usual portal. The existence of a real booking does not authenticate the attachment.

Keep the suspicious message for your security team. Headers and attachment names may help them block similar mail for everyone.

Do not publish the original attachment or upload it to a public scanner if it contains customer information. An administrator can choose an appropriate analysis method.

A real invoice should stand on its commercial facts. It should not require your email password to prove that it exists.

Sender and Attachment Checks That Help

Read the address after the display name

“Accounts” or a person’s name is editable text. The domain in the full address should match an organization you recognize.

A matching domain is helpful but not conclusive. A compromised supplier account can send a malicious file from a real mailbox.

Check the context: order number, previous conversation, expected timing, and whether the supplier normally sends files this way.

Expose the final extension

On Windows, file extensions can be shown in File Explorer. On other systems, inspect file details or ask your IT team.

The rule is not “all HTML files are dangerous.” The rule is that an unsolicited invoice disguised as a PDF deserves independent verification.

Do not rely solely on a red PDF icon. An attacker can select an icon that looks familiar while the file remains HTML.

Notice what the page asks you to do

An invoice may ask you to confirm a purchase with your supplier. It should not ask for your primary email password inside an attachment.

Some fake pages also request a one-time code after a password. Never share a sign-in code to access an unsolicited file.

If a real service requires authentication, navigate to it independently and check the document there.

What to Do if You Have Fallen Victim to This Scam

  1. If you only received the email, do not open the file. Mark it as phishing and tell your workplace administrator if it reached a business inbox.

    Receiving a message does not compromise your account. Verification is only necessary if the claimed booking matters to you.

  2. If you opened the HTML file but entered nothing, close it. Check for unexpected downloads or browser notification requests.

    A Malwarebytes scan is sensible if a file downloaded or you ran something. Seeing the fake viewer alone does not establish an infection.

  3. If you entered a password, change it from a clean device. Use your email provider’s known website, then sign out of other sessions.

    Enable multifactor authentication and change any other account using the same password. Prioritize the mailbox that receives your reset links.

  4. Inspect mailbox rules and recent logins. Remove unknown forwarding addresses, connected apps, delegated users, and recovery details.

    A workplace administrator can check audit logs and alert colleagues if the account sent messages after the suspicious login.

  5. Protect financial conversations. Tell your bank or payment provider if an invoice or transfer was altered after the email account was exposed.

    Warn affected customers through a separate trusted channel if your mailbox was used to send fraudulent payment instructions.

  6. Report and retain evidence. Preserve the email headers, attachment name, time opened, and any unusual account activity.

    Report the message through your provider. AdGuard can reduce malicious advertising, but it cannot undo a stolen password or a bank transfer.

Is Your Device Infected? Run a Free Malware Scan

Slow performance, constant pop-ups, or strange behavior? These are classic signs of a malware infection. The fastest way to find out is to scan your device with Malwarebytes Free — one of the most trusted malware removal tools available.

The free version detects and removes the most common threats, including:

  • Adware — the cause of those annoying pop-ups
  • Browser hijackers — unwanted redirects and changed homepages
  • Trojans and spyware — hidden programs stealing your data
  • Potentially unwanted programs (PUPs) — software you never asked for

👉 Select your device below — Windows, Mac, or Android — then follow the simple steps to download Malwarebytes, scan your system, and remove any threats it finds. The scan usually takes 5 to 20 minutes.

Malwarebytes for WindowsMalwarebytes for MacMalwarebytes for Android

Run a Malware Scan with Malwarebytes for Windows

Malwarebytes is one of the most popular and trusted anti-malware tools for Windows — and it’s completely free for removing infections. It catches threats that many antivirus programs miss, including adware, browser hijackers, and trojans. Follow the steps below to scan and clean your PC in just a few minutes.

  1. Download Malwarebytes

    Click the button below to download the latest version of Malwarebytes for Windows from the official source. The free version is all you need — it will scan your computer and remove adware, browser hijackers, and other malicious software at no cost.

    Malwarebytes Free for WindowsScans and removes malware at no cost
    Download MalwarebytesOfficial installer for Windows 11 and 10. Your download starts right away.Want real-time protection? See Malwarebytes Premium
  2. Install Malwarebytes

    When the download finishes, open your Downloads folder and double-click the MBSetup file. If Windows shows a User Account Control pop-up, click “Yes” to allow the installation.

    MBAM1
  3. Follow the On-Screen Prompts to Install Malwarebytes

    The setup wizard will walk you through a few quick screens:

    • Choose where you’re installing the program — “Personal Computer” or “Work Computer” — then click Next.

      MBAM3 1
    • Malwarebytes will now install on your device. This usually takes under a minute.

      MBAM4
    • When installation is complete, the “Welcome to Malwarebytes” screen will open automatically.

      MBAM6 1
    • On the final screen, click Open Malwarebytes to launch the program.

      MBAM5 1
  4. Enable “Scan for Rootkits”

    Before scanning, turn on rootkit detection so Malwarebytes can find even the most hidden threats. Click the Settings gear icon on the left side of the screen.

    MBAM8

    In the settings menu, find “Scan for rootkits” and click the toggle so it turns blue.

    MBAM9

    Done? Click “Dashboard” in the left pane to return to the main screen.

  5. Start the Scan

    Click the blue Scan button. Malwarebytes will automatically update its virus database and start checking your computer for malware.

    MBAM10
  6. Wait for the Scan to Finish

    The scan checks your entire system for browser hijackers and other malicious programs, so it can take 5 to 20 minutes depending on your computer. Feel free to do something else — just check back occasionally to see the progress.

    MBAM11
  7. Quarantine the Detected Threats

    When the scan is done, you’ll see a list of everything Malwarebytes found — malware, adware, and potentially unwanted programs. Click the “Quarantine” button to remove all of them at once.

    MBAM12

    Malwarebytes will now remove the malicious files and registry entries and move them safely into quarantine.

    MBAM13
  8. Restart Your Computer

    Some threats can only be fully removed after a reboot. If Malwarebytes asks you to restart, click Yes. Once you’re logged back in, Malwarebytes has finished removing the threats it found.

    MBAM14

That’s it — your Windows PC is now clean of trojans, adware, and other malware, and should be back to running smoothly.

Keep your PC protectedStop the next infection before it starts
If your antivirus let this threat through, it may not be enough on its own. Malwarebytes Premium adds real-time protection that blocks malware, ransomware, and malicious websites before they can infect your computer.See Malwarebytes Premium

If you are still having problems with your computer after completing these instructions, then please follow one of the steps:

Run a Malware Scan with Malwarebytes for Mac

Malwarebytes for Mac is a free on-demand scanner that removes the malware other security software tends to miss — adware, browser hijackers, and unwanted programs included. Cleaning an infected Mac with Malwarebytes has always been completely free, and it’s our go-to recommendation. Follow the steps below to scan and clean your Mac in just a few minutes.

  1. Download Malwarebytes for Mac

    Click the button below to download the latest version of Malwarebytes for Mac.

    Malwarebytes Free for MacScans and removes malware at no cost
    Download MalwarebytesOfficial installer for macOS. Your download starts right away.Want real-time protection? See Malwarebytes Premium
  2. Open the Malwarebytes setup file

    When the download finishes, open your Downloads folder and double-click the setup file to begin the installation.

    Double-click on setup file to install Malwarebytes

  3. Follow the On-Screen Prompts to Install Malwarebytes

    The Malwarebytes for Mac Installer will guide you through a few quick screens. Click “Continue” and keep following the prompts until the installation completes.

    Click Continue to install Malwarebytes for Mac

    Click again on Continue to install Malwarebytes for Mac

    Click Install to install Malwarebytes on Mac

    When the installation is complete, Malwarebytes opens to the Welcome to Malwarebytes screen. Click “Get started“.

  4. Select “Personal Computer” or “Work Computer”

    Malwarebytes will ask what type of computer you’re installing it on. Click either Personal Computer or Work Computer, whichever applies.
    Select Personal Computer or Work Computer mac

  5. Start the Scan

    Click the “Scan” button. Malwarebytes will automatically update its detection database and begin checking your Mac for malware.
    Click on Scan button to start a system scan Mac

  6. Wait for the Scan to Finish

    Malwarebytes will scan your Mac for adware, browser hijackers, and other malicious programs. This can take a few minutes, so feel free to do something else — just check back occasionally to see the progress.
    Wait for Malwarebytes for Mac to scan for malware

  7. Quarantine the Detected Threats

    When the scan is done, you’ll see a list of everything Malwarebytes found. Click the “Quarantine” button to remove all the threats at once.
    Review the malicious programs and click on Quarantine to remove malware

  8. Restart Your Mac

    Malwarebytes will now remove all the malicious files it found. Some threats can only be fully removed after a reboot — if Malwarebytes asks you to restart, allow it. Once you’re logged back in, your Mac is clean.
    Malwarebytes For Mac requesting to restart computer

That’s it — your Mac is now free of adware, rogue browser extensions, and other potentially harmful software.

Keep your Mac protectedStop the next infection before it starts
If your Mac got infected, its built-in protection may not be enough on its own. Malwarebytes Premium for Mac adds real-time protection that blocks malware and adware before they can infect your Mac.See Malwarebytes Premium

If you are still experiencing problems while trying to remove a malicious program from your computer, please ask for help in our Mac Malware Removal Help & Support forum.

Run a Malware Scan with Malwarebytes for Android

Malwarebytes for Android automatically detects and removes dangerous threats like malware and ransomware so you don’t have to worry about your most-used device being compromised. Aggressive detection of adware and potentially unwanted programs keeps your Android phone or tablet running smooth.

  1. Download Malwarebytes for Android.

    You can download Malwarebytes for Android by clicking the link below.

    Malwarebytes for AndroidScans your phone and removes malware at no cost
    Get Malwarebytes for AndroidOpens Google Play in a new tab.Want real-time protection? See Malwarebytes Premium for Android
  2. Install Malwarebytes for Android on your phone.

    In the Google Play Store, tap “Install” to install Malwarebytes for Android on your device.

    Tap Install to install Malwarebytes for Android

    When the installation process has finished, tap “Open” to begin using Malwarebytes for Android. You can also open Malwarebytes by tapping on its icon in your phone menu or home screen.
    Malwarebytes for Android - Open App

  3. Follow the on-screen prompts to complete the setup process

    When Malwarebytes will open, you will see the Malwarebytes Setup Wizard which will guide you through a series of permissions and other setup options.
    This is the first of two screens that explain the difference between the Premium and Free versions. Swipe this screen to continue.
    Malwarebytes Setup Screen 1
    Tap on “Got it” to proceed to the next step.
    Malwarebytes Setup Screen 2
    Malwarebytes for Android will now ask for a set of permissions that are required to scan your device and protect it from malware. Tap on “Give permission” to continue.
    Malwarebytes Setup Screen 3
    Tap on “Allow” to permit Malwarebytes to access the files on your phone.
    Malwarebytes Setup Screen 4

  4. Update database and run a scan with Malwarebytes for Android

    You will now be prompted to update the Malwarebytes database and run a full system scan.

    Malwarebytes fix issue

    Click on “Update database” to update the Malwarebytes for Android definitions to the latest version, then click on “Run full scan” to perform a system scan.

    Update database and run Malwarebytes scan on phone

  5. Wait for the Malwarebytes scan to complete.

    Malwarebytes will now start scanning your phone for adware and other malicious apps. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.
    Malwarebytes scanning Android for Vmalware

  6. Click on “Remove Selected”.

    When the scan has been completed, you will be presented with a screen showing the malware infections that Malwarebytes for Android has detected. To remove the malicious apps that Malwarebytes has found, tap on the “Remove Selected” button.
    Remove malware from your phone

  7. Restart your phone.

    Malwarebytes for Android will now remove all the malicious apps that it has found. To complete the malware removal process, Malwarebytes may ask you to restart your device.


That’s it — your Android phone is now clean — no more malicious apps, adware, or browser redirects.

Keep your phone protectedStop the next infection before it starts
Malwarebytes for Android Premium adds real-time protection that blocks malicious apps and scam links before they can harm your phone.See Malwarebytes for Android

If you are still having problems with your phone after completing these instructions, then please follow one of the steps:

Stay Protected: Block Ads and Malicious Sites

Now that your device is clean, keep it that way. Most infections start with a malicious ad or a fake download button — so blocking them at the source is your best defense.

We recommend AdGuard, which blocks malicious ads, phishing pages, and dangerous redirects before they can reach you.

👉 Download AdGuard and browse safely

Why This Is Not an Ordinary PDF Problem

It is tempting to focus on whether the attachment “contains a virus.” That question misses the most direct danger described for this sample.

The attacker does not need to infect a computer if the reader voluntarily enters a valid email password into a fake viewer.

Security software can help with malicious downloads. It cannot reliably tell you whether a polished form has a legitimate reason to ask for credentials.

The best defense is to separate document verification from account authentication. An invoice from a new sender should be checked through the supplier, not the attachment.

Even a real-looking invoice image can be copied or fabricated. Check payment instructions against a previously verified channel before changing bank details.

That habit protects against a wider class of business email scams, not just this one filename.

If your organization sees multiple copies, treat them as one incident. Central reporting helps administrators block the message and notify other recipients.

Do not shame the person who opened it. Fast reporting can prevent a stolen password from becoming a larger financial loss.

Frequently Asked Questions

Is .pdf.html really a PDF?

No. The final extension is HTML, so the file opens as a web page. The earlier “pdf” text is part of its deceptive name.

Can opening the attachment steal my password automatically?

The reported mechanism asks the reader to type a password. Do not assume automatic theft from simply viewing it, but investigate any downloads or scripts.

Why does the fake invoice look blurred?

The blur makes a document appear present but inaccessible. It encourages the reader to treat the password box as a normal unlocking step.

What if I really have a booking with a similar invoice number?

Contact the supplier using a known number or sign in through its established portal. A real transaction does not make an unsolicited attachment safe.

Should I change my password if I only read the email?

No password change is needed solely because the email arrived. Change it promptly if you entered it on the fake page or see suspicious activity.

Can Malwarebytes recover my mailbox after phishing?

Malwarebytes can check for malicious software. Account recovery requires changing credentials, ending sessions, reviewing mailbox settings, and contacting your provider.

The Bottom Line

Do not open a booking invoice attachment that ends in .pdf.html and asks for your email password. Verify the transaction with the sender through a channel you already trust.

If you entered a password, secure the mailbox immediately and inspect forwarding rules. The fastest useful step is account recovery, not repeatedly reopening the suspicious file.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Music Membership Renewal Scam: The Fake Billing Email That Steals Logins

Next

File to Review and Sign Email Scam: Fake SharePoint Portal Fully Explained