Fake invoices exploit the fact that a busy team pays many routine bills. They may demand payment for a listing, software renewal or service nobody ordered. Some attachments and links are phishing attempts aimed at business accounts rather than a bill at all.
Before you start
Keep purchasing records and approved-vendor contacts separate from the incoming email. If you are not the buyer, involve the person who normally approves this category.Do it step by step
- Read the vendor name, service period, purchase order and amount without opening unexpected attachments or calling the number printed on the invoice.
- Search internal records for an actual order, contract or prior invoice. An invoice number alone is easy for a scammer to invent.
- Contact the claimed vendor using a number or portal already in your records. Ask whether the invoice exists and whether the payment destination is unchanged.
- If no purchase exists, mark the message as suspicious under your team's process and tell the accounts-payable staff not to pay it. Keep evidence without forwarding a live malicious link broadly.
- If someone already paid or opened a credential-harvesting page, contact the bank immediately and secure the affected account. Document the invoice and report fraud through the relevant channel.