Examples

Fake invoice examples and red flags

Training improves when AP teams see realistic patterns. Fake invoice scams usually combine a normal business pretext with one or two pressure signals.

Use these examples for awareness training, then run suspicious requests through the Invoice Scam Check before payment.

Realistic is the danger

The best fake invoice emails look boring. The danger is in changed payment instructions, urgency, domain mismatch, and missing verification.

Free AP Fraud SOP Kit

Turn this check into an AP policy

Get the vendor bank-change policy, callback script, approval note, incident checklist, and hold triggers for your finance team.

Get the SOP kit Future paid: saved checks, audit log, PDF reports, team templates - $19/mo teaser.

Example 1: vendor bank change

A known supplier claims their accounting team changed banks this week.

  • Red flag: new bank details by email.
  • Red flag: same-day payment pressure.
  • Control: callback on known vendor number and dual approval.

Example 2: reply-to mismatch

The From address appears corporate, but Reply-To points to a free-mail address.

  • Red flag: replies go outside the vendor domain.
  • Red flag: attacker controls the conversation after AP replies.
  • Control: start a fresh verification through known records.

Example 3: executive pressure

A CFO or CEO asks AP to process a confidential wire while unavailable.

  • Red flag: secrecy plus urgency.
  • Red flag: bypass of normal approval workflow.
  • Control: in-person or phone verification and dual approval.

Example 4: duplicate invoice with changed details

The invoice number and amount match a real prior bill, but the PDF footer contains a new routing number.

  • Red flag: a familiar document is being reused to lower suspicion.
  • Red flag: payment instructions differ from vendor history.
  • Control: compare against the prior paid invoice and call the vendor on the number already in master data.

Example 5: first-time vendor without a PO

AP receives an overdue notice for services nobody can match to a purchase order or internal owner.

  • Red flag: no PO, contract, receiving record, or named buyer.
  • Red flag: late fees and collection language create pressure.
  • Control: identify the internal requester and independently verify the vendor before onboarding or payment.

Example 6: compromised real vendor mailbox

The request comes from the vendor's real domain inside an existing thread and asks AP to use a new account.

  • Red flag: a correct domain does not prove the mailbox is still controlled by the vendor.
  • Red flag: the attacker waits for a real invoice cycle before changing payment instructions.
  • Control: start a separate callback using the phone number in trusted records.

Example 7: small test followed by a large wire

The sender requests a small payment first, then uses its successful receipt as proof that the new account is legitimate.

  • Red flag: receiving money proves control of an account, not ownership by the vendor.
  • Red flag: the full payment follows before independent verification.
  • Control: confirm account ownership and authorization through known vendor contacts before any test payment.

Example 8: invoice portal reset

A message says the vendor moved to a new billing portal and asks AP to sign in through an unfamiliar link.

  • Red flag: credential capture may be the first stage of a larger BEC attack.
  • Red flag: the portal domain differs from prior invoices or bookmarks.
  • Control: open the vendor portal from a saved bookmark or official site, never from the message.

Sources and verification

Use primary sources and the provider's official support channel before acting.

Fake Invoice Examples FAQ

Do fake invoices always use bad grammar?

No. Many are polished, targeted, and based on real vendor workflows.

Can an invoice be fake if the vendor is real?

Yes. Attackers can impersonate or compromise real vendors and redirect payment instructions.