Example 1: vendor bank change
A known supplier claims their accounting team changed banks this week.
- Red flag: new bank details by email.
- Red flag: same-day payment pressure.
- Control: callback on known vendor number and dual approval.
Example 2: reply-to mismatch
The From address appears corporate, but Reply-To points to a free-mail address.
- Red flag: replies go outside the vendor domain.
- Red flag: attacker controls the conversation after AP replies.
- Control: start a fresh verification through known records.
Example 3: executive pressure
A CFO or CEO asks AP to process a confidential wire while unavailable.
- Red flag: secrecy plus urgency.
- Red flag: bypass of normal approval workflow.
- Control: in-person or phone verification and dual approval.
Example 4: duplicate invoice with changed details
The invoice number and amount match a real prior bill, but the PDF footer contains a new routing number.
- Red flag: a familiar document is being reused to lower suspicion.
- Red flag: payment instructions differ from vendor history.
- Control: compare against the prior paid invoice and call the vendor on the number already in master data.
Example 5: first-time vendor without a PO
AP receives an overdue notice for services nobody can match to a purchase order or internal owner.
- Red flag: no PO, contract, receiving record, or named buyer.
- Red flag: late fees and collection language create pressure.
- Control: identify the internal requester and independently verify the vendor before onboarding or payment.
Example 6: compromised real vendor mailbox
The request comes from the vendor's real domain inside an existing thread and asks AP to use a new account.
- Red flag: a correct domain does not prove the mailbox is still controlled by the vendor.
- Red flag: the attacker waits for a real invoice cycle before changing payment instructions.
- Control: start a separate callback using the phone number in trusted records.
Example 7: small test followed by a large wire
The sender requests a small payment first, then uses its successful receipt as proof that the new account is legitimate.
- Red flag: receiving money proves control of an account, not ownership by the vendor.
- Red flag: the full payment follows before independent verification.
- Control: confirm account ownership and authorization through known vendor contacts before any test payment.
Example 8: invoice portal reset
A message says the vendor moved to a new billing portal and asks AP to sign in through an unfamiliar link.
- Red flag: credential capture may be the first stage of a larger BEC attack.
- Red flag: the portal domain differs from prior invoices or bookmarks.
- Control: open the vendor portal from a saved bookmark or official site, never from the message.
Sources and verification
Use primary sources and the provider's official support channel before acting.
Fake Invoice Examples FAQ
Do fake invoices always use bad grammar?
No. Many are polished, targeted, and based on real vendor workflows.
Can an invoice be fake if the vendor is real?
Yes. Attackers can impersonate or compromise real vendors and redirect payment instructions.