Fake invoice scams exploiting payment delays evolve with personalised phishing tactics

Cybercriminals are increasingly using personalised, convincingly timed invoice email scams to steal credentials and divert payments, prompting urgent alert and proactive security measures.

A phishing campaign posing as an invoice query is exploiting a familiar business headache: the claim that a payment has stalled because bank details are missing. According to cybersecurity write-ups from MalwareTips and PCRisk, the message is not a routine accounts request but a credential theft attempt designed to lure recipients on to a fake file-sharing page and capture email logins. FraudRoom and NatWest International both note that invoice-related scams often rely on the same trick: pressing staff to respond quickly to what appears to be a legitimate payment problem.

The scam typically arrives with language that sounds like ordinary back-office work, referring to a progress payment, invoice verification or missing banking information. MalwareTips says the button in the message may lead to a page that imitates a recognised document service, creating the illusion that the recipient must sign in before downloading a file. That step is crucial to the fraud: once the victim enters an email address and password, the attacker can use the inbox as a foothold into the wider business. OpenScam.app says criminals often research vendors in advance so the message looks even more credible.

What makes the lure effective is not just the false claim, but the way it borrows the rhythm of real finance work. Business inboxes routinely contain invoices, purchase orders and payment follow-ups, so a note about missing details may not immediately stand out. MalwareTips says the message can also use a prefilled email address on the fake page, which gives the login screen a personalised feel. But that apparent familiarity is often just evidence that the attacker already knows where the email was sent.

The danger extends well beyond the inbox itself. Once a mailbox is compromised, fraudsters can search for invoice threads, customer records, password reset messages and attachments, then use that material to launch further attacks. FraudRoom and NatWest International say invoice scams frequently lead to payment diversion, with criminals impersonating trusted counterparties to redirect money to accounts they control. Malwarebytes has also warned this year about fake invoice campaigns that were still being assembled as they were discovered, underscoring how active and adaptable this sort of fraud remains.

There are several warning signs. A request to confirm or re-enter an email password is a major red flag, because a genuine payer or document service does not need access to the victim’s mailbox. A mismatch between the sender’s display name and the actual email domain is another clue, as is any pressure to act immediately or bypass normal approval steps. Security advice from NatWest International and FraudRoom is consistent on one point: any change to payment details should be verified using contact information already on file, not the number or link supplied in the suspicious message.

Anyone who has clicked through should treat the incident as a potential account compromise. That means changing the password from a trusted device, signing out of other sessions, checking for forwarding rules or unauthorised delegates and alerting finance or security teams. If money has already moved or payment details were altered, the bank should be contacted straight away. If the message was merely opened, the safest response is to report it, delete it and remind colleagues that invoice fraud often begins with an apparently routine request.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.