Email and invoice fraud

A fake invoice email is impersonating your business: what to do before and after payment

An email can impersonate a vendor, executive, or familiar company to change bank details, collect for nonexistent services, or steal credentials. It may us

Leer en español

An email can impersonate a vendor, executive, or familiar company to change bank details, collect for nonexistent services, or steal credentials. It may use a lookalike domain, a spoofed address, or a genuinely compromised account.

EXECUTIVE SUMMARY

What decision-makers should know

An email can impersonate a vendor, executive, or familiar company to change bank details, collect for nonexistent services, or steal credentials. It may us

    Do not pay until you verify through another channel

    An unexpected invoice, changed bank account, or urgent executive request should stop the ordinary process. Do not reply in the same thread, call the number in the signature, or open links and attachments to investigate. Find the vendor’s number in a contract, a previously verified invoice, or its official website and speak with a known contact. The FBI recommends verifying changes in account numbers or payment procedures directly with the requester.

    Check the purchase order, contract, delivery, amount, currency, beneficiary, and internal approval. A basic fake invoice charges for something never ordered; business email compromise may enter a genuine conversation after an account is breached. Knowing names, projects, or amounts does not prove authenticity. Attackers may study social media, mailboxes, and earlier correspondence.

    Train staff to notice tiny domain changes, a different reply address, secrecy, artificial deadlines, and unusual payment methods. Still, do not make one employee the only safeguard. Sensitive payments need a verifiable process, separated duties, and independent confirmation for account changes through a channel that does not depend on the incoming email.

    • Original message and headers
    • Invoice and beneficiary account
    • Related contract and order
    • Independent verification channel
    • Exact time of any payment

    Preserve evidence and separate the scenarios

    Save the original message in its complete format, not only a screenshot. Preserve headers, displayed sender, reply address, links without visiting them, unopened attachments, invoice, conversation, date, time zone, and payment details. Headers can help security teams or providers distinguish domain spoofing, a compromised mailbox, and an outside service used to send fraud.

    Determine whether the message actually left your systems. Look for unknown logins, forwarding rules, delegates, connected apps, recovery changes, sessions, sent mail, and deleted messages. Check the vendor’s account when it can cooperate. A lookalike domain may require reports to a registrar, host, or mail provider; a hacked authentic account requires recovery and containment. Both can occur together.

    Do not delete the account or restore everything before retaining relevant records. Restrict access, change credentials from clean devices, use strong authentication, and check reused secrets. Involve technology, finance, privacy, and leadership according to scope. Never publish complete headers, account numbers, signatures, documents, or personal details in a customer warning.

    If money moved, act immediately

    Contact your bank or payment provider immediately through a verified number and ask it to contact the receiving institution. Provide the unaltered amount, time, reference, beneficiary, and account. The FBI tells BEC victims to contact their financial institution promptly. Do not promise recovery: speed may help, but the result depends on the institutions, payment method, country, and elapsed time.

    In the United States, the FBI directs BEC reports to IC3.gov, and the FTC accepts reports at ReportFraud.ftc.gov. The FTC also identifies the Anti-Phishing Working Group for forwarded phishing emails. Spain, Mexico, and other countries have their own banks, police, and cybersecurity bodies. Use applicable official channels and preserve reference numbers; this guide does not determine legal reporting duties.

    If passwords, documents, or bank details were disclosed, the response does not end with a payment recall. Secure affected accounts, review later activity, and guide each person without requesting more sensitive information by email. Do not pay a recovery service that guarantees it can return the funds; that promise may be another scam.

    Protect reputation without amplifying the fraud

    When someone impersonates your business, warn exposed customers or vendors promptly through the official website, a known phone number, authentic social accounts, or authenticated email. The FTC advises leaving links out of an email warning so it does not resemble phishing. Identify the false address, the unauthorized request, the real verification process, and the right contact. Date and update the notice.

    Configure email authentication with your provider and have specialists review SPF, DKIM, and DMARC. These controls help receiving systems evaluate mail but do not stop someone registering a lookalike domain or compromising a mailbox. Register critical variants where reasonable, monitor domains, and train vendors. Maintain an approved bank-account list and require two-person confirmation for changes.

    ReputationGeo.ai can organize evidence, map domains and profiles, prepare bilingual reports, draft warnings, and monitor reappearances. Banks, providers, registrars, platforms, and authorities make their own decisions. We do not guarantee removal, blocking, actor identification, recovery, or timing. This is general information, not technical, financial, or legal advice tailored to a specific incident.

    How to turn this guidance into a responsible plan

    Begin with evidence, not assumptions. Save the exact URLs, screenshots, publication dates, search phrases, review profiles and AI answers that are creating concern. Record where each item appears, who controls the source and whether the information is inaccurate, outdated, private, misleading or simply unfavorable. These distinctions matter because removal, correction, response, suppression and monitoring are different remedies. A credible adviser should explain those differences before recommending work or discussing timing.

    Next, define the audience and the decision at risk. A result seen by prospective clients in Spain may require different language, sources and local signals from a result affecting investors in the United States. Decide which names, brands, locations and search questions matter most. Prioritization prevents a campaign from becoming a vague attempt to control the internet and turns it into a measurable program focused on accuracy, trust and discoverability.

    Evidence, people and measurements to prepare

    Create a baseline before changes begin. It can include the first two pages of Google for agreed searches, ratings and review volume, visibility of owned pages, recurring themes in AI answers and the status of platform or publisher requests. Keep personal data to the minimum necessary and share sensitive documents only through an agreed secure process. If a legal right may apply, involve qualified counsel in the relevant jurisdiction; reputation strategy does not replace legal advice.

    Assign an owner for approvals, factual verification and customer responses. Review progress consistently, but do not judge the program by one daily ranking. Useful measures include corrected or removed items, response completion, the share of credible owned and independent sources, search-result composition, branded query trends and whether public information answers real questions. The objective is a more accurate and resilient digital record, not an artificial promise that criticism will disappear.

    Keep a decision record, not just a list of links

    For every material item, record the exact source, the factual concern, the person responsible for verification, the proposed route and the reason that route is proportionate. Include the date of any request, response deadline, platform reference number and next review date. This record prevents duplicate or contradictory reports and helps a new decision-maker understand why an item was corrected, challenged, answered, monitored or left alone.

    A sound record also separates confirmed facts from interpretations. Label legal questions for qualified counsel, service failures for operational owners and public explanations for communications review. If an item changes, preserve the before-and-after evidence without collecting more personal data than necessary. This discipline is especially important when search engines and AI systems update unpredictably: it shows what actually changed and avoids claiming credit for movements that may have several causes.

    • Source, URL, date and affected search or prompt
    • Verified facts, disputed claims and supporting evidence
    • Chosen route, owner, status and next review date
    • Privacy, amplification and escalation risks

    Related ReputationGeo.ai services

    Use these service pages to distinguish image removal, broader content removal and search delisting before choosing a route.

    Frequently asked questions

    Official sources and further reading

    Rules and procedures change. Check the current official guidance before submitting a request.

    The practical next step

    Document the relevant URLs, searches and facts before acting. A responsible plan should separate what can be corrected or removed from what needs response, suppression or monitoring. The correct approach depends on the source, market and evidence.

    Apply the guide to your specific situation.

    Send the public links and the market affected. We will explain the realistic options and dependencies.

    Protected by a hidden spam-control field. No advertising trackers are loaded with this form.