An invoice arrives as an email attachment. It has a logo, a due date, an amount, and it looks exactly like the dozens your accounts payable team processes every week. That ordinariness is the whole weapon. Fake invoices work because they blend into routine, and a small business without a verification habit will quietly pay one before anyone thinks to ask whether it is real.
Invoice fraud has grown more convincing and more technical, mixing old tricks like a bill for something you never ordered with newer ones like a QR code that reroutes your payment. Microsoft reported a 146 percent jump in QR-code phishing in early 2026, and the invoice is a favorite disguise for it. Here are eleven tactics hitting small businesses through email attachments, and how to shut each one down.
Bottom line first
Fake invoices try to get paid by looking routine, creating urgency, or hiding a trap in the attachment. The defenses are the same across all of them: match every invoice to a real purchase order and a known vendor before paying, verify any new or changed payment detail by calling the vendor on a number you already had, and never pay by scanning a QR code or clicking a “pay now” link inside an invoice. Do not enable macros or open unexpected attachments, require a second approver for payments, and treat urgency as a reason to slow down. If it cannot be matched and verified, it does not get paid.
Table of Contents
1. An invoice for something you never ordered
The oldest trick still works: a bill for goods or services your company never bought, sent in the hope that a busy AP team pays anything that looks like a routine invoice. Office supplies, directory listings, and domain or ad “renewals” are common covers. The defense is simple and non-negotiable: no invoice gets paid without matching it to a real purchase order or a known, approved expense. If nobody can point to what was actually ordered, the invoice does not get paid.
2. A spoofed or lookalike vendor domain
The invoice appears to come from a supplier you use, but the sending address is subtly wrong, a domain one character off, an extra word, or a different ending. Attackers register these lookalikes because the display name reads correctly at a glance. Always check the full email address, not just the sender name, and be suspicious of any tiny discrepancy from the address your vendor normally uses. A near-match is a red flag, not a coincidence.
3. A QR code to “pay faster”
This is the fast-growing one. The invoice includes a QR code presented as a convenient way to pay, but scanning it sends your payment or login to the attacker. It is effective because a QR code is just an image, so the malicious link inside it slips past email filters that scan for bad text links, and scanning it usually pulls the victim onto a personal phone outside the company’s protections. The rule is blunt: never pay an invoice by scanning a QR code in an email. Pay only through the vendor details you already have on file.
4. A malicious PDF or HTML attachment
Sometimes the “invoice” is the weapon. The attached PDF or HTML file is not a bill at all but malware, or a fake login page that harvests your credentials the moment you enter them. HTML attachments are especially sneaky because they open a convincing but fraudulent portal right in your browser. Do not open invoice attachments you were not expecting, and never enter your email or banking login into a page that opened from one. A real invoice does not need you to sign in to view it.
5. A macro-enabled document
An attached Word or Excel “invoice” opens and prompts you to enable content or enable macros to see it properly. Clicking that runs hidden code that can install malware on your machine. Legitimate invoices are plain PDFs or documents that display without asking you to unlock anything. Treat any attachment that demands you enable macros as hostile, close it, and delete it. No genuine supplier sends a bill that only works if you disable your own security.
6. Changed bank details on a familiar invoice
An invoice that otherwise looks right quietly lists a new bank account, hoping you pay without noticing. This is one of the most expensive versions, because the money goes straight to the fraudster. Any change to a vendor’s payment details must be verified by calling them on a number you already had, never the number on the new invoice. This tactic overlaps closely with the fake bank-change request, which we cover in depth in our guide to vendor bank-change requests that are usually fraud.
7. A fake subscription or renewal notice
These pose as invoices or receipts for a service you supposedly subscribed to, an antivirus, a support plan, a software renewal, often for a startling amount, with a phone number to “cancel” or “dispute.” Call it and a fake agent walks you into handing over card details or remote access to “refund” you. The renewal never existed. Do not call the number on a surprise renewal invoice; check the account directly with the real provider using contact details you look up yourself.
8. Urgency and overdue threats
Fraudulent invoices lean hard on pressure: “final notice,” “account will be suspended,” “late fee applies today.” The urgency exists to stop you verifying before you pay. A real vendor relationship is not destroyed by a one-day check, and threats of immediate consequences are a manipulation tactic, not a genuine deadline. Any invoice pushing you to pay right now, without your usual review, has earned extra scrutiny rather than a fast payment.
9. An embedded “view invoice” or “pay now” link
Instead of a plain attachment, the email offers a button or link to view or pay the invoice online, which leads to a phishing page built to steal your login or card. The page can look identical to a real payment portal. Hover over any link to see where it actually goes before clicking, and reach payment portals by typing the known address yourself rather than following a link in an invoice email. If the destination does not clearly match the real vendor, do not proceed.
10. A small change to a real recurring bill
For a bill you pay regularly, fraudsters sometimes alter just one detail, a slightly higher amount or a changed reference, betting it gets rubber-stamped because the invoice is familiar. This is why even routine, expected invoices deserve a quick check against the agreed amount and the vendor’s normal pattern. A figure that does not match the contract or the usual charge is worth a pause, however ordinary the rest of the invoice looks.
11. A hijacked email thread
The most convincing fakes come from inside a real conversation. If a vendor’s or colleague’s mailbox is compromised, the fraudulent invoice arrives as a reply within a genuine email thread, with real history above it, so it reads as completely legitimate. Correct context is not proof of legitimacy; it usually means someone has been reading the real correspondence. Verify any payment request or new detail out of band, even when it appears in a thread you recognize.
The controls that stop most invoice fraud
A few habits defeat nearly all of these. Match every invoice to a purchase order and an approved vendor before paying, so unordered and unfamiliar bills fail at the first step. Verify any new or changed payment detail with a phone call to a number you already had on file. Require a second person to approve payments, so no one can pay a fraudulent invoice alone. Never pay by scanning a QR code or clicking a link inside an invoice, and never open unexpected attachments or enable macros. If a payment has already gone to a fraudster, contact your bank immediately to try to recall it and report it to the FBI’s Internet Crime Complaint Center at ic3.gov, since fast action is what makes recovery possible.
This article is general information, not legal or financial advice. Verify invoices and payment changes through your own established processes, and consult your bank and a qualified professional about payment controls and any suspected fraud.
Frequently asked questions
How can I tell if an invoice is fake?
Check whether it matches a real purchase order and a known vendor, verify the full sending email address, and be wary of QR codes, urgency, or new bank details. If you cannot tie the invoice to something your company actually ordered and confirm the vendor independently, treat it as fraudulent until proven otherwise.
Why are QR codes on invoices dangerous?
Because the link is hidden inside an image, a QR code can slip past email filters that only scan text, and scanning it usually moves you onto a personal phone outside your company’s security. The code can route your payment or login to an attacker. Never pay an invoice by scanning a QR code in an email.
What should accounts payable do to prevent invoice fraud?
Match every invoice to a purchase order, verify any new or changed payment details by phone using a known number, and require a second approver for payments. Do not open unexpected attachments, enable macros, or pay via links or QR codes. These controls stop the large majority of fake invoices.
Are attachments on invoices safe to open?
Not always. An invoice PDF or HTML attachment can carry malware or open a fake login page that steals your credentials, and documents that ask you to enable macros can run hidden code. Only open attachments you were expecting, and never enter a login to “view” an invoice.
What do I do if we paid a fake invoice?
Act immediately. Contact your bank to try to recall or freeze the payment, notify the real vendor, and file a report with the FBI’s Internet Crime Complaint Center the same day. Fast action within hours gives the best chance of recovering the funds.
The bottom line
Fake invoices succeed by looking normal, so the answer is a process that does not rely on things looking normal. Match invoices to real orders, verify payment changes by phone, require a second approver, and never pay through a QR code, a link, or an unexpected attachment. Treat urgency as a warning, not a deadline. For more on protecting your business, browse The Other Stream’s Business section.