Overview
Invoice scams are targeted phishing attacks designed to cause an unauthorized payment, redirect a legitimate payment, or make a recipient open a harmful attachment or link. These scams frequently target people involved in purchasing, accounts payable, budgeting, grants, or other financial processes, but anyone who receives or approves a payment request can be targeted.
One version uses fabricated threading. The scammer creates a fake forwarded-message or reply history and places it below a new email. The quoted text may appear to show that a known employee, executive, department, or vendor already discussed and approved the request.
An email history displayed inside a message can be typed, copied, or altered. It does not prove that the earlier messages were sent or that the people named in the thread approved the transaction.
How It Works
A fabricated-threading scam attempts to create the appearance of an existing internal or vendor conversation. The message may include:
- An external sender posing as a manager, vendor, consultant, or intermediary.
- A subject line beginning with “RE:” or “FW:” even though you did not receive the earlier messages.
- A fake “From,” “Sent,” “To,” or “Subject” history at the bottom of the email.
- Quoted text that appears to show approval from a UM employee, executive, or department.
- A claim that an invoice is overdue or that payment instructions have changed.
- An attachment labeled as an invoice, statement, remittance notice, or payment instruction.
- A request to bypass normal review because the matter is urgent or has supposedly already been approved.
Some business email compromise attacks use an actual compromised account. Others use look-alike addresses or fabricated threads without compromising any UM account. The visible conversation alone cannot establish that the request is legitimate.
Warning Signs
Be cautious when an invoice-related message includes:
- An unfamiliar current sender. The address that actually sent the message is external, misspelled, or unrelated to the organization named in the email.
- Inconsistent addresses in the quoted history. A displayed name may be paired with a non-UM address or a subtly altered domain.
- An unexpected forwarded conversation. The sender claims to follow up on an internal discussion that you did not participate in or cannot verify.
- A missing message history. The supposed earlier messages do not appear as separate items in your mailbox or records.
- Urgent or threatening payment language. The message uses phrases such as “long overdue,” “immediate settlement,” or “pay today.”
- New banking or remittance instructions. A vendor supposedly changed accounts, routing information, payment methods, or contact information.
- Pressure to bypass normal procedures. The sender says approval is already complete or asks you not to involve other people.
- An unexpected attachment or link. The file or website requests credentials, payment details, macros, software, or another unusual action.
- A reply-to address that differs from the sender address. Replies may be redirected to an account controlled by the scammer.
A professionally written message, correct logo, familiar name, or accurate business detail does not prove that the request is legitimate.
How to Protect Yourself
- Treat the current sender address as the starting point. Do not rely on names and addresses shown only inside quoted text.
- Verify payment requests through a separate channel. Call a known number or start a new email to a verified address. Do not reply to the suspicious message.
- Follow established UM financial procedures. Do not bypass required approvals because an email claims that someone already authorized the payment.
- Independently confirm changes to payment instructions. Use existing vendor records or a previously verified contact, not the information in the new request.
- Do not open an unexpected invoice attachment or follow its link. Verify the sender and the business purpose first.
- Be cautious with requests involving secrecy or unusual urgency. Legitimate financial work should allow time for appropriate verification.
- Do not use contact information contained only in the suspicious message. It may lead directly back to the scammer.
What You Should Do at UM
If you receive a suspicious invoice, payment request, or fabricated email thread:
- Do not reply, open attachments, click links, or process the payment.
- Verify the request out of band. Call the employee, department, or vendor using a trusted number, or start a new message to a verified address.
- Use Outlook's Report Message tool and report the email as phishing. Delete the message after reporting it. The Report Message tool may remove it automatically.
- Contact the UM IT Helpdesk or UM Information Security Office if the request involves a UM account, vendor, employee, financial process, or university data.
- Contact the appropriate UM financial or business office through a trusted method before changing payment information or continuing the transaction.
If a payment was already initiated or banking information was changed, contact the relevant UM financial office and financial institution immediately and notify the UM Information Security Office. Prompt action may improve the ability to stop or recover a fraudulent payment.
If you opened an attachment, entered a UM password, approved an MFA request, or installed software, stop interacting with the message and contact the UM IT Helpdesk or UM Information Security Office for account and device guidance.
Simply receiving or viewing the email does not mean your account or device has been compromised. Additional action is needed when you interacted with the message, changed a process, or sent information or money.
Additional Questions
For a suspicious invoice, vendor request, or payment process involving UM, contact the UM IT Helpdesk and the UM Information Security Office. Involve the relevant UM financial or business office when a payment or vendor process is affected.
For a personal or non-UM invoice scam, contact the financial institution or payment provider immediately if money was sent. Verify the vendor or organization through independently obtained contact information. Internet-enabled financial fraud can also be reported to the FBI's Internet Crime Complaint Center.
Additional Resources