Privacy & Social · September 29, 2026
What to Do When Scammers Send Fake Invoices in Your Company’s Name
A practical response plan for documenting fake invoices, protecting customers and vendors, securing payment systems, and reporting impersonation.

Confirm that the invoice is not yours, preserve the original message or mailing, and identify every fake sender, website, payment destination, and recipient you can verify. Secure your real email, invoicing, domain, and vendor accounts. Warn affected customers or vendors through contact information they already trust, and tell anyone who paid to contact their financial institution immediately. Report the impersonation to the FTC, IC3, relevant providers, and the U.S. Postal Inspection Service when mail was used.
This problem is different from receiving a random fake bill. Here, a scammer uses your company name, logo, employee identity, email lookalike, or invoice design to request payment from a customer, vendor, or partner. The invoice may contain altered banking instructions, a fake payment link, a different mailing address, or an attachment designed to steal account access.
A fake invoice does not automatically prove that your systems were hacked. The sender may have copied public branding and created a lookalike domain. However, a message sent from a real company mailbox, an unexpected forwarding rule, a changed invoice template, or activity inside a billing portal can indicate compromise. Confirm the delivery path before describing the cause publicly.
The FTC’s current Impersonation Rule addresses materially and falsely posing as a business or misrepresenting an affiliation in or affecting commerce. Other fraud, trademark, computer-access, privacy, and reporting laws may also apply depending on the facts and location. This guide provides general education, not legal advice. Significant losses, threats, or disputed responsibility deserve qualified legal and security review.
A practical step-by-step approach
01Verify one complete example
Ask a trusted recipient for the original email, message, envelope, invoice file, payment page, or screenshot. Compare the invoice number, sender domain, purchase order, service description, contact details, payment instructions, due date, and branding with company records. Do not click a link, open an unexpected attachment, or call the number printed on the suspicious invoice while investigating.
02Preserve the evidence privately
Save the original file and full email headers when available, along with the sender address, reply-to address, domain, URLs, phone numbers, bank or payment destination, mailing marks, dates, and known recipients. Record how the business learned about the invoice. Restrict access to financial and victim information, and create redacted copies for routine discussion.
03Check whether a real account was compromised
Review company email sign-ins, forwarding rules, sent and deleted folders, password changes, domain administration, invoice software, customer portals, connected apps, and payment settings. Remove unknown access, rotate exposed credentials, and enable multifactor authentication where available. Work with your email provider on authentication controls for your domain. Preserve logs before changes erase useful details.
04Alert recipients through a trusted channel
Contact confirmed recipients using a phone number, email address, portal, or account representative already in your records—not the contact information on the fake invoice. Identify the unauthorized invoice and tell people not to pay, click, reply, or share credentials. The FTC advises businesses warning customers by email to consider a message without hyperlinks so the warning itself does not resemble phishing.
05Help anyone who sent money act quickly
Tell the payer to contact the originating bank, card issuer, payment service, or other financial institution immediately and ask what recall, reversal, or fraud steps are available. IC3 advises BEC victims to contact the originating financial institution as soon as fraud is recognized and then file a detailed complaint. Recovery depends on timing and other parties, so never promise the funds will return.
06Report the impersonation and payment path
Submit an accurate report to ReportFraud.ftc.gov and IC3.gov. If U.S. Mail was used, the Postal Inspection Service accepts mail-fraud reports. Report the lookalike domain, email account, hosted payment page, or payment destination to the responsible registrar, host, provider, or financial service under its current abuse process. Include only necessary evidence and keep confirmation numbers.
07Correct public payment information
Publish one stable page that explains how genuine invoices arrive, which domains the company uses, how customers can verify a payment change, and what the business will never request. Correct inconsistent phone numbers, email addresses, and payment links across the website and important profiles. Do not reproduce a live malicious link or complete bank details in a public warning.
08Build a safer invoice process
Require purchase orders or another documented approval, limit who can create and change payment instructions, and verify bank-detail changes through a known secondary channel. Maintain a current vendor and customer contact directory. Train finance and customer-service staff to pause unexpected requests, and review the incident to identify controls, communications, and monitoring that need improvement.
Information to gather
A clear record makes it easier to choose the right channel, communicate accurately, and avoid unnecessary repetition. Start with:
- Original invoice, message, attachment, envelope, email headers, and screenshots
- Sender, reply-to, domain, URL, phone, payment destination, dates, and known recipients
- Purchase order, contract, invoice number, service, and approved payment records
- Email, domain, billing portal, connected-app, forwarding-rule, and access review
- Recipient warning, verified contact method, and internal response owner
- Financial-institution, FTC, IC3, USPIS, registrar, host, and provider report confirmations
- Public payment-verification page and post-incident control review
What not to do
Pressure can lead to decisions that create a second reputation problem. Avoid:
- Replying to the fake sender, using contact details on the invoice, or opening unexpected files
- Assuming copied branding proves that a real company account was compromised
- Publishing complete bank details, victim records, live scam links, or unredacted evidence
- Naming a suspected person publicly without reliable evidence and qualified review
- Changing real payment instructions during the incident without direct notice and verification
- Promising removal, an arrest, fund recovery, account security, or a completion date
Frequently asked questions
Does a fake invoice in our name mean our email was hacked?
No. A scammer can copy public branding, create a lookalike domain, and send a convincing invoice without entering your systems. Review sign-ins, forwarding rules, sent mail, domain administration, invoice software, connected apps, and payment settings. If a real account shows unauthorized activity, treat the event as a possible compromise.
Should we warn every customer immediately?
Warn confirmed or reasonably affected recipients promptly through a trusted channel. A broad public notice may help when the campaign is active or the recipient list is unknown, but it should stay factual and avoid amplifying malicious links or private details. Coordinate serious or legally sensitive notices with qualified advisers.
What should someone do after paying the fake invoice?
They should contact the originating bank, card issuer, payment service, or other financial institution immediately and ask about recall, reversal, and fraud procedures. Preserve the invoice and communications, then report the incident to IC3 and the FTC. Fast action may help, but repayment or recovery cannot be guaranteed.
What if the fake invoice arrived through the mail?
Keep the invoice, envelope, mailing marks, payment instructions, and any follow-up communication. Do not send payment or original evidence back to the sender. The U.S. Postal Inspection Service accepts reports when U.S. Mail was used in a suspected false-invoice scheme. Ask qualified counsel about disputed demands or significant loss.
Can a reputation company guarantee the fake invoices will stop?
No. A responsible provider can organize evidence, coordinate accurate reports, prepare recipient and public communications, correct contact information, and monitor reputation effects. Outcomes depend on the scammers, providers, financial institutions, law enforcement, evidence, applicable law, platforms, publishers, search engines, and other third parties. No provider can guarantee timing or complete prevention.
Primary resources
Policies and features can change. Review the current source before submitting a request:
- FTC: protect a small business from impersonators
- FTC: fake invoice guidance for small businesses
- FTC: Impersonation of Government and Businesses Rule
- FBI IC3: Business Email Compromise guidance
- FBI IC3: BEC tactics used against vendors
- U.S. Postal Inspection Service: false invoice scams