Common warning signs include unusual urgency, a mismatch between the sender domain and the claimed company, requests from free email accounts, and shipping instructions that point to freight forwarders or residential addresses. Fraudsters also tend to request highly specific high value items and ask for financing details such as EIN, DUNS numbers, and supporting business documents early in the exchange.
RFQ Fraud Signals That Separate Legitimate Buyers from Suspicious Requests
RFQ fraud usually reveals itself through process mismatch more than through any single red flag. A genuine buyer can still move quickly, but their request should look consistent with the organisation they claim to represent, the item being sourced, and the commercial steps that normally follow. When the language, contact details, requested documents, and delivery arrangements do not fit together, the probability of deception rises quickly.
One useful reference point is NIST SP 800-53 Rev 5 Security and Privacy Controls, which reinforces the value of identity, communications, and supplier-related controls when organisations need to validate who they are dealing with and what information they are exposing. In practice, many teams only recognise RFQ fraud after procurement and finance have already treated a suspicious request as routine vendor onboarding.
How RFQ Fraud Typically Unfolds in Practice
Fraudulent RFQs often begin with a credible-looking enquiry that is designed to reduce scrutiny. The requester may copy a legitimate company style, reference a real product category, and keep the first exchange short so that the recipient is pushed toward quoting before validating the buyer. The goal is usually to extract pricing, commercial terms, account details, or sensitive business identifiers that can be reused in invoice fraud, impersonation, or account compromise.
Several details matter because they reveal whether the request fits normal procurement behaviour. A mismatch between the sender domain and the claimed company suggests the requester is avoiding traceability. Free email accounts are even more suspicious when paired with a corporate claim, because they bypass the basic accountability expected in business purchasing. Shipping instructions that route goods to freight forwarders, collection points, or residential addresses are also a warning sign, especially when they do not align with the stated business purpose.
High-value or highly specific item requests can indicate targeting rather than ordinary sourcing. Fraudsters often select goods that are easy to resell, hard to trace, or attractive for account manipulation. Early requests for EIN, DUNS numbers, certificates, incorporation records, or financing information are especially telling when they arrive before any meaningful commercial relationship exists. That is not how a normal buyer usually earns trust.
- Compare the sender identity, domain, and signature against the claimed company.
- Check whether the delivery address and logistics instructions match the stated buyer profile.
- Assess whether the requested information is proportionate to the stage of the relationship.
- Review whether the item being requested is unusually specific, urgent, or easy to monetise.
This guidance breaks down when an organisation’s own procurement process is poorly documented, because weak internal controls can make a legitimate request look unusual.
Edge Cases That Can Look Suspicious Without Being Fraud
Tighter fraud screening often increases friction, requiring organisations to balance buyer convenience against verification depth. That tradeoff matters because some legitimate procurement teams do use alternate domains, purchasing agents, third-party logistics providers, or very compressed timelines.
The main exception is that unusual behaviour should be judged against the whole request, not one isolated signal. A free email account alone is not proof of fraud if the request is otherwise clearly from a known and validated intermediary, though that remains a poor practice. Likewise, freight forwarders are not inherently suspicious in international trade; they become concerning when the shipping path is inconsistent with the business relationship or the requested goods.
Industry consensus is weaker on exactly which signals should trigger automatic rejection versus manual review. The practical standard is to treat multiple weak indicators as stronger than any single dramatic one. If urgency, domain mismatch, unusual shipping, and early document requests appear together, the request should be handled as a verification problem rather than a normal sales opportunity.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST IR 8596 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 — Identity Management, Authentication, and Access Control | RFQ fraud depends on weak identity validation and impersonation. |
| Recommendation — Verify requester identity before sharing pricing or business documents. | ||
| CIS Controls v8 | 6.3 — Account Monitoring and Control | Suspicious RFQs exploit weak account and contact verification. |
| Recommendation — Review unusual requester accounts and block unvalidated business contacts. | ||
| NIST IR 8596 | 2.1 — Detection and Analysis | Fraud indicators need triage and escalation criteria, not ad hoc judgment. |
| Recommendation — Triage suspicious RFQs using a consistent detection and escalation process. | ||
| MITRE ATT&CK | T1583.001 — Acquire Infrastructure: Domains | Fraudsters often use lookalike or mismatched domains to impersonate buyers. |
| Recommendation — Inspect sender domains for impersonation and lookalike infrastructure. | ||
Practitioner Guidance
What to prioritise: Validate identity and transaction context before sharing pricing, account data, or business documentation. The decision point is whether the request behaves like a normal commercial buyer or a staged extraction attempt.
Decision rule: If the request combines identity mismatch with unusual logistics or early-document pressure, route it to manual review and require independent verification through a known company channel. If only one weak signal is present, treat it as a caution flag rather than a conclusion.
What practitioners underestimate: Fraud teams often focus on the buyer persona and overlook the downstream purpose of the request. The real risk is not just a bad RFQ, but the reuse of the information in invoice diversion, fake onboarding, or further impersonation.
Practitioner takeaway: The strongest indicator is not one odd detail but a request pattern that fails basic business logic across identity, logistics, and documentation.
Related resources from NHI Mgmt Group
- Who is accountable when a fraudulent request is approved through a trusted channel?
- Who is accountable when a fraudulent business partner request is approved?
- Who is accountable when a payment is redirected through a fraudulent email request?
- What are the signs that a PowerShell 7 installation is likely to fail or become unreliable?