Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What are the signs that an RFQ request…
Cyber Security

What are the signs that an RFQ request is likely fraudulent?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 8, 2026 Domain: Cyber Security

Common warning signs include unusual urgency, a mismatch between the sender domain and the claimed company, requests from free email accounts, and shipping instructions that point to freight forwarders or residential addresses. Fraudsters also tend to request highly specific high value items and ask for financing details such as EIN, DUNS numbers, and supporting business documents early in the exchange.

RFQ Fraud Signals That Separate Legitimate Buyers from Suspicious Requests

RFQ fraud usually reveals itself through process mismatch more than through any single red flag. A genuine buyer can still move quickly, but their request should look consistent with the organisation they claim to represent, the item being sourced, and the commercial steps that normally follow. When the language, contact details, requested documents, and delivery arrangements do not fit together, the probability of deception rises quickly.

One useful reference point is NIST SP 800-53 Rev 5 Security and Privacy Controls, which reinforces the value of identity, communications, and supplier-related controls when organisations need to validate who they are dealing with and what information they are exposing. In practice, many teams only recognise RFQ fraud after procurement and finance have already treated a suspicious request as routine vendor onboarding.

How RFQ Fraud Typically Unfolds in Practice

Fraudulent RFQs often begin with a credible-looking enquiry that is designed to reduce scrutiny. The requester may copy a legitimate company style, reference a real product category, and keep the first exchange short so that the recipient is pushed toward quoting before validating the buyer. The goal is usually to extract pricing, commercial terms, account details, or sensitive business identifiers that can be reused in invoice fraud, impersonation, or account compromise.

Several details matter because they reveal whether the request fits normal procurement behaviour. A mismatch between the sender domain and the claimed company suggests the requester is avoiding traceability. Free email accounts are even more suspicious when paired with a corporate claim, because they bypass the basic accountability expected in business purchasing. Shipping instructions that route goods to freight forwarders, collection points, or residential addresses are also a warning sign, especially when they do not align with the stated business purpose.

High-value or highly specific item requests can indicate targeting rather than ordinary sourcing. Fraudsters often select goods that are easy to resell, hard to trace, or attractive for account manipulation. Early requests for EIN, DUNS numbers, certificates, incorporation records, or financing information are especially telling when they arrive before any meaningful commercial relationship exists. That is not how a normal buyer usually earns trust.

  • Compare the sender identity, domain, and signature against the claimed company.
  • Check whether the delivery address and logistics instructions match the stated buyer profile.
  • Assess whether the requested information is proportionate to the stage of the relationship.
  • Review whether the item being requested is unusually specific, urgent, or easy to monetise.

This guidance breaks down when an organisation’s own procurement process is poorly documented, because weak internal controls can make a legitimate request look unusual.

Edge Cases That Can Look Suspicious Without Being Fraud

Tighter fraud screening often increases friction, requiring organisations to balance buyer convenience against verification depth. That tradeoff matters because some legitimate procurement teams do use alternate domains, purchasing agents, third-party logistics providers, or very compressed timelines.

The main exception is that unusual behaviour should be judged against the whole request, not one isolated signal. A free email account alone is not proof of fraud if the request is otherwise clearly from a known and validated intermediary, though that remains a poor practice. Likewise, freight forwarders are not inherently suspicious in international trade; they become concerning when the shipping path is inconsistent with the business relationship or the requested goods.

Industry consensus is weaker on exactly which signals should trigger automatic rejection versus manual review. The practical standard is to treat multiple weak indicators as stronger than any single dramatic one. If urgency, domain mismatch, unusual shipping, and early document requests appear together, the request should be handled as a verification problem rather than a normal sales opportunity.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST IR 8596 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1 — Identity Management, Authentication, and Access ControlRFQ fraud depends on weak identity validation and impersonation.
Recommendation — Verify requester identity before sharing pricing or business documents.
CIS Controls v86.3 — Account Monitoring and ControlSuspicious RFQs exploit weak account and contact verification.
Recommendation — Review unusual requester accounts and block unvalidated business contacts.
NIST IR 85962.1 — Detection and AnalysisFraud indicators need triage and escalation criteria, not ad hoc judgment.
Recommendation — Triage suspicious RFQs using a consistent detection and escalation process.
MITRE ATT&CKT1583.001 — Acquire Infrastructure: DomainsFraudsters often use lookalike or mismatched domains to impersonate buyers.
Recommendation — Inspect sender domains for impersonation and lookalike infrastructure.

Practitioner Guidance

What to prioritise: Validate identity and transaction context before sharing pricing, account data, or business documentation. The decision point is whether the request behaves like a normal commercial buyer or a staged extraction attempt.

Decision rule: If the request combines identity mismatch with unusual logistics or early-document pressure, route it to manual review and require independent verification through a known company channel. If only one weak signal is present, treat it as a caution flag rather than a conclusion.

What practitioners underestimate: Fraud teams often focus on the buyer persona and overlook the downstream purpose of the request. The real risk is not just a bad RFQ, but the reuse of the information in invoice diversion, fake onboarding, or further impersonation.

Practitioner takeaway: The strongest indicator is not one odd detail but a request pattern that fails basic business logic across identity, logistics, and documentation.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 8, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org