Warning signs include urgent payment demands, legal pressure, unusually specific invoice amounts, requests to move communication off normal channels, and attachments that mimic supplier branding. In more advanced cases, attackers demonstrate knowledge of prior conversations or reference details that should only be visible to the real supplier. Those clues often indicate reconnaissance, compromise, or both.
How to tell the fraud attempt is customised to a specific supplier
When invoice fraud is tailored, the attacker is no longer sending a generic lure. The message reflects reconnaissance and access to context, which means the strongest clues are inconsistencies in process combined with details that should only be known by a legitimate counterparty.
One useful way to read the attempt is to separate generic spoofing from target-specific tailoring. Generic fraud often leans on broad urgency and payment redirection. Targeted fraud adds facts that fit the real relationship, such as prior invoice timing, named employees, shipping references, or references to a live business event that makes the request look normal.
That distinction matters because tailored fraud is usually designed to bypass the usual human objections. If the request matches the supplier’s branding, language, and timing too well, the attacker is trying to reduce friction rather than simply persuade a random recipient. The more precise the context, the more likely it is that the attacker has studied the target or compromised an adjacent account.
Which clues suggest reconnaissance or compromise rather than coincidence?
The strongest indicator is when the invoice request contains information that is not publicly obvious and should not be present in a forged message. That can include exact contract terms, realistic payment amounts, references to ongoing correspondence, or an understanding of who normally approves the invoice. It can also include subtle process knowledge, such as which department is likely to be busy enough to skip a check.
Another clue is channel manipulation. Requests to move payment discussion off normal systems, use a new bank account, or confirm details through an alternative address often indicate an attempt to create a one-time path that avoids the organisation’s usual verification controls. In practice, those tactics are often paired with brand mimicry, email impersonation, or mailbox compromise. NHIMG’s Email Identity and BEC Guide is a useful companion when the fraud is riding on spoofed supplier identity and payment redirection.
Advanced cases are more revealing because the attacker may cite prior conversations, real signatories, or internal reference numbers. If those details are accurate but the payment request is abnormal, assume the message is being tailored from stolen context, not simply copied from a template. That is the point at which the question shifts from “is this suspicious?” to “how did the sender get this level of detail?”
What should practitioners verify before treating it as a real business request?
Verification should focus on whether the request fits the established payment process, not just whether the email looks credible. Compare the amount, destination account, approver, and communication channel against known supplier records and recent changes. A tailored fraud attempt often survives a quick visual check but fails when you verify the payment change through a trusted, out-of-band route.
If the request mentions legal pressure, overdue settlement, or imminent service interruption, confirm the claim with the supplier through a known contact path, not by replying to the same thread. That is especially important because urgency is often used to narrow the time available for cross-checking. The best control is to force the attacker to survive a verification step they did not fully control.
For teams handling large volumes of invoices, the practical test is whether the request bypasses normal segregation of duties or approval logic. If one person can both receive the request and push the payment change through, the fraud only needs one successful deception. If the process requires a second channel and a second approver, tailored fraud becomes much harder to execute quietly.
Risk and Threat Considerations
Tailored invoice fraud is risky because it combines social engineering with process intelligence. The attack becomes more effective when the adversary can imitate real business context, and the organisation’s own routines can make the message appear routine if controls rely too heavily on email alone.
Failure mechanism: The attacker uses reconnaissance, mailbox access, or impersonation to learn supplier names, invoice patterns, approvers, and timing, then injects a payment request that looks credible enough to bypass informal review.
Impact: The result can be an authorised-looking payment to a fraudulent account, delayed detection, disputes with the real supplier, and wider exposure if the same compromised channel is reused for follow-on fraud.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK, OWASP Non-Human Identity Top 10 and OWASP API Security Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Tailored invoice fraud often exploits account and mailbox access paths. |
| Recommendation — Restrict and review accounts that can approve or redirect payment-related changes. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication and Access Control | Verification of payment changes depends on trusted identity and access paths. |
| Recommendation — Require verified identities and controlled channels for payment-related requests. | ||
| MITRE ATT&CK | T1566 — Phishing | Targeted invoice fraud commonly arrives as social engineering to obtain or redirect payments. |
| Recommendation — Detect and train against targeted phishing messages that request payment or account changes. | ||
| OWASP Non-Human Identity Top 10 | NHI-10 — Human Use of NHI | Invoice fraud can abuse compromised mail or supplier identities to impersonate trusted senders. |
| Recommendation — Verify that payment requests are not being issued through compromised or misused identities. | ||
| OWASP API Security Top 10 | API2 — Broken Authentication | If payment workflows or portals are abused, weak authentication enables fraudulent changes. |
| Recommendation — Harden authentication on supplier and payment portals before allowing account changes. | ||
Practitioner Guidance
What to prioritise: Treat “known enough to feel normal” as the most dangerous pattern. If the message includes accurate internal details but asks for any change to bank details, payment timing, or routing, escalate it for verification rather than relying on appearance or tone.
What to verify: Confirm whether the request is consistent with the supplier’s historical behavior, known contacts, and normal approval chain. If the sender can only be trusted through the same channel that carried the request, the control has not really verified anything.
Common mistake: Teams often look for spelling errors or obvious spoofing, but tailored invoice fraud is usually designed to avoid those tells. The stronger signal is a credible request that still violates a process rule, especially when it arrives with just enough context to discourage challenge.
Practitioner takeaway: The more specific the invoice request, the less you should trust the message itself and the more you should trust the process used to verify it.
Related resources from NHI Mgmt Group
- Why do secrets stay dangerous even when they are no longer actively used?
- How should security teams reduce the impact of lateral phishing, invoice fraud, and payroll diversion as attackers target human behaviour instead of technical flaws?
- What are the signs that trusted invoice delivery is being abused for fraud?
- What are the signs that a phishing campaign is targeting employees through invoice fraud or CEO impersonation?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org