Once the target approves financing, the scam often shifts to logistics. The actor provides a delivery address, coordinates with a mule or forwarding service, and tries to move goods quickly before controls catch up. If the shipment is not revalidated, the supplier can lose physical inventory and may not discover the fraud until the payment window closes.
How the RFQ Scam Transitions from Inbox to Shipping
A fraudulent RFQ often starts as a familiar business conversation, then shifts once the target accepts the commercial terms and begins planning fulfilment. That change matters because the attacker is no longer relying only on email manipulation. The scam now uses shipping instructions, delivery timing, and supplier workflow pressure to convert a document-only fraud into a physical loss event. If teams treat the order as already trusted, the fraud can move from misrepresentation to inventory diversion without much resistance.
At that stage, the attacker may introduce a new address, request a courier handoff, or route goods through an intermediary that obscures who ultimately receives them. The main control failure is not just weak verification at the inbox. It is the absence of a second trust check when the transaction becomes operational. NIST SP 800-53 Rev 5 Security and Privacy Controls is useful here because it reinforces the need to bind approval, fulfilment, and verification to controlled processes rather than informal handoffs. In practice, many teams only realise the shipment path was compromised after the goods have already left the warehouse.
Where the Physical Loss Actually Occurs
The loss event usually happens when fulfilment is allowed to proceed on the strength of the original email chain alone. Once shipping accepts the order, the fraudster benefits from speed, routine, and interdepartmental handoff. Sales may think finance has checked the buyer, finance may think logistics has checked the destination, and neither side may re-confirm that the request still matches the original commercial relationship.
The mechanics are straightforward. A fraudulent buyer profile gains enough trust to pass initial review, then the delivery destination is changed to a mule address, forwarding service, warehouse, or other intermediate point. If the supplier does not revalidate the request before dispatch, the goods can be removed from normal recovery paths quickly. The practical issue is that physical shipment creates irreversible movement, unlike an email thread that can be reviewed later. This is why shipping controls need to be identity-aware and process-aware at the same time, especially where high-value goods or rush fulfilment are involved.
- Verify that the shipping destination is consistent with the approved buyer and contract terms.
- Require a separate approval when delivery instructions change after financing or order acceptance.
- Escalate any request that introduces urgency, alternate collection, or forwarding behaviour.
Where shipment is automated from the same record that held the fraudulent RFQ, this guidance breaks down because the false trust decision is simply propagated faster.
When the Usual Controls Stop Being Enough
Tighter shipping verification often slows fulfilment, requiring organisations to balance fraud resistance against customer convenience and delivery speed. That tradeoff is especially visible in organisations that prioritise rapid dispatch, because the very features that improve service can also shorten the time available to detect a manipulated destination.
There are a few important edge cases. Some fraudulent RFQs never need technical compromise at all; they succeed by abusing business process assumptions. Others combine email deception with external logistics services that look legitimate until the delivery chain is examined closely. Guidance on this point is not fully standardised across industries, but the general principle is consistent: when the shipping destination or collection method changes, the order should be treated as a fresh trust decision, not a continuation of the original request.
That is also where team boundaries matter. Procurement may validate the commercial side, but warehouse and fulfilment staff are the last practical checkpoint before inventory exits control. If those teams do not have authority to pause or challenge an anomalous shipment, the fraud can progress even when someone upstream is suspicious. The operational edge case is simple: once the goods are in transit to an attacker-controlled endpoint, recovery becomes far harder than prevention.
Risk and Threat Considerations
This fraud pattern creates both operational loss and adversarial opportunity. The exposure is not limited to invoice fraud; it includes physical diversion, weak chain-of-custody assurance, and delayed discovery that can leave the supplier outside dispute windows or recovery options.
Failure mechanism: The attacker leverages trust transferred from email to fulfilment. Once the RFQ is accepted, changes to delivery details can be used to route goods through a mule, forwarding service, or indirect recipient, while normal business urgency discourages revalidation.
Impact: Inventory leaves the organisation under apparently legitimate instruction, and the loss may only become visible after shipment has been irreversibly handed off or payment review has closed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST IR 8596 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 — Identity Management and Access Control | RFQ fraud relies on trust transfer and weak verification before fulfilment. |
| Recommendation — Require revalidation before release when shipping details change. | ||
| CIS Controls v8 | 5 — Account Management | Fraudulent order handling depends on validating who can alter delivery instructions. |
| 8 — Audit Log Management | Shipment fraud needs traceable evidence across order and fulfilment changes. | |
| Recommendation — Restrict who may approve destination changes and record each exception. Log shipment instruction changes and review anomalies before dispatch. | ||
| NIST IR 8596 | IR-5 — Incident Analysis | The scam becomes actionable when teams can analyse the changed shipment path. |
| Recommendation — Analyze delivery changes as a fraud indicator and escalate suspicious orders. | ||
| MITRE ATT&CK | T1566 — Phishing | The fraudulent RFQ begins as deceptive contact that primes the logistics abuse. |
| Recommendation — Map deceptive RFQ email activity to T1566 and inspect follow-on fulfilment steps. | ||
Practitioner Guidance
What to prioritise: Treat any post-approval delivery change as the highest-risk point in the workflow, because that is where a paper fraud becomes a physical one. The critical question is whether the shipment still matches the original buyer, destination, and commercial context after finance approval.
What to verify: Confirm that logistics can independently validate a destination change, alternate pickup, or forwarding request before dispatch. If the team can only confirm against the email thread, the control is too weak for fraud-prone orders.
What practitioners underestimate: The main failure is often not bad email filtering but weak cross-team ownership. Procurement, finance, and warehouse functions each see part of the risk, but none may own the final stop/go decision unless it is explicitly assigned.
Practitioner takeaway: The decisive control is not whether the RFQ looked convincing in email, but whether fulfilment can still challenge the shipment after the attacker has converted trust into an operational dispatch.
Related resources from NHI Mgmt Group
- What should organisations do when phishing moves beyond email into texts and social media?
- What signals help detect email impersonation before money moves?
- Which controls matter most when phishing moves beyond email into the browser?
- Who is accountable when fraudulent email causes a payment or data breach?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org