A Request For Quote scam is a procurement fraud in which an attacker poses as a legitimate buyer to obtain pricing, credit terms, or goods. In these campaigns, the quote request is used to build trust, open a payment relationship, or justify shipment of merchandise that will later be diverted or stolen.
Expanded Definition
A Request For Quote scam is a procurement fraud pattern that uses the quote process as a trust-building step rather than a genuine buying enquiry. The attacker may pose as a purchasing manager, reseller, or internal stakeholder to elicit prices, lead times, account details, minimum order quantities, or shipment terms, then use that information to advance theft, invoice fraud, or diverted delivery.
The term is narrower than general business email compromise because the objective is usually to manipulate the quoting and fulfilment workflow, not simply to steal credentials or request a wire transfer. It is also distinct from ordinary competitive price shopping, where the requester is real and the interaction remains bounded by legitimate procurement behaviour. The boundary is often visible in unusual urgency, reluctance to verify identity, pressure to bypass normal approval paths, or requests that move quickly from quotation to shipping or payment setup. Where the organisation handles high-value goods or specialised inventory, that early quote stage can become a low-friction entry point into a larger fraud chain.
Examples and Use Cases
Request For Quote scams commonly appear in environments where buyers and suppliers rely on email, forms, or informal account setup. The same pattern can affect distributors, manufacturers, logistics providers, and any team that ships goods before full customer verification.
- A fraudster submits a large quote request for in-demand equipment, then uses the engagement to obtain pricing and reorder thresholds before arranging diversion.
- An attacker impersonates an established customer and asks for updated bank or payment instructions as part of the quotation process, creating a path to payment redirection.
- A fake procurement contact requests expedited shipping terms and insists on bypassing standard verification, increasing the chance of unauthorised fulfilment.
- A reseller-facing sales team receives repeated RFQs that look plausible individually but are designed to map inventory availability and internal approval behaviour.
The tradeoff for legitimate sales teams is speed versus assurance. The more friction you add to quote handling, the harder it can be to serve genuine customers quickly, yet the less friction you add, the easier it becomes for a scammer to exploit a routine commercial workflow.
Security Implications
Misclassifying an RFQ scam as a normal sales enquiry can expose pricing intelligence, fulfilment processes, and account data to an untrusted party. That information is often enough to support downstream fraud even when no systems are directly compromised. The most immediate operational consequence is that staff may authorise quotes, shipments, or payment setup on the strength of a convincing but unverified request.
Once the workflow has been opened, the attacker can pivot from information gathering to account manipulation, goods diversion, or follow-on invoice fraud. A common failure condition is weak identity verification at the start of the sales cycle, especially where the business assumes that any request for a quote is inherently lower risk than a purchase order. Observable symptoms include urgent first-time requests, mismatched company details, repeated changes to destination or payment instructions, and quote approvals that happen outside the normal procurement record.
For organisations with physical goods, the blast radius is not limited to financial loss. It can include inventory depletion, chargebacks, customer disputes, delayed fulfilment, and reputational harm if the scam is executed using the organisation’s own commercial channels.
Domain and Governance Relevance
Request For Quote scams sit at the intersection of procurement governance, sales operations, and fraud prevention. The control issue is not just whether a request is believable, but whether the organisation can prove who initiated it, why it was accepted, and which checks were performed before credit or shipment terms were extended. That makes quote handling a governance surface, not merely an admin task.
For identity-led organisations, the relevant question is often whether the requester is bound to a verified business identity, approved account, or known relationship before staff treat the RFQ as actionable. When that link is weak, the quote channel becomes a low-cost way to exploit trust without needing system access. NHIMG treats this as a boundary problem: the organisation is deciding when a commercial conversation becomes a trust decision.
Consistent quote verification, approval tracing, and exception handling matter because scammers rely on routine processing. The safer the workflow feels to staff, the more valuable it is to attackers if the identity check is only informal.
Risk and Threat Considerations
Request For Quote scams create a material fraud and trust-risk exposure because they exploit a legitimate commercial workflow to obtain information, goods, or payment influence. The danger is highest where quote requests can lead directly to shipment, credit terms, or account changes with limited verification.
Failure mechanism: The scam succeeds when staff treat the RFQ as routine business contact, allowing the attacker to harvest pricing and fulfilment details, then abuse that trust to redirect delivery, manipulate payment instructions, or escalate into invoice fraud.
Impact: The organisation can lose inventory or revenue, expose pricing and customer data, and create downstream disputes that are difficult to unwind once goods have shipped or payment details have been changed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 15 — Service Provider Management | RFQ scams exploit trust in external business relationships and fulfilment channels. |
| Recommendation — Verify requester identity and contract legitimacy before extending quote or fulfilment privileges. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication, and Access Control | Quote scams hinge on weak identity verification before commercial trust is granted. |
| PR.DS — Data Security | Scammers seek pricing, customer, and fulfilment data through the RFQ channel. | |
| PR.IP — Information Protection Processes and Procedures | RFQ handling depends on repeatable verification and exception controls. | |
| Recommendation — Require identity verification before approving quote, shipment, or payment changes. Limit quote-stage disclosure to the minimum data needed to respond safely. Standardise quote approval steps and document exceptions to normal procurement checks. | ||
Related resources from NHI Mgmt Group
- What is the difference between network trust and request-level identity trust?
- Why do access-request workflows matter for NHI governance?
- How should organisations use AI in access request approval without weakening control?
- What is the difference between access request automation and access governance?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org