Invoice fraud can use lookalike addresses or compromised real accounts. Here are warning signs and a payment-verification process that reduces reliance on email alone.
Section 01
A fake invoice can come from a lookalike address or a real account that has been compromised. Familiar tone, formatting, and conversation context are not proof that changed payment instructions are legitimate.
Section 02
Forget 'look for bad grammar' — modern invoice fraud is clean. Look for these instead:
Section 03
Verify every payment-detail change by phone or another trusted channel, using contact information you already have on file rather than details supplied in the message. This reduces reliance on a potentially compromised email channel but does not eliminate fraud risk.
Make it policy: no one in your company changes where money gets sent based on an email alone, no matter how legitimate it looks or who it appears to come from.
Section 04
Some account-takeover attempts produce supported audit records before a fraudulent message, such as suspicious sign-ins, inbox-rule changes, or forwarding changes. Other activity may be unavailable or delayed.
InboxGuards checks those available audit records approximately every 5 minutes and alerts in plain English when a configured account-takeover signal appears. It cannot guarantee an alert before a fraudulent message or payment. $4 per user per month, with customer-admin authorization for read-only access.
Customer-admin authorization · Read-only access · $4/user/mo · 30-day money-back guarantee