By ICW Group Anti-Fraud Team

September 9, 2026

That Invoice May Not be What it Seems

Scammers are getting better at looking legitimate—and they are counting on people being too busy to stop and double-check. 

According to the Federal Trade Commission (FTC), consumers reported losing $3.5 billion to imposter scams in 2025, making them the most commonly reported type of fraud for the ninth year in a row. Nearly one in three fraud reports involved someone pretending to be a trusted business, financial institution, government agency, vendor, or other familiar organization. 

Businesses are also being targeted

In a recent warning, the FTC highlighted an increase in fake invoice scams, where criminals send bills for products or services a company never ordered. The invoice may look professional, reference a familiar type of service, or even arrive marked “past due” in hopes that an employee will pay it without questioning it. Some fake invoices sent by email are also phishing attempts designed to steal passwords or gain access to company systems. 

Another common tactic is Business Email Compromise (BEC). A criminal may impersonate an executive, employee, or trusted vendor and request an urgent payment, wire transfer, or change to banking information. Sometimes the difference between the real and fraudulent email address is as small as a single letter. 

A few minutes of verification can prevent a costly mistake

Whether you are protecting your business or your personal finances, a few simple habits can make a big difference: 

  1. Slow down when a request feels urgent. Scammers often create pressure, so you act before thinking. 
  2. Verify payment changes independently. If a vendor suddenly provides new banking or wire instructions, call a known contact using a phone number you already have—not one included in the questionable message. 
  3. Check invoices carefully. Make sure the product or service was truly ordered and that the vendor is one your company recognizes. 
  4. Look closely at email addresses and website addresses. One changed letter or character can signal an impersonator. 
  5. Avoid clicking on unexpected links or attachments. Visit the organization’s website directly or contact it through a known channel. 
  6. Use multi-factor authentication on business and personal accounts whenever possible. 
  7. Create clear payment approval procedures. Employees should know who is authorized to approve invoices, wire transfers, and changes to vendor payment information. 

The FBI recommends verifying unusual payment or purchase requests through a separate method—such as calling the person directly—rather than relying solely on the email or message that initiated the request. 

Remember: Stop, verify, then act

Modern scams do not always contain obvious spelling mistakes or suspicious-looking emails. They increasingly resemble legitimate business communications. If something involving money or sensitive information seems unusual, taking an extra few minutes to independently verify the request may prevent a significant financial loss. 

Suspected consumer scams can be reported to the FTC at ReportFraud.ftc.gov, while suspected business email compromise can be reported through the FBI’s Internet Crime Complaint Center at IC3.gov.

By ICW Group Anti-Fraud Team

Share this article:

Related content:

CAPTCHA-scams-700x387
back-to-school-scams-700x387
topic-3-696x385
ICW Group Insurance Companies