Fake Invoice Redirect Scam via Email
Verdict: Suspicious | Risk Score: 9/10 | Severity: critical
Category: UPI, Phishing, Government Impersonation
How Fake Invoice Redirect Scam via Email Works
Overview: This scam targets Indian businesses by impersonating legitimate suppliers through hacked emails or lookalike email addresses. Most commonly, small and medium enterprises (SMEs) in sectors like textiles, pharma, and manufacturing are the victims. The fraudsters deceive companies into transferring funds to fake accounts, posing a serious risk to business operations and trust within supply chains. How It Works: 1. Criminals hack or mimic supplier emails using nearly identical domains. 2. The company receives an urgent request for payment, often with a story about a changed bank account or updated invoice. 3. The supplied bank details direct funds to a scammer’s account via RTGS, NEFT, or sometimes the SWIFT network for cross-border payments. 4. By the time the real supplier or company notices, the funds are irrecoverable. India Angle: Indian business hubs such as Mumbai, Delhi, Chennai, and Ahmedabad are frequent targets. Most scams occur via business emails and digital payment instructions, leveraging UPI and RTGS. SMEs, especially those relying on imports or exports, are the most vulnerable. Language used is often English or Hinglish, aiming at accounts or procurement teams. Real Examples: - A purchase manager in Mumbai received an email supposedly from a long-term supplier, asking to update the payment account due to a 'bank merger.' Payment of ₹25 lakh was lost to a mule account overseas. - An SME owner in Surat got an email from an address [ADDRESS_REDACTED].com' with an urgent invoice and new NEFT details. Red Flags: - Requests to change bank account details without prior phone confirmation. - Slightly altered email domains or misspellings in sender address. - Pressure for immediate payment, claiming deadline or shipment delays. - Poor grammar or formatting inconsistent with official communication. Protective Measures: - Always confirm changes in payment information by contacting the supplier directly by phone or in person. - Implement a two-step verification before fund transfers, especially for new account details. - Check email address[ADDRESS_REDACTED]. - Regularly train staff on how to identify phishing attempts. If Victimised: - Immediately alert your bank to attempt freezing the transfer. - Report the incident to the National Cybercrime Helpline (1930) and cybercrime.gov.in. - Notify the RBI, if SWIFT or inter-bank transfers are involved. - Collect all email evidence and communicate with local cyber police. Related Scams: - Payroll Diversion Scams: Fraudulent requests to divert employee salaries. - CEO Email Spoofing: Impersonation of company leaders to authorise payments.
Visual Intelligence:
BharatSecure's AI has identified this as a used in scams targeting Indian users.
Who Does Fake Invoice Redirect Scam via Email Target?
General public across India
Red Flags — How to Identify Fake Invoice Redirect Scam via Email
- Email address[ADDRESS_REDACTED]
- Sudden requests to change the supplier bank account
- No phone confirmation for payment instruction changes
- Poor grammar or unprofessional formatting in emails
- Urgency or pressure to pay immediately
What To Do If You Encounter Fake Invoice Redirect Scam via Email
- Do not click any links or share personal information
- Block and report the sender immediately
- Report at cybercrime.gov.in or call 1930
- Inform your bank if financial details were shared
How to Report Fake Invoice Redirect Scam via Email in India
- Call 1930 — National Cyber Crime Helpline (24x7)
- File a complaint at cybercrime.gov.in
- Contact your bank immediately if money was lost
- Call RBI helpline: 14440 for banking fraud
Frequently Asked Questions
- What is Fake Invoice Redirect Scam via Email?
- Overview: This scam targets Indian businesses by impersonating legitimate suppliers through hacked emails or lookalike email addresses. Most commonly, small and medium enterprises (SMEs) in sectors like textiles, pharma, and manufacturing are the victims. The fraudsters deceive companies into transferring funds to fake accounts, posing a serious risk to business operations and trust within supply chains. How It Works: 1. Criminals hack or mimic supplier emails using nearly identical domains.
- How does Fake Invoice Redirect Scam via Email work?
- Overview: This scam targets Indian businesses by impersonating legitimate suppliers through hacked emails or lookalike email addresses. Most commonly, small and medium enterprises (SMEs) in sectors like textiles, pharma, and manufacturing are the victims. The fraudsters deceive companies into transferring funds to fake accounts, posing a serious risk to business operations and trust within supply
- How to protect yourself from Fake Invoice Redirect Scam via Email?
- Do not click any links or share personal information Block and report the sender immediately Report at cybercrime.gov.in or call 1930 Inform your bank if financial details were shared
- How to report Fake Invoice Redirect Scam via Email in India?
- Report to cybercrime.gov.in or call 1930 (National Cyber Crime Helpline). You can also contact your local police station's cyber cell.
Verify Any Suspicious Message
Check any suspicious message, link, or call for free at bharatsecure.app. BharatSecure uses AI to detect scams in real-time and protect Indian users.