Home About Shannon Services Industries San Diego Blog Tools & Resources Contact Book Now

An accounts payable clerk opens an invoice for a software subscription, billed to her company by name, addressed to her CEO. Below it is what looks like the history behind it: her CEO and the software company's president working out the purchase, the rollout, and how the invoice should be handled. It reads like the deal is already done. Nothing about the invoice looks off, and neither does the conversation sitting under it.

The problem is that no one wrote either message. Both were built by whoever sent the invoice. It's vendor payment fraud with a new layer on top, aimed squarely at the check most AP teams rely on.

That's not a hypothetical. Microsoft's security team traced a single campaign built on exactly this trick to more than a million emails sent between August 3 and 5, 2026, with nearly 88 percent of them landing in US inboxes. The specific numbers will age out of relevance. The method won't. It's worth thirty minutes of your time now, because the fix isn't reading more carefully. It's changing what counts as proof.

The Trick Isn't the Invoice. It's the Conversation Under It.

The invoices themselves aren't especially sophisticated. Microsoft's report describes attackers impersonating a CEO, CFO, or president across the sender name, the reply-to name, and the email signature, and sending through third-party email services. The invoice bills nearly $50,000 for a fake annual software subscription, with the recipient's own company name and executive name filled into the "billed to" section so it reads as legitimate at a glance. Payment goes by ACH to an account the attacker controls. Two lookalike domains, registered just three days before the emails went out, carry the whole thing. None of that is new. Invoice fraud has looked roughly like this for years.

What's new, and what makes this version worth teaching, is the fabricated thread attached to the invoice. The email doesn't just ask for payment. It includes a fake conversation between the impersonated CEO and the vendor's president, discussing the purchase, the implementation, and how to handle the invoice. It answers the question an AP person is trained to ask, did someone with authority agree to this?, before they've had a chance to ask it.

The brand being borrowed, in this case a well-known software vendor, was never involved. Microsoft found no evidence that it or any other organization named in the emails was compromised. It was impersonated, not breached. That distinction matters if you're deciding what to check: calling the real vendor would have ended this in one conversation.

The tells, if anyone looks: the quoted messages had none of the header detail a genuinely forwarded email carries, and the thread included lines like "no need to copy me," which is exactly what someone says when they don't want a second person checking.

Worth saying plainly: this comes from one company's own security telemetry, not a government fraud advisory, and most of the coverage since has restated the same report rather than investigating separately. None of that makes the mechanism less real. It just means the honest thing to do is treat it as a documented pattern, not an official warning, and evaluate your own controls on the merits.

Why an Email Thread Was Never Proof of Approval

Here's the part worth sitting with: a conversation quoted inside an email was never actually verification, even before anyone learned to fabricate one. Anyone who receives an email can quote it, forward it, or splice pieces of it into a new message. The presence of a conversation in your inbox is not evidence that the conversation happened. It's evidence that someone typed it.

Real approval has to travel through a channel a fraudster can't reach: a workflow tool your business actually uses, a phone call, a conversation with someone who was in the room. If the only evidence an invoice was approved lives inside the same email asking you to pay it, you don't have an approval. You have a claim.

This is the shift worth making in how your team thinks about payment requests. Not "does this look convincing," but "where did this approval actually come from, and could someone outside my company have manufactured that path themselves?"

The Two-Question Check That Catches Vendor Payment Fraud

Good invoice fraud prevention doesn't require new software. It takes two questions, asked every time, especially for anything new.

Does this vendor already exist in our system, with a contract or purchase order behind it? A software renewal from a company you've never signed anything with is the first flag, no matter how polished the invoice looks.

If this is a new vendor, or a payment to new bank details, has someone called a phone number we already had on file, not one printed in the email, to confirm it? The call is the entire control. A fabricated thread can survive being read. It cannot survive a phone call to a number the fraudster never had.

The person confirming should be someone with the standing to actually know, and the confirmation should happen apart from the email entirely, not as a reply to it. Replying to the thread just asks the fraudster whether the fraudster is legitimate. Once the call-back habit is in place, a forged conversation stops being useful to anyone trying to use one against you. It works best when the person approving payments isn't also the person entering them, which is the whole case for separating bookkeeping from bill-pay.

The distinction that matters: verify through a channel the sender can't touch. A number already on file, a contract already signed, a person you can reach without using anything in the email.

What to Check in Your Books Right Now

Two places to look, and neither requires special tools.

Pull your recent software and subscription bills and ask, for each one, whether an actual contract exists behind it. A fake renewal is built to look like the dozen real ones sitting next to it in your inbox.

Then look at ACH and wire payments from the last several weeks. Any payment that cleared without a purchase order or signed agreement behind it deserves a second look, whether or not anything currently seems wrong.

The exposure grows with the business, not the other way around. A solo owner usually knows every vendor by name. Once you have staff handling payments who don't personally know how the owner writes an email, and enough legitimate subscriptions that one more doesn't stand out, a fabricated invoice has more room to hide.

This Is Also a Process Problem, Not Just a Vigilance Problem

There's a second layer here worth knowing about if your business sends ACH payments through its bank. Under Nacha's fraud monitoring rule, which reached all remaining business originators in June 2026, businesses that originate ACH payments are expected to have risk-based processes and procedures for spotting payments that are unauthorized or that were authorized under false pretenses, and to review them at least annually. False pretenses is defined to include someone misrepresenting who they are or their authority to act for someone else. That's precisely this scenario: a payment you meant to send, moved because you were deceived about who was asking.

The rule doesn't dictate a format, and exactly how it applies depends on how your payments are set up, so it's worth a conversation with your bank. My practical advice is to write the process down anyway. A procedure that lives only in one person's head is hard to show anyone, and hard to hand to the next person who handles payments. If "someone always calls a known number to double-check new bank details" already describes what your team does, you're closer than you think. If nothing about vendor verification is written down anywhere, that's the gap to close first. Our free Bookkeeping Health Score is a quick way to see where your current controls stand.

If you want to see the same pattern in a different disguise, the FBI warned in September about scammers impersonating licensing authorities and telling medical practitioners their license is expiring or was used in a crime, then demanding payment to resolve it. Different costume, same core move: borrow legitimate-looking authority to get you to move money before you check. More variations are in our roundup of scams against business owners.

The Bottom Line

A fabricated approval thread is theater layered on top of an old form of vendor payment fraud. The invoice was never the vulnerable point. The assumption that a conversation in your inbox proves anything did the work. Fix that one assumption, verify anything new through a channel the sender can't touch, and the theater stops mattering. Businesses that write this down now are also getting ahead of a monitoring standard that already applies to anyone originating payments by ACH.

If you think a fraudulent payment has already gone out, call your bank first, since speed matters for any chance of recovery, then report it to the FBI at ic3.gov.

We work with business owners nationwide, entirely virtually, on exactly this kind of systems question: not just recording what happened in your books, but building the controls that keep the wrong things from happening in the first place.

See how we approach clean, reviewed books: Our Bookkeeping Services

Questions about your books? Reach us at info@saltandsandbookkeeping.com or (619) 304-SALT (7258).

Not sure your payment process would catch a fake approval? Let's take a look.

Schedule a Free Consultation
← Back to all posts