News

How to spot a fake invoice


Business email compromise

How to spot a fake invoice

It isn’t a hack. It’s a conversation. Five signals worth teaching everyone who handles a payment — and the one control that stops it.

Comstel ICT · Cybersecurity · August 2026

Someone reads a real email thread — often from a supplier who was breached, not you. They wait for a genuine invoice, then send a follow-up from a near-identical address: “Please note our bank details have changed.”

Everything about it is right. The logo, the amount, the tone, the timing. That’s why it works, and why antivirus never sees it.

  • 6 minA cybercrime reported in Australia, on average
  • $56,600Average cost per report for a small business
  • 42%Of critical incidents involved compromised credentials

Source: ASD Annual Cyber Threat Report 2024–25.

Five ways to spot one

  1. New or changed bank detailsThe single biggest signal. Always verify by phone on a number you already had — never the one printed on the invoice.
  2. Urgency and secrecy“Pay today.” “I’m in meetings, don’t call.” “Keep this between us.” Pressure and isolation are the tactic, not a coincidence.
  3. Look-alike sender addressesOne changed character is enough — comstel versus cornstel. At a glance in a busy inbox they’re identical.
  4. Details that are slightly offWording, formatting or an amount that doesn’t quite match previous invoices from the same supplier.
  5. A reply-to that doesn’t matchThe display name says one thing; the address the reply actually goes to says another.

Make it a rule, not a judgement call

Any change to payment details is verified by phone, on a previously known number, by a second person.

The businesses that don’t lose money have that written down. No exceptions, no matter who appears to be asking. It costs two minutes, and it’s the single most effective control against a scam that has no technical signature at all.

What reduces how often you need it

  • Email filtering

    Managed email security stops most of it arriving in the first place.

  • MFA everywhere

    A stolen password isn’t enough on its own to get into an account.

  • Payment verification

    A written out-of-band process for any change to banking details.

  • Dark web monitoring

    Tells you when staff credentials surface in a breach dump — usually the first step in a scam that targets you by name.

None of it replaces the phone call. All of it reduces how often you need to make one.

Find out what’s actually reaching your inbox

Book a free business audit. We’ll review your email filtering, MFA coverage and credential exposure, then tell you plainly where the gaps are.

Book a free business audit

Get in touch

Tell us what you need and we’ll get back to you — usually the same business day.

By submitting, you agree to Comstel’s Privacy Policy.

Enquiry received

A real Australian-based specialist will be in touch the same business day.