Fake Invoice Attacks
Attackers are impersonating vendors and resubmitting believable invoices to reroute payment flows.
Stat: Targeting AP departments at 50–500 employee companies
Read Full BriefEmail compromise and impersonation attacks are targeting payment approvals, invoice changes, and executive requests.
Threat alert
Get the CSM Weekly Threat Brief and updates when this threat profile changes.
Attackers compromise or convincingly spoof executive and finance accounts to redirect payments or force urgent transfers.
AI-generated language, voice cloning, and real-time OTP interception are making these scams harder to detect by instinct alone.
AP teams are being pressured through urgency, secrecy, and realistic domain spoofing designed to bypass normal review.
AP departments and finance teams
Executive assistants and operations leads
Individuals handling family or business transfers
Wire change requests submitted minutes before payroll runs.
Voice-cloned approvals delivered during travel or off-hours.
Fake vendor onboarding emails sent from lookalike domains.
Losses are immediate and often difficult to reverse.
Incidents undermine trust in financial controls and approval workflows.
Recovery frequently requires legal, banking, and vendor coordination.
Require out-of-band verification for payment changes.
Deploy anti-impersonation and email authentication controls.
Train finance staff on authority pressure tactics.
Use MFA and session monitoring on executive accounts.
Vendors
BrightMail Shield
Email Security & Anti-Phishing
Inbox defense, domain impersonation monitoring, and phishing disruption.
Find More Vendors for This ThreatSignal Fraud Ops
Financial Fraud Prevention
Wire fraud controls, anomaly detection, and finance-team verification workflows.
Find More Vendors for This ThreatAwareLine Training
Security Awareness Training
Behavior-focused training for phishing, social engineering, and policy hygiene.
Find More Vendors for This ThreatRelated
Attackers are impersonating vendors and resubmitting believable invoices to reroute payment flows.
Stat: Targeting AP departments at 50–500 employee companies
Read Full BriefSynthetic voice and video are being used to impersonate executives, bypass trust checks, and trigger sensitive actions.
Stat: Voice + video cloning now used in fraud
Read Full BriefLLMs are enabling more targeted, more fluent, and more personalized phishing at industrial scale.
Stat: LLMs used to generate hyper-personalized attacks
Read Full Brief