Why fake invoices look real
The modern version of this scam is not a badly written PDF. Attackers get into a mailbox, read months of genuine correspondence, take a real invoice, change the bank details, and send it from a domain that is one character different from the real one.
That is why 'it looked legitimate' is not a failure of attention. The document is legitimate. Only the destination changed.
The red flags
Any one of these should stop the payment until it is checked.
- The sender domain is subtly wrong — rn instead of m, an extra letter, .net instead of .com.au.
- The reply-to address differs from the from address.
- Bank details differ from the last invoice you paid this supplier.
- The account name does not match the trading or legal name.
- Urgency or secrecy language: pay today, do not call, the boss is in a meeting.
- The ABN is missing, inactive, or belongs to a different entity.
- GST is charged but the ABN is not registered for GST.
- The invoice number breaks the supplier's usual numbering pattern.
- The amount is oddly round, or just under an internal approval threshold.
- The invoice arrives from a personal email address.
- Formatting, logo quality, or wording differs from previous invoices.
- You were not expecting an invoice from this supplier at all.
The two checks that actually catch it
Eyeballing an invoice catches the crude ones. These two catch the good ones:
- Compare payee details against the last successful payment to that supplier — a change is the signal, regardless of how the invoice looks.
- Confirm by phone on a number you already had, never a number printed on the invoice.
Automate the comparison
RILLA Shield scans incoming invoices automatically, compares payee and bank details against the supplier's verified history, checks the ABN, and raises an alert before the payment is released rather than after.