Fake Invoices From Compromised Subcontractors: A Q&A

When a real subcontractor's email is hacked, fraudulent invoices look legitimate. Answers to the questions finance teams ask about this scheme.

3 min readBy Ironfield Cyber Team

One of the most convincing forms of payment fraud arrives from a real subcontractor's real email account. The sub's mailbox has been compromised, and the attacker sends an invoice or updated payment instructions to the general contractor. Everything looks right: the name, the signature, the project reference, even the thread history.

This question-and-answer format covers what finance teams, project managers and owners most often want to know.

How does this actually happen?

An attacker gains access to a subcontractor's email through a phishing page, a reused password or a missing second factor. They read the mailbox quietly to learn who the customers are, what invoices are pending and how the subcontractor writes. Then they insert themselves into an existing conversation or send a new message, often just before a payment is due, with bank details that belong to them.

Sometimes they set up inbox rules to hide replies so the real subcontractor does not see the exchange.

Why is it so hard to spot?

Because the usual red flags are missing. The email address is genuine. The language matches. The invoice references a real pay application. The only difference may be the account number or a request to use a different payment method.

What are the most common signals?

  • A request to change banking details, especially close to a payment date.
  • A new payment method, such as a wire instead of a check or ACH.
  • Urgency, or pressure to pay before a certain time.
  • A reluctance to talk by phone, or an excuse for not taking a call.
  • Slight changes in tone, formatting or invoice layout.
  • A different bank name or location than before.
  • A request to keep the change quiet or to avoid copying others.

What is the single best defense?

Verify changes by calling a known phone number. That means a number from your own records, a signed contract or a prior verified conversation, not one in the email. Ask the person to confirm the account details and the reason for the change. Document the call.

Should we trust a call back to a number in the new email?

No. If the attacker controls the mailbox, they control the contact information in the message. Use independent contact details.

What if the subcontractor is busy or hard to reach?

Pause the payment change until you reach them. A short delay is far less costly than a lost payment. Many reputable subcontractors understand the procedure and appreciate it. Tell your vendors in advance that you verify all banking changes, so the request does not surprise them.

What internal controls help?

  1. A written policy that no bank change is processed without independent verification.
  2. Separation of duties, so the person who receives the request is not the only one who approves it.
  3. A second approval for changes and for first payments to new accounts.
  4. Reports of recent vendor changes reviewed weekly.
  5. Holding payments to recently changed accounts until verified.
  6. Training for accounts payable staff, project managers and anyone who communicates with vendors.

Can technology help?

Yes, in several ways. Multi-factor authentication on your own mailboxes limits attackers inside your company. Email filtering can flag unusual messages and external senders. Email authentication records reduce spoofing of your own domain. Some accounting systems can lock vendor bank fields or require approval workflows for changes. None replaces a verification call, but they reduce exposure.

What about our own subcontractors being attacked?

Encourage your vendors to use multi-factor authentication and to tell you right away if they suspect a compromise. In contracts, consider including notification requirements and a clause requiring that payment changes follow a defined process.

What if we already paid?

Act within the first hour if you can.

  1. Call your bank immediately and ask for a recall or fraud hold.
  2. Contact the receiving bank through your bank's fraud channel if possible.
  3. File a report with the FBI's Internet Crime Complaint Center, which can help when funds are caught early.
  4. Notify your insurance carrier and counsel.
  5. Contact the real subcontractor by a verified phone number and warn them their mailbox may be compromised.
  6. Preserve all emails and records.

Speed greatly improves the chance of recovering funds, though recovery is never guaranteed.

What should we do about our own mailboxes?

Check for suspicious inbox rules, forwarding settings and unfamiliar sign-ins, and reset credentials if you suspect compromise.

A Procedure Worth Having

Writing down the verification steps and rehearsing them once a year is among the cheapest ways to prevent a large loss. Ironfield Cyber helps contractors design payment controls and train finance teams, and we can review your current process with you.