Fake Supplier Emails and Invoices: Real Fraud Cases Every Indian MSME Should Know
Fake invoices and supplier impersonation scams are a serious risk for Indian MSMEs. Real cases show how criminals use fake purchase orders, lookalike emails, forged invoices and changed bank details to redirect business payments. Learn how manufacturers, exporters, distributors, retailers, CA firms and finance teams can verify suspicious requests before approving payments or releasing goods.
A supplier sends an invoice that looks normal. The company name is familiar, the amount matches your purchase order and the email appears to come from the correct contact.
Then you notice one difference: the bank account has changed.
The message says the old account is under review and asks you to complete the payment before a deadline. Your production team is waiting for the material, the supplier is calling repeatedly and the accounts team is under pressure.
This is how supplier impersonation and invoice-payment fraud often begins.
Fake invoices, forged purchase orders, lookalike supplier emails and changed bank details can affect manufacturers, exporters, wholesalers, retailers, CA firms and other Indian MSMEs.
ScamShield AI helps businesses review suspicious emails, invoices, WhatsApp messages, links, QR codes, UPI IDs and payment requests before money or goods leave the business.
This article examines real cases reported in India and explains how businesses can build a safer payment-verification process.
Who Should Read This Guide?
This article is especially useful for:
- Manufacturers paying suppliers for raw materials, components and machinery.
- Importers and exporters handling overseas invoices and payment instructions.
- Wholesalers and distributors processing vendor and customer payments.
- Retailers accepting UPI payments and releasing goods quickly.
- CA firms reviewing GST documents and client payment requests.
- Finance and accounts-payable teams approving invoices.
- MSME owners who personally approve high-value payments.
India’s MSME sector contributes approximately 31.1% of GDP, 48.58% of total exports and around 35.4% of manufacturing output. This makes MSMEs an important part of the country’s commercial ecosystem and an attractive target for fraudsters.
What Is Fake Invoice Fraud?
Fake invoice fraud occurs when criminals create, alter or redirect an invoice to make a business send money to an unauthorised account.
The invoice may be:
- Completely fabricated.
- Copied from a real supplier’s document.
- Modified to show a different bank account.
- Sent from a compromised supplier email account.
- Sent from a lookalike domain.
- Attached to a fake purchase order.
- Accompanied by a fake GST notice.
- Connected to a fraudulent UPI ID or QR code.
The criminal does not always need to hack a company’s accounting software. In many cases, the attack begins with a convincing email or WhatsApp message that causes an employee to approve the wrong payment.
The central warning is simple:
A professional-looking invoice is not proof that the payment request is genuine.
How Supplier Payment Fraud Works
A typical supplier-payment scam follows this pattern:
- Criminals identify a business and its suppliers.
- They study company websites, LinkedIn profiles, invoices and public contact details.
- They create a lookalike email address or impersonate a known contact.
- They send an invoice, purchase order or payment instruction.
- They introduce urgency, confidentiality or a deadline.
- They replace the genuine bank details with an account controlled by the criminal.
- An accounts employee approves the transfer.
- The criminals stop responding after receiving the money.
Sometimes criminals compromise a real supplier mailbox. This makes the fraud especially difficult to recognise because the message may appear inside an existing email conversation.
Other attackers use WhatsApp, phone calls or fake government identities to reinforce the story.
Real Case: Bengaluru Firm Loses More Than ₹26 Lakh
In March 2026, a Bengaluru-based company that imported and supplied hard plastic cases reportedly lost more than ₹26 lakh after criminals posed as BSF officials and issued a fake purchase order.
According to the reported complaint, the business received an enquiry from a person claiming to work in the BSF purchase department. A purchase order followed, creating the appearance of an authentic defence-procurement opportunity.
The company then sent a proforma invoice requesting a 50% advance. Another person allegedly claimed to be from the BSF accounts department and explained that payments would follow an “Indian Army procedure.”
The criminals reportedly instructed the company to make several bank transfers. Small transactions were allegedly used to build confidence before larger payments were requested.
By the time the company recognised the fraud, approximately ₹26 lakh had reportedly been transferred. The business then reported the incident to the 1930 cybercrime helpline.
Lessons for MSMEs
This case shows how a fraudulent transaction can appear credible when criminals combine:
- A fake purchase order.
- A government or defence identity.
- A proforma invoice.
- Multiple people acting as officials.
- Small test payments.
- Multiple beneficiary accounts.
- Pressure to follow an unfamiliar procedure.
How ScamShield AI Could Help
Before making a payment, the company could have screened the purchase-order email, invoice, payment instructions and related WhatsApp messages with ScamShield AI.
ScamShield AI could help identify:
- Suspicious sender details.
- Impersonation signals.
- Unusual payment instructions.
- Multiple beneficiary accounts.
- Authority-based pressure.
- Urgent or confidential language.
- Inconsistencies between the organisation’s identity and the communication.
ScamShield AI would not replace confirmation with the genuine organisation. The company should still contact the organisation through an independently verified official channel.
The accurate claim is:
ScamShield AI could have added an early warning and escalation checkpoint before the transfers were made.
It would be inaccurate to claim that ScamShield AI definitely would have prevented the loss without verified product evidence from this case.
Real Case: Mumbai Firm Targeted Through Supplier Impersonation
In May 2026, Mumbai cybercrime police reportedly investigated a case in which criminals impersonated a Thailand-based raw-material supplier. The company reportedly lost ₹32 lakh after payments were redirected to an overseas bank account.
This type of fraud is especially relevant to:
- Manufacturers importing raw materials.
- Exporters working with overseas suppliers.
- Businesses using proforma invoices.
- Companies with international payment processes.
- Firms that rely heavily on email for supplier communication.
What Importers and Exporters Should Verify
Before paying an overseas invoice, confirm:
- The exact supplier email domain.
- The sender and reply-to addresses.
- The beneficiary name.
- The beneficiary country.
- The supplier’s registered business details.
- Whether the bank account matches previous payments.
- Whether the payment terms match the contract.
- Whether the bank-account change was confirmed independently.
Do not verify a new bank account by replying to the same email thread. If the supplier mailbox has been compromised, the criminal may continue responding.
Use a phone number or contact method already stored in your supplier records.
How ScamShield AI Could Help
ScamShield AI can provide an additional review of:
- Supplier emails.
- Proforma invoices.
- Payment instructions.
- Links and attachments.
- WhatsApp conversations.
- UPI IDs and QR codes.
The system can help identify possible:
- Lookalike domains.
- Supplier impersonation.
- Suspicious wording.
- Urgent payment pressure.
- Payment-diversion signals.
- Inconsistencies in documents.
The final payment decision should still include independent supplier confirmation, internal approval and bank-detail verification.
Real Case: Alleged Fake-Vendor Payment Diversion
In July 2026, a Mumbai airport-services company reportedly uncovered an alleged ₹1.34 crore fraud involving fake vendors, forged bills and diverted company funds. A finance manager and another person were reportedly accused in connection with the alleged scheme.
This case is different from an external supplier-email attack. It demonstrates that invoice fraud can also exploit internal finance processes and weak vendor controls.
Lessons for Finance Teams
A business should not assume that an invoice is safe simply because:
- It uses a familiar vendor name.
- It contains a GST number.
- It is entered into accounting software.
- It has been approved by one employee.
- It appears to follow the usual invoice format.
Businesses should reconcile:
- Purchase order.
- Goods-received note.
- Supplier identity.
- Invoice.
- GST information.
- Bank-account ownership.
- Approval history.
- Payment beneficiary.
How ScamShield AI Could Help
ScamShield AI is most useful at the communication and document-analysis stage. It can help flag suspicious emails, attachments, invoices and payment requests before they move through the approval process.
However, AI screening should be combined with:
- Segregation of duties.
- Dual approval.
- Restricted vendor-master access.
- Independent supplier verification.
- Regular vendor reviews.
- Bank-account confirmation.
- Accounting reconciliation.
A strong control environment does not rely on one tool or one employee.
Who Needs Protection?
Manufacturers
Manufacturers should pay particular attention to raw-material and machinery payments.
Before approving an invoice:
- Compare it with the purchase order.
- Confirm that the goods were actually ordered.
- Check the sender domain against previous supplier emails.
- Verify any bank-detail change by phone.
- Match the beneficiary name with the approved supplier.
- Require a second approval for high-value payments.
- Review unusual urgency connected to production delays.
ScamShield AI use case: Submit the supplier email, invoice and payment instruction for a risk review before payment approval.
Check a suspicious supplier email before paying for raw materials.
Importers and Exporters
International payment fraud can be difficult to reverse because money may move through several jurisdictions.
Before payment:
- Confirm the supplier or buyer’s legal identity.
- Check the exact email domain.
- Compare the beneficiary country with previous transactions.
- Confirm any account change through a known contact.
- Review the proforma invoice against the contract.
- Check whether the request matches normal trade terms.
- Avoid making urgent payments based only on email.
ScamShield AI use case: Analyse overseas supplier emails, proforma invoices, attachments and payment instructions.
Protect import-export payments from supplier impersonation.
Wholesalers and Distributors
Wholesalers and distributors often handle frequent payments and release goods quickly.
Protect both outgoing and incoming payments:
- Check supplier invoices before paying.
- Verify new bank details independently.
- Confirm incoming money in your own account.
- Never release goods based only on a screenshot.
- Review suspicious UPI IDs and QR codes.
- Use dual approval for large orders.
ScamShield AI use case: Check supplier emails, UPI IDs, QR codes, screenshots and WhatsApp conversations.
Check a suspicious payment screenshot before releasing stock.
Retailers
Retailers are often targeted at the point of sale.
Common warning signs include:
- A customer showing a screenshot instead of waiting for confirmation.
- A “payment successful” message that is not visible in your account.
- A request to refund money to another UPI ID.
- A QR code supplied by an unfamiliar person.
- Pressure to release goods immediately.
- A payment showing as pending or failed.
Use this rule:
No payment visible in your own merchant account means the payment is not yet verified.
ScamShield AI use case: Analyse a payment screenshot, QR code, UPI ID or WhatsApp message.
Check suspicious UPI payment evidence.
CA Firms and Accountants
CA firms handle sensitive financial communication for multiple clients.
Before advising a client to make a payment or accept an invoice:
- Verify whether the communication came from a known contact.
- Check GST details through official systems.
- Match invoices with the client’s records.
- Confirm that goods or services were actually supplied.
- Treat urgent tax-payment instructions as suspicious.
- Do not rely only on a PDF or screenshot.
- Preserve the document and communication trail.
ScamShield AI use case: Triage suspicious GST notices, invoices, payment requests, links and WhatsApp messages before professional review.
Add fraud screening to your client communication workflow.
Finance and Accounts-Payable Teams
The finance team should use a standard pre-payment workflow:
- Receive the invoice or payment request.
- Screen the message, attachment or link with ScamShield AI.
- Review the risk verdict and explanation.
- Compare the invoice with previous documents.
- Call the supplier using a known number.
- Independently verify any bank-account change.
- Match the purchase order, goods receipt and invoice.
- Obtain a second approval.
- Release the payment only after all checks pass.
- Save the evidence and approval record.
Adding independent bank-detail verification to the vendor-payment process can strengthen protection against payment diversion.
Warning Signs of a Fake Supplier Invoice
A Changed Bank Account
Treat any request to change bank details as high risk until independently confirmed.
A Lookalike Email Address
Check every character in the domain. Criminals may replace a letter, add a word or use a different domain ending.
Urgent Payment Language
Be cautious when a message says:
- “Pay today.”
- “This is confidential.”
- “The old account is closed.”
- “The supplier will stop dispatching.”
- “The director has already approved this.”
- “Do not call because I am travelling.”
- “This is the final reminder.”
A New UPI ID or QR Code
A familiar company name does not prove that the UPI ID or QR code belongs to the supplier.
A Suspicious Attachment
Look for:
- Different fonts.
- Misaligned totals.
- Incorrect GST details.
- Missing invoice information.
- Inconsistent invoice numbering.
- Poor-quality logos.
- An unexpected file type.
- A bank account that differs from previous invoices.
An Unusual Approval Process
A request that bypasses procurement, accounts or management controls should be paused.
How ScamShield AI Helps
ScamShield AI provides an additional risk-screening layer for Indian businesses.
Depending on the feature being used, a team can submit:
- Supplier emails.
- Invoices.
- Purchase orders.
- Payment instructions.
- WhatsApp messages.
- Screenshots.
- Links.
- QR codes.
- UPI IDs.
- GST notices.
ScamShield AI helps analyse signals such as:
- Lookalike sender domains.
- Impersonation patterns.
- Suspicious urgency.
- Payment-diversion language.
- Inconsistent document information.
- Suspicious UPI identifiers.
- Potentially malicious links or QR codes.
- Evidence that a payment screenshot may have been manipulated.
The result is intended to support a safer business decision and help employees know when to escalate a message for independent verification.
ScamShield AI does not replace:
- Bank confirmation.
- GST-portal verification.
- Supplier due diligence.
- Purchase-order matching.
- Goods-received checks.
- Two-person approval.
- Professional tax or legal advice.
The strongest protection combines technology with clear internal controls.
A Payment-Verification Policy for MSMEs
Businesses can adopt this simple policy:
No employee may approve a payment to new or changed bank details based only on an email, WhatsApp message, invoice, PDF, screenshot or phone call. All payment-detail changes must be verified through a previously known supplier contact. Payments above the company’s approval threshold require a second authorised reviewer.
This policy is simple, but it addresses the main weaknesses exploited in many payment-diversion scams.
What to Do If Fraud Is Suspected
If money has already been transferred:
- Contact your bank immediately through its official fraud channel.
- Call India’s cyber-fraud helpline at 1930.
- Report the incident through the National Cyber Crime Reporting Portal.
- Preserve emails, full headers, invoices, bank details, phone numbers and transaction records.
- Contact the genuine supplier through a previously known number.
- Inform your finance lead, owner, CA or legal adviser.
- Do not delete or edit the original messages.
- Keep a record of every action and reference number.
The Government of India has described the 1930 helpline and the National Cyber Crime Reporting Portal as part of its financial-cyber-fraud response system. Fast reporting can help financial institutions and authorities trace or restrict suspicious funds.
If you have not yet lost money but have received a suspicious phone number, email, URL, WhatsApp handle or message, use the appropriate official reporting channel rather than engaging with the sender.
What ScamShield AI Can and Cannot Do
ScamShield AI can help you:
- Review suspicious emails and invoices.
- Identify possible impersonation signals.
- Detect lookalike domains.
- Analyse urgent payment language.
- Check suspicious WhatsApp messages.
- Review payment screenshots.
- Examine UPI IDs and QR codes.
- Explain why a communication may be risky.
- Create an early-warning checkpoint before payment or dispatch.
ScamShield AI cannot guarantee:
- Detection of every scam.
- Recovery of money after a transfer.
- That a valid GSTIN proves a transaction is genuine.
- That a risk verdict replaces human approval.
- That a low-risk result guarantees safety.
- That a document is legally valid for GST purposes.
Honest limitations are important. ScamShield AI is designed to help businesses make safer decisions, not to replace their entire finance, tax or procurement process.
Final Checklist
Before paying a supplier or releasing goods, confirm:
- The sender’s domain is correct.
- The invoice matches the purchase order.
- The supplier identity is verified.
- The GST details are checked through official systems.
- The goods or services are expected and documented.
- The bank account has not changed without confirmation.
- The beneficiary name is correct.
- The payment is approved by the required people.
- A suspicious message or document has been screened.
- All supporting evidence is retained.
If anything feels unusual, pause the payment.
Protect Your Business Before Money Leaves
Fake invoices and supplier impersonation do not always look like obvious scams. They may appear as a normal email, a professional PDF, a familiar supplier conversation or an urgent request connected to a genuine order.
That is why MSMEs need a repeatable verification process.
Whether you manufacture products, import materials, export goods, distribute stock, operate a retail shop, manage client accounts or approve invoices, ScamShield AI can provide an additional risk check before money or goods leave your business.
Check a suspicious supplier email with ScamShield AI.
Check a fake payment screenshot before dispatching goods.
Forward a suspicious WhatsApp message for analysis.
A suspicious invoice should never be treated as routine until it has been independently verified.