Ghotala.wtf
English

Choose your language

Report a new scam

Choose your language

All languages

Vendor Invoice / Bank-Detail Diversion Fraud

In short

A business receives a message changing a supplier's invoice or bank-payment details The objective is typically to redirect a legitimate business payment to the fraudster.

What it is

The email appears to come from the real vendor or a compromised business mailbox. The victim is then pushed to pay an invoice to a new bank account controlled by the attacker.

How it starts

A business receives a message changing a supplier's invoice or bank-payment details.

What they tell you

The email appears to come from the real vendor or a compromised business mailbox

What they want you to do

Pay an invoice to a new bank account controlled by the attacker

How you lose money

redirect a legitimate business payment to the fraudster

What happens next

After the first successful step, the fraudster may demand more money/information, deepen account or device access, or disappear.

Warning signs

trust | urgency | routine | business email compromise | email takeover | domain spoofing

Where this is documented

India — officially documented by an Indian authority/regulator

How to avoid it

Verify payment-detail changes and executive requests through a second trusted channel; use MFA and domain/email controls; pause unusual urgent transfers.

If it already happened

Contact the bank/payment provider immediately if money moved; report financial cyber fraud promptly via 1930 and cybercrime.gov.in; preserve messages, transaction IDs, phone numbers and URLs. Alert finance/security teams and the receiving bank immediately, and preserve email headers and approval records.

Known variants

  • Invoice Thread HijackAn attacker uses a compromised mailbox inside a real invoice conversation.

Sources

Published documents this page draws on.

Already sent money or shared something?

What to do now

Vendor Invoice / Bank-Detail Diversion Fraud — Scam types