{"success":true,"data":{"id":"fake-invoice-vendor-payment-phish","label":"Fake vendor impersonating a known supplier with an attached invoice due immediately and a claim that banking details have changed — BEC payment-diversion fraud; real vendor banking-detail changes are authenticated out-of-band, never via cold email with \"process payment to the following account.\"","description":"Fake vendor impersonating a known supplier or business partner with a plausible invoice number (e.g., \"Invoice #8842 due immediately\") combined with a claim that banking or payment details have changed and an instruction to process payment to a new account — Business Email Compromise (BEC) payment-diversion fraud, one of the FBI IC3's highest-dollar loss categories. Real vendor banking-detail changes are authenticated through established out-of-band controls (phone callback to a verified number, signed letter on company letterhead, authenticated vendor portal update); a cold email claiming banking details have changed and directing the target to process an invoice payment to a new account is textbook BEC payment diversion. Distinct from wire-transfer-ceo-fraud-phish (executive impersonation / urgent wire / COB deadline) — this targets the vendor-impersonation / attached-invoice / banking-details-changed / process-payment-to-following-account pretext. Detection: attached invoice due immediately + banking details have changed + process payment to following account vocabulary + no List-Unsubscribe + no In-Reply-To + not protected sender. Trash score: +4. Source: GC1-R28; FBI IC3 BEC advisory 2024 (BEC losses $2.9B+); FinCEN BEC payment-diversion advisory; CISA BEC email guidance.","tier":"danger","category":"phishing","isThin":false}}