Email Spoofing: How Fake Business Emails and Invoice Scams Actually Work

Email Spoofing: How Fake Business Emails and Invoice Scams Actually Work

A payment request can look routine: the supplier name is familiar, the invoice format looks right, and the message appears to come from someone your team knows. That is why email spoofing deserves attention from New Zealand businesses. Attackers no longer depend on obvious spelling mistakes or unlikely stories; they exploit normal payment habits and trusted identities. For organisations reviewing Microsoft 365 setup and support NZ, understanding how fraudulent email is created, delivered, and verified can stop a convincing message from becoming a costly transfer.

Why Fake Invoice Requests Can Be So Convincing

Invoice fraud succeeds because the attacker imitates a normal business process. A convincing request may arrive near month-end, refer to a genuine project, or claim that a supplier has changed bank accounts. The risk rises when staff are busy, and payment approval depends mainly on what appears in the inbox.

Attackers Study How a Business Communicates

Criminals may gather information from company websites, LinkedIn profiles, breached credentials, public tenders, or earlier conversations. They learn who handles accounts, which suppliers are used, and how senior staff normally write. This is why business email compromise can be damaging: a real mailbox gives the attacker timing, signatures, invoices, and genuine conversation history.

Spoofing Is Not the Same as a Compromised Mailbox

With email spoofing, the attacker makes a message appear to come from a trusted sender without necessarily controlling that person’s mailbox. In a real compromise, the criminal has authenticated access and may read conversations or send messages internally. A staff member may describe either incident as “email account hacked”, but the distinction matters because investigation and containment steps differ.

What a Typical Invoice Scam Looks Like From Start to Finish

A fake invoice email usually creates a believable sequence that lowers suspicion. One reason email spoofing works is that each step can resemble something finance teams already process every week.

  • Initial contact: The message appears to come from a supplier, manager, director, or accounts contact.
  • Plausible reason: The sender says banking details changed or an urgent invoice needs processing.
  • Pressure: The email mentions a deadline, late fee, shipment delay, or senior management request.
  • Payment redirection: New account details are supplied, sometimes on a copied invoice with only the banking information altered.
  • Follow-up: If the recipient hesitates, the attacker replies quickly and confidently.

If a business accepts bank-detail changes by email alone, the criminal may only need a convincing message to pass that weak process.

How Attackers Make a False Sender Look Legitimate

A false message can exploit what employees see on screen and how mail systems validate the sender. On a phone, a familiar display name can be more prominent than the real address, while a near-identical domain may be hard to spot.

Lookalike Addresses Exploit Visual Trust

Domain spoofing may use an address that looks almost identical to the genuine company domain, while display-name tricks can show a familiar person’s name even when the underlying address is unrelated. Because email spoofing can imitate familiar identities, employees should inspect the full sender and reply-to details before acting on unusual financial requests.

Authentication Controls Reduce Impersonation Risk

DKIM helps receiving systems verify that a message was authorised by the sending domain and not altered in transit, while DMARC tells receiving servers how to handle messages that fail authentication checks. These controls strengthen business email security, but criminals can still register lookalike domains or compromise genuine accounts.

Why New Zealand Businesses Should Treat Payment Changes as High Risk

In Q3 2025, New Zealand’s National Cyber Security Centre reported NZ$12.4 million in direct financial losses and highlighted significant losses involving compromised business mailboxes, fake invoices, and altered payment details. Its guidance remains practical: new or changed bank details should be verified through another trusted channel rather than relying only on the email itself.

A useful rule is: a changed bank account is a changed risk condition. Before paying, staff should call a supplier using a number already held on file, not one included in the message.

Watch for:

  • an unexpected request from a senior employee;
  • a reply address that differs from the visible sender;
  • unusual urgency or secrecy;
  • invoice formatting that is almost, but not quite, familiar;
  • a suspicious login notification around the same time as unusual email activity.

Several clues appearing together should be enough to pause the payment and verify it independently.

What to Check When Microsoft 365 Email May Be Compromised

If a user has entered credentials into phishing emails or approved an unexpected sign-in request, resetting the password may not be enough. Attackers can preserve access or alter mailbox behaviour after the breach, so the response should examine both identity and email settings.

Review the Mailbox for Persistence

Attackers sometimes create malicious forwarding rules so finance-related messages continue going to an external address. Review mailbox rules, forwarding settings, recent sign-ins, active sessions, recovery information, administrator roles, and connected applications. Check whether fraudulent messages were sent to customers or suppliers who may need warning.

Strengthen Identity Controls After Containment

Require MFA for users and especially administrators; two-factor authentication adds an important barrier when a password is stolen. Remove unnecessary privileged access and review new devices or applications associated with the account.

For businesses in Wellington, Hutt Valley and Wairarapa needing hands-on help with devices, email configuration or wider IT issues, Tech On Road provides on-site technical support across those regions. That service model can help when a cloud investigation also involves affected PCs, Outlook profiles, mobile devices, or local network problems.

Build a Payment Verification Process Before the Next Scam Arrives

The most effective defence against email spoofing combines technical controls with a payment process that assumes email can be manipulated. Configure sender authentication, protect identities, restrict unnecessary administrator access, and train staff to question unusual requests. Make independent verification mandatory for new suppliers, changed bank details, and high-value payments.

Define the procedure before anyone is under pressure. Who approves a bank-detail change? Which trusted phone number should accounts staff use? What happens when the requester says the payment is urgent? Clear answers make security part of normal work rather than an emergency reaction.

If your organisation has never tested this process, use the next finance or IT meeting to walk through a realistic invoice scenario. Strong account security is not only about stopping attackers at the login screen; it is also about ensuring one convincing email cannot bypass the checks that protect company money.