Facebook Pixel
(303) 578-6256

Even an IT support company gets targeted. This week, someone tried to trick our team into wiring over twelve thousand dollars to a fake vendor, and they did it by combining two scams into one. We caught it before any money went out, but the attempt was convincing enough that we wanted to break it down for you in detail. If it can land in our inbox, it can land in yours.

This wasn't a sloppy, obviously-fake phishing email. It was patient, professional, and built to look exactly like a normal accounts payable task. That's what makes it worth talking about.

Stage One: The Fake Vendor Invoice

The first email showed up looking like it came from an accounting contact at a consulting firm we've never actually worked with. It referenced a specific invoice number, described a plausible service (executive training and software subscription management), and asked for payment via ACH. It even included a section labeled "required documentation" with a link to what claimed to be a W-9 form, along with an attached invoice PDF.

Nothing about it screamed scam at first glance. The formatting was clean, the tone was professional, and the invoice amount was just over twelve thousand dollars. That's large enough to matter, but not so large that it would automatically trigger extra scrutiny at most businesses. That's not an accident. Scammers often pick numbers that fall just under the threshold where a company would require additional sign-off.

Stage Two: The Spoofed "Owner" Follow-Up

About a month later, a second email landed, this one appearing to come directly from our owner and sent to our whole team. It referenced the same invoice and pushed for same-day payment. The message was short, urgent, and used exactly the kind of language you'd expect from someone in a hurry: pay this today, skip the standard vendor verification process, use the bank details already on file, confirm once it's done.

This is the part that made us sit up. The scammer wasn't just impersonating a vendor anymore. They were impersonating our own leadership, using internal-sounding language, and applying pressure to short-circuit the checks our team normally runs before paying anyone. It's a combination attack, and we're seeing more of them.

Why This Combination Almost Works

On their own, either of these emails might get caught. A random invoice from an unfamiliar vendor usually raises a flag. A single urgent request from "the owner" might also get a second look. But when the two arrive together, weeks apart, they reinforce each other. By the time the second email showed up, the invoice already existed in someone's inbox as a known reference point. It felt less like a request out of nowhere and more like a follow-up on something already in motion.

A few psychological levers were doing a lot of work here:

  • Authority. People are less likely to question a request that appears to come from an owner or executive, especially when it's sent to the whole team at once.
  • Urgency. Words like "same-day," "today," and "expedited" are designed to get someone moving before they stop to verify.
  • Permission to skip steps. Being told to bypass standard verification is a major warning sign on its own. Real leadership does not typically instruct staff to skip a company's own internal controls.
  • Plausible detail. A real-sounding invoice number, a specific dollar amount, and a named service all made the request feel routine instead of suspicious.

This is exactly the pattern the FBI describes as business email compromise: criminals send a message that appears to come from a known, trusted source making a request that looks completely legitimate.

How We Caught It

We didn't send the payment. Someone on our team noticed the mismatch between how the request was framed and how we actually handle vendor payments, and paused before acting instead of moving fast to "help." That pause is the whole point of training your staff on this. It doesn't take a security expert to catch a scam like this one. It takes someone who knows to stop and verify before money moves, even when the email looks legitimate and even when it appears to come from someone they trust.

How You Can Train Your Team to Catch the Same Thing

A few habits go a long way toward stopping scams like this before they cost you anything:

  • Verify payment requests through a separate channel. If an email asks for money, a phone call or an in-person conversation with the actual requester should confirm it before anything gets sent, even if the email appears to come from an owner or executive.
  • Never let urgency override process. "Bypass the standard verification" should be treated as a red flag, not an instruction to follow. If your normal process involves checking a new vendor before paying them, that process exists for a reason.
  • Check the actual sender address, not just the display name. Spoofed emails often use a display name that matches someone real while the underlying email address has nothing to do with your company.
  • Be suspicious of new vendors asking for "expedited" or "one-time" treatment. Scammers frequently ask for shortcuts specifically because they know a full onboarding process would expose them.
  • Report it, even if nothing was lost. We reported this attempt to the FBI's Internet Crime Complaint Center (IC3) and reviewed the FTC's guidance on business impersonation scams. Reporting attempts helps law enforcement track patterns, and it can keep the same scammer from succeeding against another business.

According to CISA, most BEC incidents involve either a compromised executive email account or a compromised vendor account, both used to redirect a wire transfer or ACH payment that looks completely routine. That's exactly the pattern we saw, and it's why "does this look normal" isn't a good enough test on its own anymore.

The Bottom Line

Hackers are getting smarter about blending in. The days of obviously broken English and suspicious foreign wire requests are fading. What's replacing them are quiet, well-written, patient scams that mimic your actual business processes. We caught this one because someone paused instead of moving fast. That's the entire defense: a team that knows to slow down and verify, no matter how legitimate a request looks or who it appears to come from.

If you want help putting real verification steps in place for payment requests, or want your team walked through what to look for, reach out to us for a quick security review. We're happy to help you build a process that catches this stuff before it ever becomes a problem.


Worried your team might not catch a scam like this?

Talk to ITGuys About Security Training