The fake unpaid invoice email
A notice claiming an overdue invoice, pressuring quick payment to avoid a late fee or service disruption.
The scenario
This is an illustrative training example, not a real invoice from Claro or any supplier. In this scenario the email is dressed up as a routine bill from a vendor or your own finance department, with a subject line like 'Invoice Overdue' or 'Payment Required'. It usually carries a PDF attachment or a 'view invoice' link, plus a polite but firm note that payment is now past due.
The pretext leans on how ordinary invoices are. Paying suppliers is normal business, so a bill rarely feels suspicious on its own. The message adds just enough pressure, a late fee, a threatened suspension, or a note that an account will go on hold, to nudge you toward paying before you stop to check the details.
It reaches finance and operations staff in the flow of everyday work, often mixed in with genuine invoices during a busy billing period or near month-end. Because these teams handle a high volume of similar documents, one more request blends in easily, and the sender may even reference a real project or a familiar supplier name to lower your guard.
It is convincing because the trap is in the details rather than the design. The attachment might be a macro-enabled document that runs code when opened, or the link might lead to a fake payment portal. In the most damaging versions the bank account number has been quietly changed, so a routine-looking payment lands in the attacker's account instead of your real supplier's.
Red flags to spot
A slightly altered vendor email address, with an extra letter or a different domain
Attackers spoof a familiar vendor name while the actual sending address is a close lookalike.
Bank account details that differ from the vendor's usual account
A sudden change in payment details is one of the most common signs of invoice fraud.
A threat of service suspension or legal action if you do not pay immediately
Genuine vendors rarely threaten instant suspension over a single invoice without any prior notice.
An attachment that asks you to enable macros or install a viewer to open it
This is a common technique to run malicious code the moment the file is opened.
An amount or reference that does not match any purchase order or contract you have
Legitimate invoices tie back to a real order, so a bill you cannot reconcile deserves a closer look.
Pressure to keep the payment quiet or bypass your normal approval steps
Fraud thrives when someone skips the second check, so any nudge to work around process is a warning.
The lesson
Verify any invoice or change of payment details before you act, no matter how routine it looks. Call the vendor on a phone number you already have on file, not one printed in the email, and confirm the amount and bank account against your own records or approval system. If the request cannot be verified, hold the payment and report the message to your finance and security teams.
These are illustrative examples built for training purposes only, not real messages sent by Claro or any actual organization.
Frequently asked questions
Contact your bank straight away to see whether the payment can be recalled, and tell your finance and security teams what happened. If you opened an attachment, disconnect the device from the network and let IT check it. Fast reporting improves the odds of recovering funds and containing any malware.
Related pages
Courier Delivery Scam
A message claiming to be from a courier says a package couldn't be delivered and asks for a redelivery or customs fee via a link.
Learn moreHR Payroll Update
An email posing as HR asks employees to update their bank or payroll details through a linked form.
Learn moreCloud Storage Alert
A fake cloud storage or M365 notification claims a document has been shared or your storage quota is full, leading to a fake login page.
Learn moreRun these patterns as real simulations
Claro turns each of these lures into a localized, trackable phishing simulation your team can learn from safely.
Request a demo