Recently, our company email has received several suspicious messages involving supposed invoices, payment receipts and tax-related notifications.
One claimed that an invoice was due for payment. Another went further:
“Your payment has been received successfully.”
The problem? We never made or authorised such a payment.
A payment requires initiation and separate authorisation. Therefore, a message claiming “payment received successfully” immediately raises a red flag when no such transaction was authorised.
Similar tactics are also used in tax scams. Messages may impersonate tax authorities or claim there are outstanding taxes, penalties, refunds, e-Invoice issues or urgent actions required. The objective is often the same: create urgency so that the recipient clicks a link, opens an attachment, provides credentials or makes a payment.
A professional-looking email containing your company name, invoice number, amount, tax reference or payment date does not automatically make it genuine. Some of this information may be obtained from websites, social media or other public sources.
For businesses, basic controls remain important: verify the sender independently, examine the actual email domain, match invoices against POs/contracts/supporting documents, and confirm that the goods or services were actually ordered or received.
For tax matters, verify directly through the relevant official government portal or authority, rather than using links or contact details contained in an unsolicited email.
Cybersecurity isn't only about firewalls and antivirus. Internal controls, segregation of duties, staff awareness and human verification remain important lines of defence.
Don't click first and investigate later. VERIFY FIRST.