Scenario 1
Unexpected Vendor Invoice
A staff member receives this message near the end of the month. What is the strongest phishing indicator?
Past Due Invoice - Immediate Action Required
- From
- Accounts Payable <billing@payables-secure.example>
- To
- accounting@yourcompany.example
- Date
- Today, 8:14 AM
Hello,
Your organization has an overdue invoice. To avoid late fees and account suspension, please download the invoice and submit payment today.
Use the secure payment center below:
Thank you,
Accounts Payable
Correct answer: suspicious HTML invoice attachment and unverified vendor domain.
HTML attachments can open fake login or payment pages. The sender domain does not match a known vendor, the message uses urgency, and there is no purchase order or normal accounting context. Verify invoices through a known vendor contact or your accounting system.