
Freight invoice fraud is now the dominant threat in logistics billing: half of classified freight fraud is communication-based — fake invoices, compromised inboxes, payment-change requests. In June 2026, a fake FedEx Freight rebill passed DKIM and DMARC because it rode FedEx’s real Salesforce CRM. Only out-of-band payment verification reliably stops it.
Why is freight invoice fraud surging right now?
The attack surface moved from the truck to the inbox. Highway’s Q2 2026 Freight Fraud Index found that communication-based attacks — fake invoices, spoofed emails, and payment-change requests — now make up half (50%) of all classified fraud vectors, up from 42.7% in Q1. In a single quarter the platform blocked 784,201 fraudulent inbound emails (a 48.5% jump quarter over quarter) and 109,995 fraudulent or spoofed calls (up 53.2%).
The federal numbers explain why criminals are pouring in. The FBI’s IC3 issued a public service announcement on April 30, 2026 warning of cyber-enabled cargo theft, and reported 2025 cargo-theft losses of roughly $725 million — up about 60% year over year, averaging near $273,990 per incident. Zoom out to all business email compromise and the 2025 IC3 report counted $3.04 billion in BEC losses across 24,768 complaints (about $123,000 average), with 86% of the money moving by wire or ACH. That spike in spoofed calls is the same social-engineering wave hitting other channels — we covered the voice side in Microsoft Teams vishing and ransomware.
How does the fake-invoice and payment-change play actually work?
Freight invoice fraud is not one trick — it is three variations on the same goal: get your accounts-payable team to send a real payment to an account the fraudster controls. They usually appear in this order of sophistication.
- The fake invoice. A convincing bill for freight, a rebill, or an accessorial charge lands from a name your team recognizes. If the amount looks routine and the sender looks familiar, it gets scheduled.
- The bill-to or bank-change request. The invoice is real, but a follow-up asks you to update the remittance details — a new bank, a new bill-to entity, a new remit-to address. This is the highest-yield version, because it redirects payments you were always going to make.
- The compromised real thread. The attacker is inside a legitimate mailbox — yours, the vendor’s, or a broker’s — and simply replies in an existing conversation. There is nothing to spoof, because the email genuinely comes from the real account.
Every version ends the same way: money leaves on the fraudster’s banking details, and because 86% of BEC losses move by wire or ACH, it clears before anyone notices. The request itself is the weapon — not a virus, not an attachment.
Why didn’t DMARC stop it?
This is the part that unsettles security teams. On June 12, 2026, the email-security vendor Ironscales documented a rebill request that asked to change the bill-to on FedEx Freight invoice #0584162950. The message was sent through FedEx Freight’s own Salesforce CRM, so it carried a valid DKIM signature for fedexfreight.com and passed DMARC with compauth=100. There were no links and no attachments — the fraudulent request in the body was the entire payload.
Here is the uncomfortable truth every AP team needs to internalize: email authentication proves the sending infrastructure, not the sender’s intent. DKIM, SPF, and DMARC confirm that a message really traveled through a domain’s authorized systems. When an attacker abuses a legitimate CRM, marketing platform, or relay — or simply logs into a real mailbox — the message is authentically from that infrastructure. It passes every check and still carries a lie. Authentication was never designed to judge whether the human request is honest, and no green checkmark ever will.
The five controls that actually stop payment-change fraud
Because the fraud passes technical filters, the controls that work sit at the process and identity layer, not the spam filter. These five, layered together, close the gap. The table after them shows what each one stops and who owns it.
1. Out-of-band bank-change verification
The single highest-value control, and the FBI’s number-one listed mitigation: before you change any bank or remit-to detail, verify it by calling the vendor back on a known-good number from your vendor master — never a number, link, or contact in the email requesting the change. A thirty-second phone call defeats the entire play, because the fraudster does not answer the vendor’s real line.
2. A payment-change approval workflow with dual sign-off
No single person should be able to change vendor banking details and release a payment on their own. Require a second approver for any change to remittance data above a set threshold. Dual control means one tricked employee is not one payment away from a loss.
3. Impersonation-protection and behavioral email tooling
Standard authentication passes these messages, so you need tooling that scores behavior and intent: look-alike display names, first-time senders asking for money, unusual reply-to addresses, and language patterns typical of payment-redirect fraud. This is a layer we configure and monitor as part of security administration — it flags the message DMARC waved through.
4. MFA and conditional access on finance mailboxes
The compromised-thread version depends on someone owning a real inbox. Lock the finance and AP mailboxes hardest: enforced multifactor authentication plus conditional access that blocks logins from unexpected locations and risky sign-ins. On Microsoft 365 this is exactly what our managed Microsoft 365 services harden by default, so an AP inbox cannot quietly become the fraudster’s sending platform.
5. Vendor-master hygiene
Your vendor master is the source of truth the callback depends on. Keep it clean: restrict who can edit banking details, log every change, and periodically re-verify the records so a silent edit cannot slip through unnoticed. A control is only as trustworthy as the data behind it.
| Control | What it stops | Who owns it |
|---|---|---|
| Out-of-band bank-change verification | Payments redirected to a fraudster’s account on a spoofed change request. | Finance / AP |
| Payment-change approval workflow (dual sign-off) | A single tricked employee moving money alone. | Finance / AP |
| Impersonation-protection & behavioral email tooling | Look-alike senders and anomalous thread behavior that pass DMARC. | IT / MSP |
| MFA + conditional access on finance mailboxes | Account takeover of the inbox the fraud rides on. | IT / MSP |
| Vendor-master hygiene | Silent edits to vendor bank details behind everyone’s back. | Finance + IT (shared) |
What are the red flags an AP team should treat as stop signs?
Train the people who touch payments to pause on these signals. Any one of them should trigger the out-of-band callback before a dollar moves — even when the email passed every technical check.
- Any change to bank, remit-to, or bill-to details — the single biggest one. Treat every banking-change request as unverified until a callback confirms it.
- Urgency or secrecy — pressure to pay today, or to keep the change quiet, is a manipulation tactic, not a business norm.
- A reply that subtly changes the reply-to address or arrives from a look-alike domain one character off.
- A new invoice, rebill, or accessorial charge that does not match a shipment or contract you can find.
- A phone number supplied in the email for you to call to confirm — always verify against your own records instead.
What your IT provider owns vs. what stays with finance
Here is where we draw the line honestly, because a lot of this is not an IT problem you can buy your way out of. As your MSP, QOS MSP owns the technology and identity controls: impersonation-protection and behavioral email tooling, enforced MFA and conditional access, mailbox monitoring, and hardening the systems around AP. We can make the fraudulent message far more likely to be flagged and far harder to send from a real account.
What stays with finance is the process discipline: the callback rule, dual sign-off, and the vendor-master procedures. No product can decide for your AP clerk whether a bank-change request is legitimate — that judgment, and the callback that backs it, is a human control your team owns. And to be candid about when not to buy tooling: a disciplined two-person AP team with a strict, no-exceptions callback rule may not need new email tooling yet. If the process is airtight, add the tooling when volume or headcount grows — not before.
One boundary we will not blur: if money has already left, that is a banking and law-enforcement matter, not an IT ticket. Contact your bank immediately to attempt a recall or SWIFT/ACH reversal, and file a report with the FBI at ic3.gov — the first 24 to 72 hours are when recovery is still possible. We help you harden everything around the payment; we are not your bank, your insurer, or your attorney, and we will tell you plainly when the next call needs to be to one of them.
Frequently asked questions
What is business email compromise (BEC)?
Business email compromise is a fraud in which an attacker uses email, often from a spoofed or genuinely compromised account, to trick an employee into sending money or changing payment details. It relies on deception rather than malware. The FBI IC3 reported 3.04 billion dollars in BEC losses across 24,768 complaints in 2025, averaging about 123,000 dollars per incident.
How can a fraudulent invoice pass DKIM and DMARC?
Email authentication like DKIM and DMARC verifies the sending infrastructure, not the sender’s intent. When a fraudster sends the message through a legitimate provider, such as a vendor’s real CRM or email relay, or logs into a genuine mailbox, the email is authentically from that system and passes every check. In June 2026 a fake FedEx Freight rebill passed DMARC because it was sent through FedEx’s own Salesforce CRM.
What is out-of-band verification for a payment change?
Out-of-band verification means confirming any bank or remit-to change through a separate channel from the request. Before updating vendor banking details, call the vendor back on a known-good number from your vendor master, never a number or link in the email itself. It is the FBI’s first-listed mitigation and defeats the fraud because the criminal does not answer the vendor’s real phone line.
Can you recover money sent to a fraudster?
Sometimes, but only if you act fast. Contact your bank immediately to attempt a wire recall or ACH reversal, and file a report with the FBI at ic3.gov as soon as possible. Because 86 percent of BEC losses move by wire or ACH, the funds often clear within hours, so the first day matters most for any chance of recovery.
Does cyber insurance cover invoice fraud?
Often, but usually under a specific social-engineering or funds-transfer fraud rider rather than the base policy, and those riders frequently carry lower sublimits. Insurers also increasingly require controls like multifactor authentication, dual approval on payment changes, and callback verification before they will pay a claim, so funding these controls both prevents the loss and protects your coverage.
Our take
Freight invoice fraud won the technical arms race — the FedEx case proves a message can pass DKIM, DMARC, and compauth and still be a lie. So stop trying to filter your way out of it. Layer the identity and email controls we own with the callback discipline finance owns, and the fraud has nowhere left to land. Funding these controls also pays off at renewal: they are increasingly what your cyber-insurance policy requires before it will cover a funds-transfer loss.
Want a second set of eyes on how your AP mailboxes and email security are configured? Talk to us — we will tell you honestly which of the five controls you already have and which one is the gap a fraudster is counting on.