Forged paperwork, fabricated approvals, and false deadlines are turning fraudulent payments into routine, already-approved ones.
Trustmi analysts observed a fivefold year-over-year rise in payment fraud attempts, from 119 incidents in H1 2025 to 597 in H1 2026. The growth was marked by attackers relying on forged financial documents, fabricated business conversations, and behavioral pressure to make fraudulent payments look routine and already approved.
Fake invoices, W-9s, bank letters and supporting documentation became the common thread across the observed activity. Seven of nine tracked patterns included a fake invoice. The single most common pattern paired a fake invoice with a fabricated email in 193 incidents. The invoice supplied the request, and the thread supplied the history and the approval.
Two named attacks define the shift. Ghost Executive Fraud manufactures executive approval through a fabricate email thread or forged financial documents. Deadline Deception Fraud pairs fake paperwork with a false deadline, often a past due notice, to collapse verification time and force payment.
Neither of these attacks depends on malware or a single technical compromise. They manipulate the payment process itself, using several believable artifacts that reinforce one another across email, vendor records, documents, and payment workflows. Controls that validate only the sender, only the attachment, or only the payment instruction may miss the full attack narrative.
Threat Growth
Primary Attack Pattern
Most Common Named Campaign: ~255 incidents (more than 4 in 10)
Executive impersonation fraud that manufactures approval. The attacker inserts a fabricated executive thread or forged financial documents so the payment looks like a decision that has already been made.
Most common signals: executive impersonation paired with a fabricated email, and executive impersonation paired with a fake invoice.
Fastest Growing Pattern: ~97 incidents in six months
Fake paperwork paired with a false deadline. A past-due notice or a demand for same-day payment collapses the time a team must verify, so the request clears before anyone checks.
Most common signals: a fake invoice with an overdue-payment pretext.
Supporting Documents Used
The following elements commonly appear together in Ghost Executive and Deadline Deception attacks, but they do not always occur in a strict or linear order. Attackers may introduce, repeat, or combine these tactics at different points in the payment process to reinforce legitimacy and move the request toward payment.
Generate supporting paperwork:
Apply urgency:
Because these attacks may not contain malware or a conventional technical indicator of compromise, organizations should monitor for behavioral and payment indicators across the workflow. No single indicator confirms fraud; combinations and deviations from established behavior increase risk.
| Category | What to watch |
|---|---|
| Identity and communication |
Recently registered or look-alike sender domain; unrelated mailbox posing as a known firm; conversation history that cannot be independently verified; executive referenced but absent from the live exchange. |
| Documents | Unexpected invoice; multiple financial documents arriving at once; W-9 supplied alongside a bank change; invoice metadata inconsistent with the claimed creator; signs of editing, splicing, template reuse, or newly created document elements; or, increasingly, documents that appear entirely clean and show no visible signs of manipulation, but become suspicious only when evaluated in the broader context of the payment request, vendor history, approval chain, and banking activity. |
| Vendor and banking | New banking instructions; first-time payment destination; vendor identity not found in approved records; bank details that differ from prior payments; supporting documentation introduced only after a change request. |
| Behavior and timing | Sudden deadline; overdue or final-notice framing; month-end or end of-day pressure; request that discourages normal verification; approval presented as complete before the recipient was involved. |
Trustmi identifies the attributes behind Ghost Executive Fraud and Deadline Deception Fraud across communications, financial documents, vendor records, and payment activity, correlating signals that look legitimate on their own. The Trustmi team continues to monitor for new document templates, fabricated vendor identities, and past due and same-day urgency pretexts as these attacks evolve.
Treat clean documents and apparent executive approval as claims to verify, not proof that a payment is legitimate. Validate the request end to end, across identity, communications, documents, vendor data, and payment activity. A name, a deadline, and a matching invoice are not authorization.
Protecting businesses globally against socially engineered fraud and errors.
By Eliminating Fraud and Payment Errors
Manual Process Time Reduced