Join our Partner Program | Fuel growth, scale impact, and eliminate cyber-driven payment fraud—together. Register Today
Need to Meet Nacha’s 2026 Requirements? See How
The 5x Surge in Payment Fraud in H1 See the Report
Cyber-driven fraud is the #1 CEO priority, according to World Economic Forum. Read More
Going to Black Hat 2026? | Stop by Booth #5839. Let's Meet Up
TRUSTMI FRAUD INTELLIGENCE ALERT

Ghost Executive Fraud and Deadline Deception Fraud: Two Named Attacks Driving Invoice Fraud in 2026

Forged paperwork, fabricated approvals, and false deadlines are turning fraudulent payments into routine, already-approved ones.

Severity: Critical
Report Period: H1 2026
Status: Active
Fraud Class: Payment
Incidents Analyzed: 597
YOY Change: ~5x

Threat types:

  • Executive Impersonation

  • Business Email Compromise

  • Invoice Fraud

  • Vendor Fraud

  • Document Forgery

Overview

Trustmi analysts observed a fivefold year-over-year rise in payment fraud attempts, from 119 incidents in H1 2025 to 597 in H1 2026. The growth was marked by attackers relying on forged financial documents, fabricated business conversations, and behavioral pressure to make fraudulent payments look routine and already approved.

Fake invoices, W-9s, bank letters and supporting documentation became the common thread across the observed activity. Seven of nine tracked patterns included a fake invoice. The single most common pattern paired a fake invoice with a fabricated email in 193 incidents. The invoice supplied the request, and the thread supplied the history and the approval.

Two named attacks define the shift. Ghost Executive Fraud manufactures executive approval through a fabricate email thread or forged financial documents. Deadline Deception Fraud pairs fake paperwork with a false deadline, often a past due notice, to collapse verification time and force payment.

Neither of these attacks depends on malware or a single technical compromise. They manipulate the payment process itself, using several believable artifacts that reinforce one another across email, vendor records, documents, and payment workflows. Controls that validate only the sender, only the attachment, or only the payment instruction may miss the full attack narrative.

Key Findings

Threat Growth

  • ~5x increase in observed payment fraud
  • 597 intent-driven attacks analyzed
  • Seven of nine attacks include fake invoices

Primary Attack Pattern

  • 193 incidents of Fabricated email thread + Fake invoice

The Two Named Attacks

Ghost Executive Fraud

Most Common Named Campaign: ~255 incidents (more than 4 in 10)

Executive impersonation fraud that manufactures approval. The attacker inserts a fabricated executive thread or forged financial documents so the payment looks like a decision that has already been made.

Most common signals: executive impersonation paired with a fabricated email, and executive impersonation paired with a fake invoice.

Deadline Deception Fraud

Fastest Growing Pattern: ~97 incidents in six months

Fake paperwork paired with a false deadline. A past-due notice or a demand for same-day payment collapses the time a team must verify, so the request clears before anyone checks.

Most common signals: a fake invoice with an overdue-payment pretext.

Supporting Documents Used

  • Fake invoices
  • Fake W-9s
  • Bank letters
  • Fabricated approval chains
  • Spoofed email conversations

Common Attack Chain

The following elements commonly appear together in Ghost Executive and Deadline Deception attacks, but they do not always occur in a strict or linear order. Attackers may introduce, repeat, or combine these tactics at different points in the payment process to reinforce legitimacy and move the request toward payment.

Stage 1

  • Target a finance or AP employee

Stage 2

  • Create or borrow a fraudulent vendor or executive identity

Stage 3

Generate supporting paperwork:

  • Invoice
  • W-9
  • Banking documents

Stage 4

  • Insert executive approval or fabricate an email thread

Stage 5

Apply urgency:

  • Past Due
  • Need today
  • CEO approved

Stage 6

  • Payment initiated

Behavioral Indicators of Fraud

Because these attacks may not contain malware or a conventional technical indicator of compromise, organizations should monitor for behavioral and payment indicators across the workflow. No single indicator confirms fraud; combinations and deviations from established behavior increase risk.

 

Category What to watch
Identity and
communication
Recently registered or look-alike sender domain; unrelated mailbox posing as a known firm; conversation history that cannot be independently verified; executive referenced but absent from the live exchange.
Documents Unexpected invoice; multiple financial documents arriving at once; W-9 supplied alongside a bank change; invoice metadata inconsistent with the claimed creator; signs of editing, splicing, template reuse, or newly created document elements; or, increasingly, documents that appear entirely clean and show no visible signs of manipulation, but become suspicious only when evaluated in the broader context of the payment request, vendor history, approval chain, and banking activity.
Vendor and banking New banking instructions; first-time payment destination; vendor identity not found in approved records; bank details that differ from prior payments; supporting documentation introduced only after a change request.
Behavior and timing Sudden deadline; overdue or final-notice framing; month-end or end of-day pressure; request that discourages normal verification; approval presented as complete before the recipient was involved.

 

Detection Opportunities

  • Flag first-time bank accounts and bank-detail changes, especially alongside a new document or an urgent request.
  • Compare sender domains, reply-to addresses, and mailbox history against known vendor and executive identities.
  • Confirm that an apparent email history exists in your real mail environment, not only inside the forwarded content.
  • Inspect attachments at the file level for inconsistent metadata, fonts, edited fields, and creator information. A document can pass file level inspection and still be fraudulent, so weigh it against vendor history, banking activity, and approval context.
  • Correlate executive approval claims with independent records or known workflows. Calendar activity can support the check, but is not proof on its own.
  • Detect identical or near identical invoice templates reused across unrelated vendors or payment requests.
  • Prioritize requests that combine several signals: a new payee, altered banking details, forged paperwork, executive authority, and time pressure.

Trustmi Protection

Trustmi identifies the attributes behind Ghost Executive Fraud and Deadline Deception Fraud across communications, financial documents, vendor records, and payment activity, correlating signals that look legitimate on their own. The Trustmi team continues to monitor for new document templates, fabricated vendor identities, and past due and same-day urgency pretexts as these attacks evolve.

Recommended Actions

Immediate

  • Pause payments that introduce new banking instructions, a first-time destination, or an unverified vendor.
  • Validate executive approvals through a known channel separate from the request.
  • Verify vendor banking changes using previously established contacts, not details supplied in the change request.
  • Treat callback verification as necessary but not sufficient.
  • Escalate requests that pair urgency with altered payment information or new supporting documents.

Short term

  • Inspect invoice, W-9, and bank letter metadata and content for manipulation.
  • Document a standard out-of band verification procedure for approvals, vendor changes, and overdue demands.
  • Review recent payments for the named patterns.
  • Train finance, procurement, and security teams on behavioral indicators, not only phishing and malware cues.

Long term

  • Move from one time document checks toward ongoing review of payment activity.
  • Look at identity, communications, documents, and payment together, rather than in isolation.
  • Flag activity that departs from a vendor’s or employee’s established pattern for review.
  • Establish shared finance and security ownership, with clear escalation paths and metrics.

Assessment

Treat clean documents and apparent executive approval as claims to verify, not proof that a payment is legitimate. Validate the request end to end, across identity, communications, documents, vendor data, and payment activity. A name, a deadline, and a matching invoice are not authorization.

Ghost Executive and Deadline Deception are the first two named payment fraud attacks from Trustmi.
They will not be the last.

$240 Billion Secured

Protecting businesses globally against socially engineered fraud and errors.

Up to 2.5% of Budget Saved

By Eliminating Fraud and Payment Errors

From Hours to Seconds

Manual Process Time Reduced

$240 Billion Secured

Protecting businesses globally against socially engineered fraud and errors.

Up to 2.5% of Budget Saved

By Eliminating Fraud and Payment Errors

From Hours to Seconds

Manual Process Time Reduced

Eliminate B2B Payment Fraud Today
See It In Action
To top
Trust Center Form

Get Access to Trustmi's Trust Center

Please enter your details


Trust Center Login

Login to access Trustmi's Trust Center