Check an unfamiliar software invoice against trusted accounts, payment records and authorised owners, without paying a duplicate or following a fraudulent link.

Direct answer: Do not approve the invoice from the message alone: compare its supplier, account, service period, reference and amount with trusted purchase and payment records. Ask the authorised account owners, then contact the supplier through an independently verified route if the evidence is incomplete. If money has already gone to a suspected fraudster, contact your bank through its official channel immediately and alert whoever handles security; do not wait for the routine invoice investigation to finish.

An unfamiliar invoice can be a legitimate forgotten renewal, a duplicate request, a reseller's bill or a fraudulent message. Neither an unfamiliar logo nor a familiar sender name proves its status.

My recommendation is to require a record-backed match before approval, even when the amount looks too small to justify an investigation. Keep the check proportionate, but do not use a low amount as a substitute for establishing who is asking, what was bought and whether it has already been paid.

Applies to: small-business software purchasing and invoice checks, with UK reporting context. Contractual, accounting and reporting requirements vary by country, sector and agreement; obtain qualified local advice for a disputed liability or consequential incident.

Use the invoice identity verification

The invoice identity verification is an editorial method for separating a payment request from evidence that payment is due. Follow the request through supplier identity, purchase authority, service delivery and payment status. A match at only one stage is not enough.

Keep the original message and invoice in an approved restricted location according to your records policy. Do not forward it widely or upload it to a public AI tool to ask whether it is fraudulent. It may contain account identifiers, personal details and bank information that are not needed by everyone involved.

The NCSC warns that business payment fraud can involve convincing impersonation, altered payment requests or malicious invoice attachments. It advises contacting your IT contact and bank promptly if a fraudulent payment is suspected, using the bank's official contact route. NCSC guidance on business payment fraud.

For the ordinary investigation, appoint one owner and record the status as unverified, confirmed, duplicate, disputed or referred for incident response. A clear status avoids one colleague paying a reminder while another is still checking the original.

Establish the identity without following the message's route

Use a supplier address or account bookmark already established in your purchase records. If you need to find an official website, verify the domain carefully before signing in; do not use a sponsored result or a link in the questionable invoice as proof of identity.

Compare the legal supplier name, trading name and account identifier with the contract or prior verified invoices. A changed name may have an explanation, but ask the known supplier to confirm it. Do not infer a rebrand or acquisition because the new invoice looks professional.

For changed bank details, make a separate check through an independently verified supplier contact. Report Fraud's mandate-fraud guidance specifically recommends corroborating new-account requests through official, verifiable contact details. A reply within the same email conversation is not an independent check of that request. Report Fraud guidance on payment diversion.

Do not open an unexpected attachment merely to inspect its design, enable macros or install an invoice viewer. Use your organisation's safe handling process or ask the security contact to inspect it. You can often begin with the sender's stated reference and your own records without opening the file.

Match the purchase and the service period

Ask the people authorised to buy or administer the service, not the entire organisation. Give them the minimum information needed: supplier name, amount, account identifier and billed dates. Ask for a purchase record or trusted account confirmation rather than a guess based on recognition.

Check whether the bill covers a new subscription, a renewal, extra usage or a separate workspace. The same supplier and amount can appear on two legitimate invoices for different accounts. Conversely, a new invoice date does not prove a new service period.

Look for the approved order, account owner, accepted price and renewal terms. If these are missing, record an ownership or purchasing-control gap. Do not silently turn a colleague's memory that “we probably used it” into approval of the current demand.

Open the service through the verified account route, using your own authorised access. Compare the invoice there with the received request if the account provides billing records. Do not borrow a former employee's credentials or create a new paid account just to see whether the name is familiar.

Check payment status before paying again

Compare the reference, amount, currency and service period with the purchase ledger and reconciled payment evidence. An entry marked “scheduled” is not the same as a completed payment. A bank debit may also need matching to the correct invoice rather than assuming equal amounts establish the link.

If a payment appears complete but the supplier says it is outstanding, ask the finance owner to provide suitable remittance information through the verified route. Share only what is necessary and approved; a full bank statement may expose unrelated transactions.

Use the evidence to choose the next action:

FindingEvidence still neededAppropriate next action
Forgotten legitimate purchaseApproved account, correct period and unpaid statusReturn to the normal approval process
Duplicate requestSame obligation and matched completed paymentRecord the duplicate and obtain supplier reconciliation
Genuine supplier, disputed amountContract, usage or cancellation evidenceRefer to finance or the contract owner
Suspected impersonation or compromisePreserve existing evidence without risky interactionFollow incident and reporting procedures

Do not cancel the software as an investigative shortcut. It may support another team's work, and cancellation may not resolve an already incurred liability. Establish the facts first, then make a separate decision about whether the service should remain.

Work through a £287 invoice

Suppose a fictional design business receives a £287 software invoice that its finance assistant does not recognise. All figures and findings in this example are illustrative, not a reported incident or a claim about fraud frequency.

The assistant checks three authorised account owners. Two do not recognise it; the third provides the approved account record and identifies the service. That response is a lead, not final proof. The finance assistant opens the supplier's established account route and compares the reference and twelve-month service period.

Assume the records show one genuine £287 obligation and a reconciled £287 payment against it. The new message repeats that same reference and period. If it were paid again, total outflow would become £287 + £287 = £574, although the verified obligation is £287. The duplicate exposure is therefore £574 − £287 = £287.

A mistaken reminder need not be criminal. Obtain confirmation through the verified supplier route and mark the duplicate so another colleague does not process it.

Suppose the work takes eight minutes to preserve and triage the message, seven to check payment records, four minutes from each account owner, ten for supplier confirmation and six to document closure. Total effort is 8 + 7 + 3 × 4 + 10 + 6 = 43 person-minutes. Elapsed time may be longer while waiting for replies.

The £287 is an identified duplicate payment avoided under these assumptions, not new revenue or an estimate of annual savings. The 43 minutes remain a real administrative cost. Better purchase records can reduce that work next time, but a single example does not establish how much they will save.

Preserve the result and fix the ownership gap

Record the verified supplier, account owner, service period, payment status, evidence references and closure decision. Keep the evidence in your normal restricted financial records, not in a public team chat. Use the applicable retention policy and do not destroy material needed for a dispute or incident.

If the purchase is legitimate but poorly documented, add the missing owner and renewal information to the existing software register. That is a useful input to the small-team technology retrospective, which can address why the service became invisible.

Treat an unexplained charge and an account-security warning as different problems that may coexist. Unexpected account changes, unauthorised purchases or information entered into a suspicious site warrant the security response, even if the supplier itself is genuine.

Do not promise a refund or successful recovery. The bank, provider and relevant authorities will need the facts, and available remedies depend on the circumstances and applicable rules.

Start the check now and set a decision point

  1. In the first five minutes, stop unverified approval, preserve the message safely and assign an investigation owner. Escalate a suspected fraudulent payment immediately.
  2. During the next working session, compare trusted purchase and payment records and ask the authorised account owners.
  3. Contact the supplier through a verified route for unresolved identity, amount or payment questions. Record any genuine deadline and ask the contract owner how to handle it.
  4. Close only when the evidence supports payment, duplication, a dispute or incident referral. If it remains unresolved after one working day, escalate rather than leaving an unexplained bill in a queue.

The one-day escalation point is an editorial working rule, not a legal deadline. An active compromise, payment already sent or imminent contractual consequence requires faster action.

Frequently asked questions

What if the card statement uses a different company name?

Treat the difference as something to reconcile, not automatic proof of fraud. Compare the transaction date, amount and account records, then ask the known provider through its verified support route to explain the billing name. A payment processor or seller arrangement may account for the difference, but do not assume one without evidence. If you cannot connect the charge to an authorised purchase, ask your finance owner and bank about the appropriate investigation process. Avoid entering card details into a website found only by searching the unfamiliar statement text; that would create a new exposure while investigating the original one.

What if the person who bought the software has left?

Use the organisation's existing purchase records and authorised account-recovery or administrator process. Do not sign in as the former colleague, request their personal password or assume their private email belongs to the business. Check who now owns the contract and whether the supplier can verify the organisation through its documented procedure. Missing ownership may take longer to resolve than a normal invoice query, so involve the finance or business owner early. The immediate aim is to establish the obligation and payment status; deciding whether to retain the software can follow once access and responsibility are clear.

Should I send a small payment to check that the account is genuine?

Not as the first step in verifying an unfamiliar invoice. A payment reaching an account does not establish that the account belongs to the intended supplier or that the invoice is due. Confirm identity, payment details and the obligation through trusted records and an independent contact first. Any subsequent payment test should follow your finance process and the bank's advice, with confirmation from the already verified recipient. Do not let a sender's offer of a small “verification charge” bypass the investigation. The amount being small changes the exposure, not the quality of the evidence.

What if the invoice threatens to suspend an essential service today?

Check the claim inside the service through your established account route and involve the person responsible for that service immediately. Urgency may reflect a genuine billing problem, but it is not evidence that the message's payment instructions are safe. Preserve the stated deadline and ask the verified supplier about the account status while the finance owner checks the obligation. Prepare an authorised continuity option if interruption is plausible. Do not ignore a genuine contractual issue, but do not grant a suspicious message payment authority merely because it says the team's work will stop within hours.

What should we do if someone has already entered login details through the invoice link?

Treat that as a possible account-security incident rather than waiting for the invoice to be classified. Tell the person responsible for security promptly, preserve the message and use the provider's official recovery guidance through an independently verified route. Explain what was entered and when, without copying the password into a report or team chat. If payment information or money was also involved, contact the bank through its official channel. The appropriate recovery steps depend on the account and exposure; do not assume deleting the email or changing one password resolves every connected session or permission.

If the invoice is genuine, should we automatically renew the service?

No. Establishing that a bill is genuine answers an identity question, not whether renewal is the right business decision. Check the agreement, current obligation and cancellation conditions with the contract owner before changing anything. Separately assess who still uses the service, what data or workflows depend on it and how leaving would work. A forgotten tool may be unnecessary, or it may quietly support an essential process. Avoid both automatic renewal and immediate cancellation based only on familiarity. Use the verified account information to make a documented keep, change or leave decision through the normal purchasing process.

Sources and verification

  • National Cyber Security Centre: business payment fraud, checked 11 September 2026 for impersonation, malicious invoice risks and prompt contact with security and the bank through official routes.
  • Report Fraud: mandate fraud, checked 11 September 2026 for independently verifying changed payment details and the response to a payment already made. This is UK reporting guidance, not a promise of reimbursement.
Twokq Tech

This article is practical guidance. Apply it in proportion to your tools, evidence, risks, and responsibilities.