Fake invoices to small businesses: the toner you never ordered, the directory that doesn't exist
Phony invoices for office supplies, bogus business-directory listings, fake domain renewal notices, look-alike trademark fee demands — all engineered so the person who pays the bills just pays. Here's each variant, the FTC rule that says you can keep unordered merchandise for free, and the one process change that stops all of them.
The invoice doesn’t look like a scam. It looks like Tuesday. A bill for toner cartridges, an “annual listing renewal” for a business directory, a domain expiration notice, a trademark fee with an official-looking seal — modest amounts, professional layout, a due date. It lands in front of the person whose job is to pay bills quickly, at a company small enough that the same person receives, approves, and pays. That’s the entire design of the small-business fake invoice scam: no hacking, no malware, just paperwork engineered to ride your own accounts-payable routine straight to payment.
Here’s the first move, before the variants: no invoice gets paid unless someone can match it to an order you actually placed or a vendor you actually use. Every real bill survives that check. None of these do.
The con targets your process, not your judgment
The FTC’s small-business guide describes the mechanism plainly: “Scammers create phony invoices that look like you ordered products or services for your business. They hope the person who pays your bills will assume the invoices are real and make the payment.” Note what’s being exploited — not gullibility, but efficiency. Paying invoices promptly is a virtue in a bookkeeper, and the amounts are deliberately small enough to sit below anyone’s mental alarm threshold. This is a different animal from business email compromise, where criminals hijack a real supplier’s email mid-conversation to redirect a payment you genuinely owe. Here there is no relationship at all: a stranger invents one and bills you for it. BEC forges the “where to pay”; the fake invoice forges the “whether you owe.” Both die to the same habit — verifying outside the message — but they enter through different doors, and a business needs to recognize both.
The toner trick: unordered supplies
The oldest version starts with a phone call, not a package. Per the FTC, “a scammer might call, claiming they want to ‘confirm’ an existing order, ‘verify’ an address, or offer a ‘free’ catalog or sample. If you say yes to any of those, unordered merchandise will arrive at your doorstep — followed by high-pressure demands to pay for it.” The shipment is the trap’s second jaw: once boxes are physically in your storeroom, paying feels more natural than arguing.
The law is entirely on your side, and the FTC states it without hedging: “if you receive merchandise you didn’t order, you have a legal right to keep it and use it for free.” Don’t pay, and don’t ship it back at your own expense. The follow-up calls may quote details from that first conversation — that’s the point of the call — but a recorded “yes, that’s our address” is not an order.
The phantom directory listing
The second variant sells nothing at all. “Scammers try to fool you into paying for nonexistent advertising or a listing in a phony business directory,” the FTC warns, and the setup mirrors the toner call: a request for your contact details for a “free” listing, or a call “simply to ‘confirm’ your information.” Then the bill arrives — and, in the FTC’s words, “the scammer may use details — or even a recording — of the earlier call to pressure you to pay.” Some crews add a collections voice, threatening your business credit. A directory you’ve never heard of, billing for a listing no one authorized, is not a debt. It’s a script.
The domain renewal that isn’t
Every business with a website gets these: an urgent notice that your domain is about to expire, sometimes dressed in the branding of ICANN, the organization that coordinates the domain name system. ICANN’s own guidance dismantles this one cleanly. “Phishing emails may claim that your domain name registration needs to be renewed and that you must pay some sort of fee to get it back,” it warns — but ICANN “will never send registrants a WHOIS Data Reminder Policy (WDRP) notice, registration data verification request, domain name expiration reminder, or domain name renewal request message,” and it never collects fees from registrants directly. Your renewal relationship exists with exactly one party: the registrar you pay. So whatever the costume — email or paper letter, ICANN logo or generic “Domain Services” letterhead — the check is the same: log in to your registrar account yourself, and if a notice claims to be from ICANN, ask your registrar whether it’s genuine. The FTC’s business guide flags the aggressive version too: scammers “calling from a tech company, threatening that your business will lose its website URL if you don’t pay immediately.” The consumer-side version of this bill — fake antivirus and subscription renewals — runs on the identical reflex; see the fake subscription renewal invoice.
The official-looking trademark fee
If you’ve registered a trademark, your name and deadlines sit in a public database — and an entire cottage industry mines it. The USPTO warns that solicitation notices “frequently appear to be an invoice and typically specify fees ‘due’ that are higher than the official USPTO required fees,” sent by companies with names built from words like “United States,” “Trademark,” “Office,” or “Agency.” The fine print admitting the sender isn’t a federal agency is usually there — in the smallest type on the page. The FTC lists the harder-edged version among its impersonation scams: letters warning you’ll lose your trademark if you don’t pay a fee immediately. The USPTO gives you two clean checks: real USPTO email ends in @uspto.gov, and official communications — including anything requesting payment — are uploaded to your file in the TSDR database. Not in TSDR, not official. Maintenance fees are paid directly to the USPTO, no middleman required.
The fix is a rule, not a sharper eye
These four scams share one weakness: none of them can survive a match against your own records. So take the decision away from instinct and give it to process — this is Two-Channel Verification applied to accounts payable. The FTC’s guidance for businesses is to “make sure procedures are clear for approving purchases and invoices and ask your staff to check all invoices closely.” In practice: keep a list of vendors you actually use, match every invoice to an order or that list before payment, and verify anything unmatched through a channel you find yourself — never the phone number printed on the suspicious invoice. Payment method is a tell of its own; the FTC is blunt that a demand for wire transfer, cryptocurrency, or gift cards means a scam. For the rest of the small-business threat landscape — payroll diversion, CEO fraud, phishing — see the owner’s playbook.
If you already paid
Dispute a card charge with your issuer, ask your bank about recalling a transfer or stopping a check, and work through getting your money back by payment method. Report to the FTC at ReportFraud.ftc.gov and your state attorney general; forward trademark solicitations to TMScams@uspto.gov. Then close the gap that let it through, because paying once puts you on a list of businesses that pay.
Train the eye that opens the mail: run your team through the 60-second quiz, and keep the full set of defense moves where accounts payable can see it.
- An invoice arrives for supplies, advertising, or a listing that no one can match to a purchase order or a vendor you actually use — priced low enough that paying feels easier than questioning it.
- A caller wants to "confirm an existing order," "verify your address," or send a "free" sample — the FTC warns these calls set up unordered merchandise deliveries and recorded-consent pressure later.
- A renewal or fee notice for your domain or trademark comes from an official-sounding company you've never dealt with, with fine print admitting it isn't a government agency or your registrar.
- Make the rule mechanical: no invoice gets paid unless it matches a purchase order or a vendor on your known list — and any new or unmatched biller is verified on a channel you find yourself, never a phone number or link on the invoice itself.
- Route domain notices to one answer: log in to your registrar account directly. ICANN never sends registrants expiration reminders or renewal requests, so a "renewal notice" from anyone but your own registrar is a solicitation or a scam.
- For trademark mail, check the source before the deadline: official USPTO communications are uploaded to TSDR, real USPTO email ends in @uspto.gov, and maintenance fees are paid directly to the USPTO — not to a "Trademark Office" with a lookalike name.
- If merchandise you never ordered shows up, don't pay and don't ship it back at your expense — the FTC says you have a legal right to keep it and use it for free. And per the FTC, anyone demanding payment by wire transfer, cryptocurrency, or gift cards is running a scam.
What strikes me about this scam family is that the price is the camouflage. A $95 'directory listing' costs less than the twenty minutes it would take a busy bookkeeper to investigate it, and the scammers know that math better than their victims do. That's why I think the fix has to be mechanical — a no-match, no-pay rule — because any defense that relies on someone deciding an invoice looks suspicious will lose to an invoice designed to be beneath suspicion.
Sources
Frequently asked
A company sent us toner we never ordered, and now they're calling with an invoice — they even have a recording of us saying "yes." Do we owe them anything?
No. The FTC's small-business guidance is direct: "if you receive merchandise you didn't order, you have a legal right to keep it and use it for free." The recording trick is part of the same documented playbook — a caller asks you to "confirm" an order or "verify" an address, then uses your answer as fake proof of consent. The FTC describes scammers using details, or even a recording, of that earlier call to pressure you to pay. Don't pay, don't return the goods at your own cost, and report the demand to ReportFraud.ftc.gov.
I got an email saying our domain is about to expire and we'll lose our website unless we renew today. How do I know if it's real?
Ignore the email's links entirely and log in to your registrar account directly — the company you actually pay for the domain. That one move resolves every case, because only your registrar bills you. ICANN, the organization that oversees the domain system, says it "will never send registrants a WHOIS Data Reminder Policy (WDRP) notice, registration data verification request, domain name expiration reminder, or domain name renewal request message," and that it never requests fees from registrants — yet scammers routinely borrow ICANN's name and logo for fake renewal emails. If your registrar dashboard shows nothing due, you have your answer. If a notice claims to come from ICANN, ICANN's advice is to contact your sponsoring registrar directly to check it.
Our bookkeeper already paid one of these invoices. What can we do?
Move on the payment first: if it went on a credit card, dispute it with your issuer now; if by check or transfer, call your bank about stopping or recalling it. Our guide to [getting your money back by payment method](/get-your-money-back-by-payment-method) covers each rail. Then report — to the FTC at ReportFraud.ftc.gov and your state attorney general, plus TMScams@uspto.gov for trademark solicitations. Finally, treat it as a process gap, not a person's mistake: add the vendor-match rule so the next fake invoice has no path to payment. And expect follow-ups — a business that paid once gets marked as a payer.