Clone Websites Trick Firms Into Paying Fake Invoices

The Hacker News · Medium sophistication
Last updated July 30, 2026

Researchers described a long-running fraud campaign where criminals clone real Russian company websites and replace contact and bank details to intercept international business deals. Victims are lured through cold calls, phishing emails, and fake supplier websites, then sent realistic contracts and invoices that route “advance payments” to attacker-controlled accounts.

How the attack worked

This campaign relies on cloned websites that copy the look, content, and branding of real companies engaged in international trade. The only changes are to contact details and bank account information, which are altered to route communications and payments to the attackers instead of the legitimate supplier. Victims are drawn in through cold calls, phishing emails, and these fraudulent corporate websites, then guided through what looks like a normal sales process: a commercial offer, a contract, and finally an invoice requesting an advance payment for goods that do not exist.

In some cases, hired sales representatives make the initial cold call and then hand the deal off to a supposed senior manager once negotiations near the payment stage. From that point on, all communication is with the fraudsters, who supply convincing documentation, including offers and contracts on what appears to be official letterhead, with only the payment details swapped out.

Why it succeeded

The scheme works because the documentation looks complete and authentic. Attackers prepare a full set of business paperwork designed to build confidence and mirror a genuine transaction. Because the cloned website and communications closely resemble the real supplier, victims have little reason to suspect anything is wrong until the payment has already gone to a fraudulent account. The reliance on an advance payment model for international goods purchases also creates a natural point where money moves before the buyer ever receives a product to inspect.

What to watch for

  • A website that resembles a known supplier but uses a slightly different or lookalike domain name
  • Contact details in an email or on a website that differ from previously known legitimate information
  • An unexpected cold call that quickly escalates toward a contract and payment request
  • A handoff mid-negotiation to a new contact, such as a "senior manager," right before payment terms are finalized
  • Invoices or contracts referencing bank details for a "subsidiary" that cannot be independently confirmed

How to build resistance

  • Independently verify supplier contact details and bank account information through a trusted, previously established channel, not the one provided in a new email or website
  • Treat complete-looking documentation, such as offers, contracts, and invoices on official letterhead, as something to verify rather than accept at face value
  • Apply extra scrutiny to any advance payment request tied to international purchases, especially when the relationship began through a cold call or unsolicited email
  • Train procurement, finance, and sales-facing staff to recognize these red flags, since these teams are the primary targets of this type of fraud

Key findings

  • Attackers created “clone websites of Russian companies” and used lookalike domains to impersonate real suppliers.
  • Targets were international B2B customers, approached via “cold calls, phishing email campaigns, and fraudulent corporate websites.”
  • Fraudsters sent “commercial offers, contracts, and invoices with bogus bank details,” tricking victims into advance payments for non-existent goods.
  • At least one victim (an Azerbaijani company) reportedly lost $150,000 in April 2025.
  • Investigators found nearly 100 counterfeit domains and identified infrastructure tied to IPs 212.127.73[.]235 and 167.86.100[.]68.

Who’s being targeted

  • Commonly targeted roles: Procurement, Finance/Accounts Payable, Supply Chain, Sales (vendor-facing), Executive leadership (approval of large transfers).
  • Affected industries: International trade (B2B), Fertilizer manufacturing, Petrochemicals, Metallurgy, Logistics and transportation, Banking.
  • Attack channels: website, email, vishing.
  • Impersonated: A legitimate Russian supplier (using a cloned website and “subsidiary” bank details), Sales representative for a legitimate supplier; later a “senior manager” at the company, A legitimate Russian company (brandjacked via a cloned domain and copied website content).

Red flags to watch for

  • Website is a lookalike copy and contact details are altered to reach the attackers
  • Invoice/contract contains bank details for a “subsidiary” that are not independently verifiable
  • Pressure to make an advance payment for goods
  • Unexpected cold call initiating a supplier relationship
  • Caller pushes to move to a different contact (“senior manager”) near the payment stage
  • Payment instructions provided by phone/email rather than verified via trusted channels
  • Email drives you to a domain that is similar but not identical to the known supplier domain
  • Website language/branding looks correct but WHOIS/registration date is recent or suspicious
  • Contact emails/phone numbers differ from previously known legitimate details
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How do cloned supplier websites lead to fraudulent payments?

Attackers copy content from a legitimate company's website onto a lookalike domain, altering only the contact details and bank account information so victims unknowingly send advance payments to the fraudsters.

What roles are most at risk from this fake invoice scheme?

Procurement, finance and accounts payable, supply chain, and sales staff who handle vendor communications and payment approvals are the primary targets.

How can a company verify a supplier invoice is legitimate?

Independently confirm contact details and bank account information through a trusted, out-of-band channel rather than relying on the details listed in the email or website that initiated contact.

Why do cold calls play a role in this fraud?

Some campaigns use sales representatives to cold-call potential customers and then hand the negotiation off to a supposed senior manager right before payment, adding a layer of social pressure and legitimacy.

Read the video transcript

You get a great offer from a Russian supplier, contract attached, invoice ready. Looks legit, right? Behind that email is a cloned website of a real Russian company, same logo, same text, but a lookalike domain and swapped contact and bank details sending money to someone else. They cold-call, send phishing emails, then hit you with polished offers, contracts, and invoices on letterhead. One company in Azerbaijan wired $150,000 in an 'advance payment' straight to bogus subsidiary bank details. Aha moment: if the website or caller gives you bank details, don’t trust them. Before any advance payment, independently confirm the account using a phone number or contact you already know.

Similar attacks

How Attackers Bypass MFA in the Real World

How Attackers Bypass MFA in the Real World

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…

July 29, 2026