Quickbooky

Accounting News

QuickBooks

QuickBooks Email Invoice Fraud Targets Small Businesses

Fraudsters are spoofing QuickBooks payment emails to trick businesses into approving fraudulent transfers. Learn how these scams work and how to protect your company.

NEWSQUICKBOOKY

When reports surface of businesses losing tens of thousands of dollars to fraud linked to a familiar accounting tool, it is rarely the software itself that has been breached. Instead, criminals are exploiting how businesses use email and electronic payments — and QuickBooks is a common cover because it is so widely trusted.

Law enforcement agencies, including police in Dillon, Montana, have recently warned local businesses about schemes tied to QuickBooks-branded communications that resulted in significant financial losses. Here is what is typically happening and how to keep your business protected.

How the Scam Works

These fraud campaigns usually rely on deception rather than hacking. A common tactic is sending a fake email that appears to come from Intuit or the QuickBooks platform. The email might claim that an invoice has been paid, that a payment is pending, or that account verification is required.

Because the message looks legitimate and carries a recognizable brand, an employee may click a link, log in to a spoofed portal, or approve a transaction. In some variations, criminals compromise a business email account and intercept actual invoices — altering the bank routing or payment details before the invoice reaches the customer.

Practical Steps to Protect Your Business

  • Verify payment changes independently. If a vendor or customer emails you new banking instructions, call them at a known, verified phone number. Never use the phone number printed inside an email.
  • Scrutinize invoice links. Before clicking a “pay now” or “view invoice” link, hover over it to check the destination URL. Look for subtle misspellings in the web address.
  • Train your team. Make sure anyone handling accounts payable or receivable knows that legitimate payment platforms will not ask for sensitive credentials via email.
  • Enable multi-factor authentication. Require it on your QuickBooks account and your business email to block unauthorized access even if a password is stolen.

What to Do If You Are Targeted

If your business receives a suspicious QuickBooks-related email, do not click any links or open attachments. Contact your bank immediately if you believe a payment was sent to a fraudulent account — the sooner the transfer is reported, the better the chances of recovery. For broader guidance on navigating QuickBooks securely and troubleshooting account access, our team at qbo.support provides resources for QuickBooks Online users.

The most effective defense is a simple, consistent policy: treat every payment instruction as unverified until you confirm it through a separate, trusted channel.

← Back to News