Fake invoices and shell invoice mills: the fiscal phishing that contaminates the company
The invoice PDF that carries malware and the cold invoices used to validate fictitious transactions.
Audience: Companies and Operations · Risk level: ATTENTION
Blindfy Intelligence Unit · Technical review by Blindfy
Scenario
Accounts payable receives an email with an invoice PDF from a "regular" supplier. Nothing seems off when it opens — but the PDF carried a malicious macro that installed an infostealer. In parallel, finance discovers that other invoices received were issued by an invoice mill with no real operations, used to inflate expenses and validate fictitious transactions.
How the scam works
Criminals use two vectors: (1) invoice PDFs with an embedded payload that activates on opening; (2) cold invoices issued by shell CNPJs, received by accountants or finance teams as if they were real operations. Both contaminate the company: the first technically, the second fiscally and in the books.
Common mistake
Treating an invoice PDF as a neutral document. Attachments with a fiscal appearance are among the most exploited vectors in Brazilian SMBs.
Impact
Compromised finance machines, tax assessments for using invalid invoices, disallowed tax credits, fines for tax evasion and criminal liability for partners in extreme cases.
What works
Blindfy structures technical and fiscal validation of invoices (automated checks with the state tax authority + a sandbox for PDFs), monitors invoice access key exposure in leaks and trains finance on modern fiscal vectors.
Protection checklist
- Validate every invoice directly with the tax authority via its access key
- Block macro execution in PDFs in corporate email
- Adopt a sandbox for opening suspicious fiscal attachments
- Keep a supplier registry with activity codes and registration status
- Audit invoices with values inconsistent with the issuer's size
- Train accounting on the invoice mill pattern
- Set alerts for atypical issuance by recurring suppliers
Editorial sources
- CERT.br / NIC.br — Cartilha de Segurança para Internet
- ENCCLA / Ministério da Justiça — Enfrentamento a golpes digitais
The invoice became a double vector: technological and accounting. Validating the issuer is as critical as validating the file.