Pause an unexpected invoice or payment-detail change until you confirm it through a contact route established independently of the message. Call the creator or their authorized representative using a previously verified number. Check the invoice against the agreement, then have finance approve any change before paying. A strange address, urgent deadline, or new bank account warrants verification; none proves fraud by itself.
An influencer collaboration email scam can arrive during a real negotiation. Australia's cyber security guidance on business email compromise describes both impersonation and the use of compromised email accounts. A familiar sender therefore still needs a payment-change check.
Separate campaign risk from payment verification
Modash's article on risky collaborations discusses creator vetting, communication, and limits on campaign risk. Those checks address whether a partnership suits your brand and campaign. Payment verification asks a narrower question: did the authorized person request this specific invoice or change?
Keep three decisions separate:
- Identity. Are you speaking with the creator or a representative whose role you have confirmed?
- Authority. Can that person approve this invoice, payment recipient, or account change?
- Payment. Does the request match the agreed work, amount, currency, and payment milestone?
Knowing the campaign name answers none of these on its own. The Australian guidance on invoice fraud explains that someone with access to a vendor's email can alter a legitimate invoice and send it from that account.
The workflow below is an operational recommendation for a campaign team. It does not establish a universal legal payment deadline or permission to disregard your agreement.
Decide what needs a hold
Apply a hold to the affected payment and payment-record change. Avoid labeling the creator as fraudulent while you investigate.
| What changed | What to check | Action pending confirmation |
|---|---|---|
| An invoice appears before a fee was agreed | The approved scope, fee, and billing milestone | Keep it out of the payment queue |
| The beneficiary or bank account changes | Who requested the change and who may approve it | Preserve the existing record; do not substitute the new details |
| A new manager requests payment | The creator's confirmation of the representative's role | Pause the change and verify the handover |
| The sender demands secrecy or an exception | Why the normal finance process must be bypassed | Escalate to the payment approver |
| A link asks you to sign in to view an invoice | Whether an independently accessed account contains the request | Leave the message's link unopened |
Bank-detail changes, urgency, domain mismatches, and pressure to bypass business processes appear in the Australian government's warning signs. Treat them as reasons to investigate. A creator may have changed agencies or banks for a legitimate reason.
Do not open an attachment to satisfy your curiosity about a suspicious request. The US FTC's phishing advice warns that links and attachments can install harmful software. Ask your security team how to preserve and inspect the message.
Verify outside the incoming message
Start with the campaign's existing records. Find the agreed fee, payment trigger, known representative, and contact details verified before this request arrived.
Call the saved number yourself. Do not use a new number in the invoice, signature, or reply. The FTC recommends contacting a known company through a phone number or website you know is real, independently of the suspect message.
A reply to the same thread cannot provide that separation when the mailbox itself may be compromised. A second email address supplied by the sender has the same weakness. An unsolicited callback also needs verification through your established route.
If you have no trusted number, keep the payment on hold while you establish one. For an agency, start from its independently verified official website and ask for the named representative. For a creator, use your established onboarding contact process. Verify that a contact page belongs to the creator before treating a newly found page as evidence of identity.
Public profile links can help locate a contact route. They do not establish that the person answering may redirect payment. If you cannot establish identity and authority, escalate rather than making a guess.
Use a payment-change verification script
The following is an illustrative script for a call you place through an independently verified route. It contains no real campaign or customer details.
I'm checking a payment request connected with our collaboration. Our process requires a separate check before we change the recipient or bank details.
Did you request a payment change? Please describe what changed and why.
Which invoice, amount, currency, and payment milestone does it concern?
Who is authorized to approve this change? If an agency will receive payment, can we confirm that arrangement through our agreed approval process?
Finance will collect the confirmed details through our approved payment process. We will release payment after the change and invoice have been approved.
Ask the person to describe the request before you supply its answers. Matching campaign details supports the review, but details alone do not prove identity. Keep the independent contact check and finance approval in place.
Do not ask for passwords, sign-in codes, or bank-login access. Do not paste full banking details into a group campaign thread. Use the separate guidance on keeping payment details out of general campaign notes to decide where finance stores the verified record.
Resolve the request with a recorded decision
Use one of three outcomes:
| Verification result | Decision | Record |
|---|---|---|
| The authorized contact confirms the change and finance approves it | Process the verified instruction | Contact route, approver, date, and payment-record reference |
| The contact denies the request or details conflict | Keep the payment blocked and notify security | Original message reference and the conflict |
| The contact is unavailable or authority remains unclear | Keep the change pending and assign a follow-up owner | Unresolved question and next contact attempt |
For a hypothetical example, suppose a creator's usual address sends an invoice with a new agency beneficiary. The campaign manager calls the number verified during onboarding. The creator confirms a new agency relationship but says they have not approved the invoice. The invoice stays pending while finance checks the agency's authority and the billing milestone. Confirmation of the agency relationship alone does not complete the payment check.
When a real management change explains the request, prepare a creator-manager handover so the next invoice has a clear owner.
Escalation checklist if something went wrong
If you already acted, stop further payments and tell finance and security what happened. Use this checklist:
- Record whether you only received the message, clicked a link, opened a file, entered credentials, or sent funds.
- Preserve the original message and payment reference through the team's incident process. Do not circulate suspicious attachments to campaign colleagues.
- If you sent money or banking details to a suspected scammer, contact your bank immediately through its established channel. Australian government guidance calls for immediate bank contact. Ask what action is possible; do not assume recovery.
- If credentials or a device may be compromised, involve the person responsible for account security. Avoid signing in again through the suspicious link.
- Use the reporting route for your jurisdiction. The FTC's phishing guidance names US reporting and identity-theft resources. The Australian guidance links to its cybercrime reporting route.
- Tell the verified creator contact which request is on hold without making an unsupported accusation.
Before the next creator payment, name the person who verifies changes and the person who approves them. Save the independently verified contact route during onboarding, while there is time to check it.



