Every fraud lesson is about money leaving. This one takes your stock instead.
A polite enquiry from a household-name company invites your business to quote. The logo is right, the Houston address is real, the signature block is complete. You quote, you ship on thirty-day terms, and then you find out the buyer never existed.
At a glance
In a fake RFQ scam the fraudster is the buyer, not a fake supplier. They impersonate the procurement team of a large real company, send a Request for Quotation, accept your price, return a purchase order on Net 15, 30 or 45 terms, and have the goods delivered to a warehouse or a residential address that has nothing to do with the company on the letterhead. Nothing is ever paid. Proofpoint's researchers found the goods chosen for resale value, things like Fluke test equipment, surveillance systems, medical instruments and networking hardware, with many shipments onward-forwarded to West Africa. The check that ends it takes one phone call: find the buyer's number yourself, on their real website, and ask whether the RFQ is theirs. Do not use the number in the signature. If a link or a domain is involved, it is worth checking where that actually resolves before you reply, because these emails are sent from lookalike domains registered for the purpose.
One that arrived this week
The email that prompted this piece landed on 3 September 2026. It carried the TotalEnergies logo, a Houston address at 1201 Louisiana St, a phone and fax number, a full legal disclaimer, and a green "consider the environment before you print" footer. It was signed by a Thomas Pierre, Procurement Manager, and it attached two PDFs: a product sheet and a document labelled as the RFQ itself.
The sender domain was totalenergiessupplymanager[.]com. TotalEnergies is at totalenergies.com. The fake reads as plausible precisely because it is built from real words in a sensible order, which is a harder thing to notice than a misspelling.
That domain now returns danger from our scanner and is on our blocklist. What it serves in a browser is nothing much: a placeholder page. It has its own mail server, and sending mail is the entire job. That is also why content-based detection struggles with this class, a point worth returning to later.
The sentence that gives it away
Second paragraph, and easy to read past:
"While some of the listed items may fall outside your standard product range, we would greatly appreciate any support you can offer in sourcing and delivering them."
Read that as a business person rather than as a security person. A real procurement team sourcing specialist equipment goes to suppliers who stock it, because that is the point of sourcing. An invitation to supply things you do not normally sell is not flexibility. It is a wider net, written so that every recipient has a reason to reply regardless of what they actually do.
The same email also flatters: "We have confidence in your company's capability to meet our procurement needs efficiently." A large buyer approaching a smaller supplier out of nowhere, complimentary and undemanding, is the emotional shape of this thing. Nothing is threatened and nothing is urgent, which is why it does not trip the instincts that urgent CEO wire requests do.
How the whole sequence runs
Proofpoint documented this pattern in July 2025, and the stages are consistent.
- The approach. An RFQ arrives from a lookalike domain or a free email account, impersonating a real procurement agent. Researchers found the operators using stolen or publicly available data, including employer identification numbers, to make the paperwork credible.
- The quote. You price the goods. Everything is normal and businesslike, and there is no fraud yet, which is what makes the next step easy.
- The terms. A purchase order comes back on Net 15, 30 or 45. This is the hinge of the entire scam: it asks for goods on credit, so no money has to move in either direction for the fraud to succeed.
- The paperwork. If your credit check hesitates, fraudulent business documentation appears to smooth the approval.
- The delivery. Goods go to a warehouse or a residential address in your own country, not to the corporate site on the letterhead. Many are then freight-forwarded onward, with Proofpoint tracing a significant share to Nigeria and Ghana.
- The silence. The invoice is never paid. Proofpoint disrupted part of this infrastructure by deactivating 19 malicious domains, which tells you both that this is organised and that domains are disposable.
The government version, and the moment people find out
The same scheme runs against federal contractors, and the GSA Office of Inspector General publishes a fraud alert about it. There, fraudsters impersonate federal employees with spoofed addresses, target businesses registered on SAM.gov, and send fake RFQs for cell phones and laptops. Fake purchase orders then direct shipment to storage facilities or freight forwarders.
The GSA alert contains the detail that describes this fraud better than any warning sign does. Victims discover it when they try to invoice the agency, and the agency has no record of the transaction.
Sit with the timeline that implies. The goods have shipped. The credit period has run. The discovery happens at the moment you ask to be paid, weeks after anything could have been stopped. That is a long way past the point where noticing helps.
What they ask for, and why
The goods are chosen for resale, not for use. Proofpoint's list runs to Fluke testing equipment, surveillance systems, medical instruments and networking hardware. The GSA sees cell phones and laptops.
The common properties are high unit value, portability, and a liquid second-hand market that does not ask many questions. A related tell falls out of that: order quantities tend to be larger than a first-time relationship would normally justify, because the operation only gets one shipment out of you and wants it to count.
Red flags, in the order they appear
- The domain is nearly right. Real brand words, arranged into a domain the brand does not own. Check it against the company's actual website rather than against your memory of it.
- From and Reply-To disagree. The GSA lists this explicitly. It is invisible until you open the headers, and it is decisive when you do.
- You are invited to supply things you do not sell. The widening line. Treat it as the strongest single signal in the message.
- Credit terms on a first order. Net 15, 30 or 45 from a buyer with no history with you. Genuine new relationships usually start tighter than this, not looser.
- The delivery address does not match the buyer. Search it. GSA advises exactly this, and a storage unit or a house is the answer that ends the conversation.
- No phone call. A procurement contact who will not take a call, or who only offers a number that appears in their own signature, has told you what you need to know.
- Language that is slightly off. The GSA mentions misspellings and awkward phrasing, though this one is weakening as the writing improves, so do not rely on it alone.
The check that settles it in one call
- Find the buyer's number yourself. Their real website, or a directory you already trust. Never the signature block, and never the reply address.
- Call and ask whether the RFQ is theirs. Give the reference number. A real procurement department can confirm or deny it in a minute, and a large company being impersonated will want to know either way.
- Compare the sender domain to the real one, character by character, side by side rather than from memory.
- Search the delivery address and see whether it has any connection to the buyer.
- Hold your normal credit policy. If a new account would not normally get Net 30, a persuasive letterhead is not a reason to grant it. The whole scheme rests on that one exception being made.
Why your email filter and your gut both miss this
Worth being clear about, because the failure is structural rather than careless.
There is no malicious link to click and no attachment that executes. The PDFs are usually just documents. Nobody is asked for a password, so no credential alarm fires. The email asks for something entirely normal in business, which is a quotation. Every trained instinct people have about phishing is looking for a different shape.
And the money never moves in the direction fraud training describes. Nothing leaves your bank account. The loss is inventory on a lorry, which is why it sits outside both the wire-transfer and fake-invoice patterns most finance teams rehearse. It is closer in spirit to payroll diversion: quiet, patient, and dressed as routine.
Flag the domain, because the domain is the one hard fact
Being precise about scope matters here, because most of this scam is outside what a browser tool can see.
We cannot read your inbox, we cannot judge a PDF attachment, and we cannot tell you whether a purchase order is genuine. The phone call above is the check that does that, and nothing on this page replaces it.
What is checkable is the domain, and in this scam the domain is the one thing the fraudster cannot fake. The email can borrow a logo, an address and a disclaimer, but it has to be sent from somewhere, and that somewhere is a name they registered. Layer 1 reads the shape of a domain locally. Layer 2 checks it server-side against reputation sources, our blocklist, and a brand database of more than 550 names. Layer 3 is the AI deep scan, a Premium feature with one free scan a day for everyone else, which reads what a page actually serves.
This particular case is also a fair illustration of where Layer 3 alone is not enough. The scam domain serves a placeholder page, so there is no scam content to read; our AI could only reach caution on it. It took a blocklist entry to make it danger, which it now is. That is worth saying plainly rather than claiming the AI caught it.
Is that procurement domain really the buyer?
Paste it here before you send a quotation or release stock. Our 3-layer engine (Local + APIs + AI) returns a verdict in about 3 seconds. Free, no signup.
Frequently asked questions
What is a fake RFQ scam?
A fraudster poses as the procurement department of a large, real company and emails your business a Request for Quotation. You quote, they send back what looks like a purchase order on standard credit terms, and you ship the goods. No payment ever arrives, because the company whose name is on the email was never involved. The loss is not money transferred out, it is stock shipped out, which is why it does not look like the fraud most businesses are trained to watch for.
How do I check whether an RFQ is genuine?
By phone, using a number you find yourself. The GSA Office of Inspector General puts it plainly in its fraud alert: locate the phone number for the listed procurement official using an independent source, then call them. Never the number in the signature block. While you are there, check the sender domain against the company's real one and search the delivery address to see whether it has anything to do with the buyer. A procurement contact who avoids a phone call is telling you something.
Why does the email say items outside my usual range are fine?
Because the operation does not care what you sell, only that you reply. A genuine buyer sourcing specialist equipment approaches suppliers who stock it. A line inviting you to source things you do not normally handle exists to widen the net so that every recipient has a reason to answer. In the email that prompted this article, that sentence sat in the second paragraph, and it is the clearest tell in the whole message.
What goods do they target?
Things that are expensive, portable and easy to resell. Proofpoint's researchers recorded requests for Fluke testing equipment, surveillance systems, medical instruments and networking hardware, and the GSA alert describes fake federal RFQs for cell phones and laptops. The pattern is high unit value with a ready second-hand market, which is also why the quantities requested tend to be larger than the relationship justifies.
I already shipped. What can I do?
Move fast, because the goods are usually still in transit or sitting at a forwarder. Call your carrier immediately and ask whether the shipment can be intercepted or recalled, since the delivery address is often a warehouse or a residential address rather than the buyer's premises. Tell your insurer and your bank. Report it to the FBI's Internet Crime Complaint Center at ic3.gov, and if the impersonated buyer was a federal agency, to that agency's Inspector General as the GSA alert directs. Then contact the real company being impersonated, because their security team usually wants to know.