Warning: Fake invoices are circulating in Elisa’s name
Translated from Estonian and summarized by DistantNews. Read the original for the full story.
At a glance
- Scammers are sending fake Elisa invoices that imitate the company’s branding and routine billing emails.
- The links can lead to fraudulent pages designed to steal banking credentials or trick users into approving unwanted payments.
- Elisa advises customers to verify addresses, avoid payment links in emails and carefully read Smart-ID or Mobile-ID confirmation requests.
Elisa has warned customers about a new wave of scam emails that look like ordinary company invoices. The timing makes the scheme especially deceptive because Elisa is also sending genuine bills to customers.
The fake messages copy Elisa’s name, visual identity and billing design. Unlike many phishing emails, they may not contain obvious threats or claims about unpaid debts. Instead, they present what appears to be a normal invoice and direct the recipient to a payment page.
Ivar Tennokes, Elisa’s product manager for digital security, said the overlap with the company’s real billing cycle could make customers accept the messages automatically. Elisa’s official invoices come from arved@elisa.ee, but the company cautions that checking the sender name alone may not be enough because scammers can make messages appear authentic.
This is currently a period when Elisa customers are also receiving genuine invoices, and scammers are deliberately exploiting that. If someone is already expecting an invoice and receives an email with Elisa’s name and design, it is very easy to assume automatically that it is genuine.
Elisa has removed direct payment links from its invoices as an additional security measure. The “Pay invoice” button now takes customers first to Elisa’s self-service portal, where they can check the invoice details before paying. A link that takes a customer straight to a bank or payment page should be treated as a warning sign.
The fraudulent page may imitate Elisa, a bank or a familiar payment service. It can ask users to authenticate or confirm a payment. Elisa warns that entering banking credentials or approving an action through Smart-ID or Mobile-ID could give scammers access to an account or authorize a different payment from the one displayed. Customers should check the sender and website addresses, never share PINs or banking passwords, avoid paying through email links, keep security measures updated and contact their bank and Elisa immediately if they suspect fraud.
With Smart-ID or Mobile-ID, you must always read what you are confirming. The PIN does not confirm the text shown on the website, but a specific action. If the confirmation does not match what you intended to do, cancel the action immediately.
Originally published by Postimees in Estonian. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.