A finance manager in Casablanca gets a clean, well-formatted email: “Action required, register your company for the new e-invoicing system before the deadline.” The same week, a long-standing supplier emails to say it has “updated its bank details ahead of the new system” and asks that the next payment go to a new account. Both emails look routine. Both are invoice fraud, and Morocco’s e-invoicing reform will not stop either one.

That is the uncomfortable part of this story. The reform Morocco is rolling out under Article 145 of the Code General des Impots is a real, serious project to close the tax gap. It is not a payment security system. Understanding exactly what it checks, and what it does not, is the first step to protecting your business.

Diagram of Morocco's e-invoicing clearance flow showing the payment step as the unprotected gap exploited by invoice fraud

What Morocco’s e-invoicing reform actually changes, and why invoice fraud survives it

Morocco’s reform, introduced through the Finance Law 2024, moves the country toward a “clearance” model, also called continuous transaction control. Instead of a company issuing an invoice and reporting it later, the invoice is sent to a platform run by the Direction Generale des Impots (DGI) for validation before it has legal and tax effect.

The DGI platform checks the invoice’s format, its qualified electronic signature, the ICE (Identifiant Commun de l’Entreprise) of the parties, and mandatory data fields. Only structured formats qualify: UBL 2.1 and UN/CEFACT CII XML. A PDF, a scan, or an emailed invoice will not be compliant. Validated invoices must then be archived for ten years in an unalterable format. DGI is the central validator at launch, with certified service providers (CSP) expected to be authorized later.

The rollout is phased: large companies first, those with annual revenue above 200 million MAD, roughly 1,655 businesses, extending to SMEs around 2027-2028 and to very small businesses after that, eventually covering roughly 1.2 million Moroccan businesses. Small businesses without an ERP system are meant to get a free web portal, while ERP users connect through EDI (electronic data interchange). DGI Director General Younes Idrissi Kaitouni has framed the reform as a prevention measure against tax fraud rather than a coercive one, but that intent does not change what the system technically verifies.

Clearance validates the document: its structure, its signature, its tax identifiers. It does not validate the business relationship behind the invoice, and it says nothing about whether the bank account named on it is the real one. A perfectly compliant, DGI-validated invoice can still carry fraudulent payment instructions. This is why invoice fraud does not disappear as the reform rolls out: tax compliance and payment security are almost entirely separate problems, and only one of them is being solved.

Threat 1: fake DGI onboarding and e-invoicing phishing

The biggest advantage attackers have right now is uncertainty. As of this writing, the decree implementing the reform (decret d’application) was still awaiting publication by the Secretariat General du Gouvernement, and no precise calendar or thresholds had appeared in the Bulletin Officiel. Some Moroccan press has circulated 1 September 2026 as a start date, but that date has not been officially confirmed and should not be treated as fact. The DGI’s own e-invoicing platform is also not yet generally available to businesses.

That gap between “the reform is coming” and “nobody has published the exact rules or portal yet” is precisely the fraud window. It lets attackers send a convincing “register your company now” email, because most recipients have no official calendar to check it against. Vendor guidance has already flagged a related risk: the DGI’s e-invoicing portal name can be easily confused with an unrelated, existing Moroccan payment service with a nearly similar name. That is a name-confusion risk worth knowing, not an accusation, but exactly the kind of detail a rushed employee will not notice.

A real tax administration will not ask you to click a link to “activate” e-invoicing, will not request login credentials or a signing certificate by email, and will not threaten penalties over a system with no confirmed start date. If an email pressures urgent action on e-invoicing registration, verify it with your accountant or official DGI channels first, the same discipline you would apply to any phishing email.

Anatomy of a fake DGI e-invoicing onboarding phishing email showing the red flags of invoice fraud

Threat 2: supplier bank-detail change fraud

This is the classic version of invoice fraud, and the reform does nothing to touch it. An attacker compromises a supplier’s email account, often through an earlier phishing attack, or spoofs the supplier’s domain closely enough to pass a quick glance. From that mailbox they send your finance team routine-looking correspondence: “We have changed banks, use the account details below for future invoices.”

If your team updates its records and pays the next invoice there, the money goes straight to a criminal. The invoice itself may be genuine in every other respect, correct amount, correct company, correct reference, with only the payment destination altered. This is why invoice fraud is so effective: it targets a process your team already trusts, not a system they are suspicious of.

Business email compromise (BEC), the umbrella term for this attack, is not a small problem. The FBI’s Internet Crime Complaint Center (IC3) recorded 24,768 BEC complaints in the US in 2025, with reported losses of 3.05 billion USD. That is an average of roughly 123,000 USD per reported incident, on top of more than 55 billion USD in reported losses over the past decade. These are US figures, cited to show scale, not a claim about Moroccan losses. Speed matters too: Kaspersky research on Morocco found that roughly 49% of successful messaging-based fraud cases are completed within 30 minutes of first contact, which is why a mandatory pause before paying is one of the most effective controls available.

Threat 3: the new attack surface e-invoicing itself creates

The reform also creates things worth protecting that did not exist before. Connecting an ERP system to the DGI platform, directly or through a certified service provider, means new API credentials granting access to a company’s tax and invoicing data. Those credentials deserve least-privilege access, rotation, and monitoring, not a shared login in a spreadsheet.

The qualified electronic signature required to validate invoices is functionally a payment-grade credential: if it is stored carelessly, whoever holds it can produce invoices carrying your company’s legal signature. The ten-year immutable archive is also a target, a large, structured repository of financial data attractive to anyone planning future invoice fraud. Finally, third-party e-invoicing vendors and CSPs become part of your supply chain risk. Vet them the way you would vet any supplier who touches your finances directly.

How to protect your business from invoice fraud

A short, disciplined set of controls closes most of the gap the reform leaves open.

  • Callback verification on every bank-detail change. Call a phone number you already had on file, never one in the email, and confirm verbally before updating anything.
  • Dual authorization above a threshold. Payments over an agreed amount need sign-off from a second person who did not initiate them.
  • MFA on every finance mailbox. Multi-factor authentication, a second login step beyond a password, makes stolen credentials far less useful.
  • SPF, DKIM and DMARC on your domain. These email authentication standards make it harder for anyone to send mail that appears to come from your domain or a trusted supplier’s.
  • Treat the signing certificate like a payment credential. Restrict access to it and log every use.
  • Vet your e-invoicing vendor and any CSP before connecting systems, and confirm how they protect credentials and archived data.
  • Train the finance team on this specific scam, not phishing in general. Show them a real fake DGI onboarding email and a real bank-detail scam side by side so the pattern is recognizable. Understanding common phishing attacks in detail makes this training far more effective than a generic warning.
Two-path callback verification diagram for stopping invoice fraud when a supplier requests changed bank details

What to do if you have already paid a fraudulent invoice

Act within minutes. Contact your bank immediately to request a recall or freeze, since the earlier a bank intervenes, the higher the chance of recovery. Preserve the original email, full headers and attachments without forwarding or deleting anything. Report the incident to your bank’s fraud unit and the relevant Moroccan authorities. Finally, check whether your own mailbox or your supplier’s was compromised: if the attacker still has access, a second attempt is likely, so it is worth ruling out ongoing cyber extortion early.

Frequently asked questions

Does Morocco’s e-invoicing reform reduce invoice fraud risk?

It reduces certain tax fraud by validating invoice format, signatures and tax identifiers before an invoice has legal effect. It does not verify bank account details or the business relationship, so payment-related invoice fraud is unaffected.

Has an official start date for e-invoicing been confirmed?

No. As of this writing, the implementing decree had not been published and no official calendar had appeared in the Bulletin Officiel. Dates circulating in the press, including 1 September 2026, remain unconfirmed.

What is business email compromise?

Business email compromise (BEC) is fraud where an attacker impersonates a trusted contact, often through a compromised or spoofed email account, to trick a business into sending money or changing payment details. It is the mechanism behind most supplier bank-detail scams.

Morocco’s e-invoicing reform is a genuine step toward tax transparency, and businesses should prepare for it seriously. But preparing for compliance and preventing invoice fraud are two different projects. Treat every bank-detail change request, and every urgent email about a new government system, with the same verification discipline, however official it looks. For more context, see our overview of cybersecurity in Morocco and the legal framework governing data and fraud.

Follow Secureweb