Vendor email compromise (VEC) is a form of business email compromise where attackers take over or convincingly imitate a supplier''s email account and use the trusted relationship to redirect payments or harvest data from the supplier''s customers. It is the hardest email fraud to detect, because the messages often come from a genuine mailbox inside a genuine thread.
Key facts
- The attack chain starts at the vendor: phishing or credential theft compromises a supplier mailbox, attackers study invoice cadence and tone, then intervene at the moment money moves.
- Every technical signal can be legitimate: real domain, real thread, passing SPF/DKIM/DMARC.
- The financial ask is disguised as routine: updated bank details, a revised invoice, a new payment portal.
Anatomy of a VEC attack
- Compromise: a supplier employee is phished; the attacker gains mailbox access and sets quiet forwarding rules.
- Reconnaissance: weeks of reading: which customers, which amounts, who approves, what the invoices look like.
- Intervention: at invoice time, the attacker sends the "updated bank details" from the real account, or from a lookalike domain registered for the occasion, matching the thread perfectly.
- Persistence: replies are intercepted via mailbox rules so the real vendor never sees the customer''s questions.
Why it defeats both filters and training
Employees are trained to spot suspicious senders; in VEC the sender is not suspicious, it is the supplier they mail every month. Filters look for bad payloads; there are none. The only reliably wrong thing is behavioral: payment details changing in a relationship whose history never included such changes, subtle shifts in tone or timing typical of pretexting, or a lookalike domain one character away from the real one.
How to defend
Treat every payment-detail change as hostile until verified through a known channel established outside email. Extend that rule to "new portal" and "revised invoice" messages: this is where invoice fraud most often lands. On the technical side, behavioral email security that models each vendor relationship''s history is the layer built for exactly this: Sentaro flags payment-detail changes and behavioral breaks inside established threads and catches lookalike supplier domains at first contact.