← Glossary

Vendor Email Compromise (VEC)

Vendor email compromise (VEC) is business email compromise where attackers hijack or imitate a supplier's mailbox to redirect payments inside genuine invoice threads.

Updated

Vendor email compromise (VEC) is a form of business email compromise where attackers take over or convincingly imitate a supplier''s email account and use the trusted relationship to redirect payments or harvest data from the supplier''s customers. It is the hardest email fraud to detect, because the messages often come from a genuine mailbox inside a genuine thread.

Key facts

  • The attack chain starts at the vendor: phishing or credential theft compromises a supplier mailbox, attackers study invoice cadence and tone, then intervene at the moment money moves.
  • Every technical signal can be legitimate: real domain, real thread, passing SPF/DKIM/DMARC.
  • The financial ask is disguised as routine: updated bank details, a revised invoice, a new payment portal.

Anatomy of a VEC attack

  • Compromise: a supplier employee is phished; the attacker gains mailbox access and sets quiet forwarding rules.
  • Reconnaissance: weeks of reading: which customers, which amounts, who approves, what the invoices look like.
  • Intervention: at invoice time, the attacker sends the "updated bank details" from the real account, or from a lookalike domain registered for the occasion, matching the thread perfectly.
  • Persistence: replies are intercepted via mailbox rules so the real vendor never sees the customer''s questions.

Why it defeats both filters and training

Employees are trained to spot suspicious senders; in VEC the sender is not suspicious, it is the supplier they mail every month. Filters look for bad payloads; there are none. The only reliably wrong thing is behavioral: payment details changing in a relationship whose history never included such changes, subtle shifts in tone or timing typical of pretexting, or a lookalike domain one character away from the real one.

How to defend

Treat every payment-detail change as hostile until verified through a known channel established outside email. Extend that rule to "new portal" and "revised invoice" messages: this is where invoice fraud most often lands. On the technical side, behavioral email security that models each vendor relationship''s history is the layer built for exactly this: Sentaro flags payment-detail changes and behavioral breaks inside established threads and catches lookalike supplier domains at first contact.

Questions we get asked.

What is the difference between VEC and BEC?

VEC is a subtype of BEC: instead of impersonating your executives, the attacker operates from or as your supplier, exploiting an external trusted relationship. It is typically harder to detect than internal impersonation.

Why does email authentication not stop VEC?

Because the mail is often genuinely from the vendor''s real, compromised account: SPF, DKIM and DMARC all pass. Authentication proves the mailbox, not the intent of the person controlling it.

What are the warning signs of vendor email compromise?

Changed bank details or payment routes, new urgency in a routine relationship, tone or language shifts mid-thread, and lookalike domains. Any of these warrants out-of-band verification before payment.

Whose fault is a VEC loss, ours or the vendor''s?

Legally it varies and is often disputed; practically, the paying organization bears the loss and the burden of prevention. Contracts increasingly address liability for compromised communications; verification procedures protect you regardless.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.