Vendor and Supplier Email Compromise
When a supplier's email account is hacked, attackers send invoices and bank detail changes from the real address. How vendor email compromise works and the payment controls that stop it.

Your regular supplier emails from their usual address, in the ongoing thread about this month's delivery: "Please note our bank has changed. Kindly use the new details below for this payment." Everything looks right, because it comes from the supplier's real mailbox. That mailbox has been hacked.
How it works
- Attackers compromise a supplier's email, often through phishing.
- They read conversations about invoices and payments with customers.
- At the right moment, they reply in real threads with changed bank details or new invoices. See reply-chain phishing.
- They may set rules to hide customers' replies from the real supplier.
- Customers pay the attacker's account.
Warning signs
- A change of bank details, especially to an account in a different name or country.
- Urgency, or claims of an audit or banking problem.
- Slight differences in tone, signature or reply-to address.
- Requests to keep the change quiet or not to call.
Controls that stop it
- Call to confirm any change of bank details, using a phone number from your records, not the email.
- Two-person approval for new or changed payees. See phishing aimed at finance teams.
- Hold payments to changed accounts until verified.
- Tell suppliers how you will verify changes, and ask them to do the same.
A genuine address is not enough. Verify every bank change by phone.
If you paid the wrong account
Contact your bank immediately to recall the payment, alert the supplier, and report to the police or your national fraud service. See invoice fraud and changed bank details.
Got a bank detail change request? Paste it into CyberWatch AI Scan for a free check, then call the supplier.
For all the types of phishing, read our complete guide.
Frequently asked questions
How is this different from business email compromise?
In vendor email compromise, the supplier's account is compromised and used to defraud its customers. The emails come from a genuine address, which makes them harder to spot.
The email came from our supplier's real address. How can it be fraud?
Because the supplier's mailbox itself was hacked. Always confirm bank changes by phone using a number you already had.
Who is responsible if we pay the wrong account?
It depends on contracts, law and circumstances, and recovery is often difficult. Prevention through verification is far better.
Sources
- Cybersecurity for Small Business, US Federal Trade Commission
- Small business guide: cyber security, UK National Cyber Security Centre
- Internet Crime Complaint Center, FBI


