Vendor Email Compromise (VEC)
Vendor email compromise hijacks a supplier's real email account or thread to redirect customer payments — BEC's hardest-to-spot variant.
Vendor email compromise (VEC) is a form of business email compromise in which the attacker compromises — or convincingly impersonates — a supplier's email account and uses it to redirect payments from that supplier's customers. Where classic CEO fraud fakes an internal authority, VEC weaponizes an external one: an invoice from a vendor you really owe, in a thread you were already having, for an amount you were already expecting. That context is why VEC consistently produces some of the largest per-incident losses in the BEC category.
How it works
The attack usually starts with an account takeover at the vendor — a phished mailbox at a supplier, builder, or law firm. The attacker then reads quietly for weeks: who invoices whom, for how much, on what cadence, in what tone. Mailbox rules hide the attacker's activity by auto-archiving replies or forwarding the accounts-payable thread to an external address.
The strike is timed to a real payment. The attacker replies inside the genuine invoice thread — or from a lookalike domain one character off — announcing updated bank details "due to an audit" or "a change of banking partner," often attaching a doctored but otherwise authentic-looking invoice (see invoice fraud). Because the sender, history, amount, and timing are all legitimate, standard phishing tells are absent. The customer pays the real invoice to the wrong account, and the loss is often discovered only when the real vendor chases the unpaid bill weeks later — long after the funds have moved on.
How to defend against it
- Verify bank-detail changes out-of-band, every time. Call the vendor on a number from your master vendor file — never one in the email or invoice — before changing payment details. Make the callback mandatory and exception-free, no matter how urgent the request.
- Alert on the tells that survive. Lookalike vendor domains, reply-to mismatches, and new mailbox rules on your own AP staff's accounts are detectable even when the content is perfect.
- Prepare the response. If a payment goes out, minutes matter: your incident response plan should route straight to the bank's fraud desk and an FBI IC3 filing, and finance teams should rehearse the scenario in simulations before it arrives for real.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo