What is Vendor Email Compromise?
Vendor email compromise is BEC aimed through a trusted supplier. Attackers breach or spoof a vendor, then send altered invoices or payment instructions to that vendor's customers — riding existing business relationships that finance teams already trust.
How a Vendor Email Compromise Attack Works
Compromise a weaker vendor
Small suppliers often have weaker email security than their enterprise customers.
Study open invoices and threads
Real PO numbers, amounts, and contacts make fraudulent updates believable.
Send payment-change notices
Customers receive "updated banking details" from a familiar address or thread.
Collect diverted funds
Money lands in attacker-controlled accounts before anyone reconciles.
Real-World Example
A construction GC paid a fraudulent "updated" draw request that appeared to continue an email thread with a subcontractor. The subcontractor's mailbox had been compromised two weeks earlier.
How AiVERSARY Detects Vendor Email Compromise Risk
AiVersary surfaces public vendor and partnership signals attackers use to pick intermediary targets — helping you prioritize verification procedures for high-risk supplier relationships.
Is your organization exposed to vendor email compromise?
AiVERSARY scans your public footprint and identifies the exact data attackers would use against you. $499 per report.
Get Your Threat ReportRelated Terms
Business Email Compromise
Business email compromise is when an attacker impersonates a senior executive — usually the CEO or CFO — to trick an employee into wiring money or sharing sensitive data. These attacks don't require any malware or hacking; they rely entirely on convincing someone that a fraudulent request is coming from their boss. The FBI reports BEC has caused over $50 billion in losses worldwide.
Supply Chain Attack
A supply chain attack reaches your organization through a third party — software updates, managed providers, or operational vendors. Instead of breaking your front door, attackers break someone you already let inside.
Lookalike Domains
Lookalike domains are registered names that visually or typographically resemble a trusted brand — rn instead of m, extra letters, or alternate TLDs. They power phishing sites, fraudulent invoices, and executive impersonation that bypass casual visual checks.
Pretexting
Pretexting is when an attacker creates a fabricated scenario — a "pretext" — to trick someone into sharing information or performing an action they normally wouldn't. Think of it as method acting for criminals: they invent a believable character and situation, then play that role convincingly enough to bypass your team's natural skepticism. The quality of the pretext depends entirely on how much real information the attacker can gather beforehand.