Security Glossary

What is Vendor Email Compromise?

Vendor email compromise is BEC aimed through a trusted supplier. Attackers breach or spoof a vendor, then send altered invoices or payment instructions to that vendor's customers — riding existing business relationships that finance teams already trust.

How a Vendor Email Compromise Attack Works

1

Compromise a weaker vendor

Small suppliers often have weaker email security than their enterprise customers.

2

Study open invoices and threads

Real PO numbers, amounts, and contacts make fraudulent updates believable.

3

Send payment-change notices

Customers receive "updated banking details" from a familiar address or thread.

4

Collect diverted funds

Money lands in attacker-controlled accounts before anyone reconciles.

Real-World Example

A construction GC paid a fraudulent "updated" draw request that appeared to continue an email thread with a subcontractor. The subcontractor's mailbox had been compromised two weeks earlier.

How AiVERSARY Detects Vendor Email Compromise Risk

AiVersary surfaces public vendor and partnership signals attackers use to pick intermediary targets — helping you prioritize verification procedures for high-risk supplier relationships.

Is your organization exposed to vendor email compromise?

AiVERSARY scans your public footprint and identifies the exact data attackers would use against you. $499 per report.

Get Your Threat Report