Vendor Email Compromise: How Fake Invoice Fraud Hits Your AP Department

A vendor email compromise attack happens when a hacker breaks into your supplier’s actual email account and uses it to trick your accounts payable team into paying a fraudulent invoice. Unlike a standard phishing attempt where a sender address is spoofed, this threat rides a real vendor thread. The attacker simply watches the compromised inbox, waits for a legitimate billing conversation, and steps in to change the bank routing details right before you pay.
This specific type of invoice fraud business email compromise is incredibly difficult to spot because the email comes from a trusted partner. The invoice amount is correct. The goods or services were actually delivered. The only thing that changed is the destination bank account. By the time your real vendor asks why their invoice is past due, your money is already gone.
The Financial Toll of Supplier Email Compromise
Business email compromise is a massive drain on the global economy. The numbers below come from the FBI’s Internet Crime Complaint Center (IC3):
| Period | Complaints / Incidents | Losses |
|---|---|---|
| 2024 BEC (IC3) | 21,442 complaints | $2.77 billion adjusted losses; second-highest loss category of all reported internet crime that year |
| 2024 total internet crime (IC3, all categories) | 859,532 complaints | $16.6 billion, up 33% from 2023; BEC accounted for more than 17% of that total |
| 2023 BEC (IC3) | 21,489 complaints | $2.9 billion+ adjusted losses |
| Oct 2013 to Dec 2023 BEC, global cumulative | 305,033 incidents | $55,499,915,582 exposed losses |
| Oct 2013 to Dec 2023 BEC, U.S. domestic cumulative | 158,436 complaints | $20,089,561,364 exposed losses |
| Real estate BEC, 2022 | 2,284 victims | $446.1 million losses |
The 2013 to 2023 global figures were reported in all 50 states and 186 countries, with over 140 countries receiving fraudulent transfers. Primary intermediary banking locations included the United Kingdom, Hong Kong, China, Mexico, and the United Arab Emirates. Real estate BEC also grew fast: between 2020 and 2022, IC3 saw a 27% increase in victim reports and a 72% increase in victim losses.
The FBI identifies five main variants of these attacks:
- Executive impersonation
- Attorney impersonation
- Data theft targeting HR departments (see our guide to the payroll variant)
- Real estate transaction targeting
- Vendor email compromise (VEC), where invoice payment details are changed to a fraudster-controlled account
How Vendor Email Compromise Attacks Work
A financial supply chain compromise does not happen overnight. Attackers follow a specific three-step playbook to ensure their fake invoices get paid without raising suspicion.

- Take over the vendor’s mailbox (Reconnaissance and Vendor Account Takeover). The attacker targets one of your suppliers and sends a phishing email to their billing department. An employee at the supplier clicks a bad link and enters their email credentials, handing over a complete vendor account takeover. The attacker logs in, sets up hidden inbox rules to forward incoming messages to a private folder, and begins reading, studying how the supplier speaks, how they format invoices, and which clients pay the largest bills.
- Hijack the live invoice thread (Conversation Hijacking). Once the attacker understands the billing cycle, they wait for a high-value invoice to be generated. When the supplier emails you the legitimate invoice, the attacker intercepts the thread and uses the compromised mailbox to send a follow-up email, apologizing for a sudden change in banking partners or claiming an internal audit requires funds to be sent to a new routing number.
- Divert the payment (Fraudulent Invoice Payment Diversion). The attacker attaches a modified version of the real invoice. The document looks perfect because it is the real document, just with different remittance instructions at the bottom. Your accounts payable team receives the email from the correct sender address, sees the familiar invoice format, updates the payment details in your system, and authorizes the wire transfer, completing the fraudulent invoice payment diversion.
Vendor Email Compromise vs BEC: Why It Beats Standard Controls
When comparing vendor email compromise vs BEC, the biggest difference is the source of the threat. Standard business email compromise often relies on a vendor impersonation attack where the hacker uses a lookalike domain, emailing you from a misspelled domain and hoping you will not notice the typo. Supplier email compromise is a different animal, because it rides a real, authenticated mailbox instead of a fake one.
| Signal | Standard BEC (Lookalike Domain) | Vendor Email Compromise |
|---|---|---|
| Source of the email | A misspelled or lookalike domain the attacker registers | The supplier’s actual, authenticated cloud email environment |
| SPF / DKIM checks | Fails or looks suspicious | Passes perfectly |
| DMARC | Blocks or flags direct domain spoofing | Not triggered, since there is no spoofing to catch |
| Sender history | New or unfamiliar domain | Years of legitimate communication |
| What catches it | Email authentication protocols (SPF, DKIM, DMARC) and AI-driven platforms that detect behavioral anomalies and flag newly registered lookalike domains | Nothing technical. Detection falls entirely on your accounts payable team |
Because the threat actor is using the real account, technical filters usually let the vendor email compromise message through.
The One Control That Stops It: Out-of-Band Verification
Since technical filters cannot reliably catch a compromised supplier, you must rely on strict operational processes. The single most effective method for accounts payable fraud prevention is out-of-band verification.
If a vendor emails you to change their bank account, routing number, or payment address, you must verify that request outside of the email environment. This means you must call the vendor on the phone.
When executing out-of-band payment verification vendors must be contacted using a known-good phone number. You must pull this number from your own internal vendor master file or a historical contract. You must never call the phone number listed in the email requesting the change, as the attacker will simply answer the phone and authorize their own fraud. You speak directly to your established contact at the supplier and ask if they actually requested a change to their banking details. This brief phone call stops almost all invoice fraud.
Accounts Payable Hygiene and Controls
Beyond phone verification, your finance department needs structured workflows to prevent unauthorized payments. If you want to know how to prevent vendor email compromise, you must lock down how your team handles money.
Dual Approval Workflows
Implement dual approval accounts payable controls for all wire transfers and vendor profile changes. One employee should be responsible for entering the new bank information into your accounting software. A second, senior employee must review the documentation, confirm that out-of-band verification took place, and approve the change. No single person should have the authority to alter vendor payment details and release funds.
Vendor Master File Discipline
Treat your vendor master file as a highly secure database. Log every change made to a vendor profile, including who requested the change, who verified it, and who approved it. Regularly audit this file to ensure there are no duplicate vendors or unauthorized banking updates.
Aging Payment Checks
Pay attention to vendor inquiries. If a supplier reaches out to ask why an invoice is past due, but your accounting system shows the wire transfer cleared recently, you must investigate immediately. Do not assume it is a simple administrative error. This is often the first sign that you have fallen victim to a compromise. For a complete list of administrative safeguards, review the full prevention checklist.
What to Do if You Pay a Fake Invoice
If your team discovers they sent money to a fraudulent account, speed is critical. Victims should report BEC to ic3.gov and immediately contact their financial institution to request a wire recall. The practical recovery window is approximately 24 to 72 hours from when the wire was sent. After funds move from the initial receiving account, recovery probability drops significantly with each additional transfer.
Under UCC Article 4A (sections 4A-209 and 4A-211), a wire transfer is accepted and final the moment funds are credited to the beneficiary’s account. The receiving bank has no legal obligation to return funds. A wire recall is simply a request from the sending bank asking the receiving bank to voluntarily return funds. If the receiving bank agrees, it issues a Hold Harmless Letter or Letter of Indemnity to protect itself.
The IC3 Recovery Asset Team (RAT) was established in February 2018 to streamline communications with financial institutions and FBI field offices to assist in freezing funds for BEC victims. The RAT process works as follows:
- The victim contacts their originating bank to request a recall or reversal, along with a Hold Harmless Letter or Letter of Indemnity.
- The RAT forwards transaction details to the point of contact at the recipient bank, requesting the account be frozen.
- Once the recipient bank responds, the RAT contacts the appropriate FBI field office to follow through on investigation.
| Year | FFKC Incidents | Potential Losses | Frozen / Held | Success Rate |
|---|---|---|---|---|
| 2024 | 3,020 (2,651 domestic complaints, 369 international complaints) | $848.4 million | $469.1 million domestic, $92.5 million international | 66% |
| 2023 | 3,008 | $758.05 million | $538.39 million | 71% |
The RAT assumed responsibility for domestic-to-international transactions in April 2024.
If your funds went overseas, the international Financial Fraud Kill Chain (FFKC) can be activated only when all four conditions are met:
- [ ] The wire transfer is $50,000 or greater
- [ ] The transfer is international
- [ ] A SWIFT recall notice has already been initiated
- [ ] The transfer occurred within the last 72 hours
See Where You Stand
Free 2-minute BEC Exposure Check: 9 quick questions on how your business moves money, see your exposure level and the gaps to fix. No sign-up to see your result. free 2-minute BEC exposure assessment
Related Guides
- How to Prevent Business Email Compromise: SMB Checklist
- Payroll Diversion Fraud: When HR Email Gets Hijacked
- CEO Fraud and Wire Transfer Scams: How They Work
- Wire Transfer Fraud Recovery: What to Do in the First Hours
Frequently Asked Questions
What is vendor email compromise?
Vendor email compromise is a targeted cyberattack where a hacker gains unauthorized access to a supplier’s legitimate email account. The attacker uses this compromised account to send fraudulent invoices or updated bank routing details to the supplier’s clients. Because the emails come from a real, trusted partner, the fraudulent payment requests are highly convincing.
How do vendor email compromise attacks work?
Attackers first steal a vendor’s email credentials through phishing and take over their mailbox. They monitor the inbox to learn how the vendor bills clients and wait for a legitimate invoice to be generated. They then intercept the email thread, attach a modified invoice with their own bank details, and trick the client into wiring funds to the fraudulent account.
What is a red flag for a business email compromise?
A sudden, unexplained request to update banking details or routing numbers is the primary red flag for invoice fraud. Other warning signs include a sense of extreme urgency, requests to bypass normal payment approval channels, or emails from a vendor that use unusual language or formatting. Any change in payment destination should trigger an immediate phone call to the vendor.
Who is usually targeted in a BEC attack?
Hackers specifically target employees who have the authority to move money or access sensitive data. This typically includes accounts payable clerks, finance directors, controllers, and human resources personnel. Attackers focus on these roles because compromising their workflows leads directly to financial payouts or valuable data theft.
What should I do if my vendor’s email is compromised?
If you sent money to a compromised vendor, you must contact your bank immediately to request a wire recall, as the practical recovery window is only 24 to 72 hours. You should then report the incident to the FBI at ic3.gov so their Recovery Asset Team can attempt to freeze the funds. Finally, notify the vendor by phone so they can secure their email environment and warn other clients.
Secure Your Finance Workflows
LeadingIT is a Chicagoland managed IT and cybersecurity provider that has helped Illinois businesses since 2010. We serve roughly 200 organizations, building the payment-verification and incident-response processes that stop BEC in its tracks. If you need help locking down your email environment and training your staff against wire fraud, explore LeadingIT’s managed cybersecurity services, book a call, or contact us at 815-788-6041.
