Vendor Email Compromise: When “Our Bank Details Changed” Drains Your Accounts Payable

Cover graphic on a deep navy field reading Vendor Email Compromise, showing an email in a real invoice thread that says our bank account has changed, with an arrow rerouting a wire payment away from the supplier and into a criminal's account, and a stat noting more than 3 billion dollars in reported business email compromise losses in 2025

Bottom line up front

A supplier you have paid for years emails inside a real invoice thread to say their bank account changed — please update the details before the next payment. The message looks right and the thread is genuine, but the account belongs to a criminal who quietly took over the vendor’s mailbox, and the money leaves by wire or ACH and rarely comes back. One habit beats every version: never accept a change to payment details by email. Call the vendor on a number you already had — not the one in the message — and require a second person to approve the change before anything moves.

The email arrives on a Tuesday, in the middle of a thread you have had open for a week. Same supplier, same invoice number, same signature block, same slightly-too-formal tone the account manager always uses. There is one new line near the bottom: “Please note we’ve switched banks — kindly update our remittance details so this month’s payment isn’t delayed.” New account number, new routing number, a fresh remittance form attached on company letterhead.

Nothing about it trips an alarm. The address is the real one. The reply lands in the real thread. Your accounts-payable clerk has processed forty invoices from this vendor without a hitch, the payment is due Friday, and a delayed payment means an awkward call with a supplier you like. So the clerk updates the record and schedules the wire. The work is done in ninety seconds, the way it is supposed to be.

Everything in that email is real except the bank account. A criminal has been sitting inside the vendor’s inbox for weeks, reading the billing conversation, waiting for exactly this moment. This is vendor email compromise, and it has quietly become the most common way businesses lose money to email fraud — not the cartoonish “CEO needs gift cards” note, but a routine housekeeping request from a partner you trust.

$3B+ Reported losses to business email compromise in 2025 alone — the second-costliest category of internet crime the FBI tracks, behind only investment fraud. The overwhelming majority of it moves by wire or ACH, which is fast, cross-border, and hard to reverse.
Source: FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report.

Seven red flags in a “we changed our bank” request

You are not looking for a typo or a broken logo. Modern vendor-impersonation email is clean. You are looking for the shape of the request — and any one of these is enough to stop and verify before a cent moves:

  1. A change to bank or payment details, full stop. This is the whole game. Any email that updates an account number, routing number, remittance address, or payment method deserves an out-of-band check — every time, even from a vendor you have paid for years.
  2. The change rides in on a real thread. Attackers reply inside genuine invoice conversations because it inherits all the trust. The presence of prior legitimate messages is not proof the newest one is legitimate.
  3. A reason that sounds administrative and dull. “We’re switching banks,” “our account was flagged for maintenance,” “consolidating to one processor.” Boring is the point — it invites a quick yes.
  4. Gentle time pressure tied to the relationship. Not “wire in 20 minutes” but “so the payment isn’t delayed” or “before the month closes.” The FBI notes you should be especially wary when a requester presses you to act quickly.
  5. A reply-to or CC that is subtly off. Sometimes the mailbox is genuinely compromised and everything matches; sometimes it is a look-alike domain — john.kelly versus john.kelley, or .co in place of .com. Read the address character by character.
  6. “Don’t call the old number — use this one.” Any nudge that steers you toward a phone number, contact, or form supplied in the same message is steering you back to the attacker.
  7. It targets the person who can pay. These emails land on accounts payable, a controller, an office manager, a bookkeeper — whoever can move money without a committee. If that is you, you are the target, not because you are careless but because you hold the checkbook.

Definition

Vendor email compromise (VEC): a form of business email compromise in which criminals take over or convincingly impersonate a supplier’s email account, then use the genuine invoice thread to send updated banking details. The payment looks routine; the account belongs to the attacker. Losses move by wire or ACH and are rarely recovered.

Why this beats the fake-CEO email

For years the classic business email compromise was the fake executive: an urgent note from “the CEO” asking a junior employee to buy gift cards or push through a wire before a board meeting. It still happens, and it still works on new hires. But finance teams have gotten wise to it. Sudden urgency from the boss now gets a second look.

Vendor impersonation sidesteps all of that suspicion because it doesn’t feel like an attack — it feels like Tuesday. Paying suppliers is the job. A banking-change request from a known vendor is unremarkable enough that questioning it can feel rude. That mismatch between how dangerous the request is and how ordinary it looks is exactly why it lands. In one large analysis of email attacks, the security firm Abnormal found that vendor-impersonation activity made up the majority of business email compromise it observed, and that employees engaged with those vendor messages at far higher rates than with fake-executive ones — a pattern it has described as a silent, high-dollar threat because so little about the email looks wrong.

The FBI puts the same scenario at the very top of its list of what BEC looks like in practice. Its first example isn’t the CEO at all — it’s “a vendor your company regularly deals with sends an invoice with an updated mailing address.” The costume looks like a supplier because a supplier is who criminals have learned to be. And the money is real: across all forms of BEC, the FBI logged more than $3 billion in reported losses in 2025, and industry group Nacha has noted the IC3 tallied almost $8.5 billion lost to BEC over three years. Small and mid-sized businesses feel it hardest, because a single diverted invoice can equal a payroll run.

Figure 01 · Anatomy of a vendor email compromise
1 THE BREAK-IN The supplier’s email login is phished, or a session token stolen — walking past MFA. 2 THE WIRETAP A hidden inbox rule auto-files anything about invoices and payments — unseen by the owner. 3 THE WATCH For weeks they read the billing thread — learning tone, amounts, and payment timing. 4 THE PIVOT They reply inside the real thread: “We’ve switched banks — here are the new details.” 5 THE PAYMENT You update the record and send the wire or ACH — believing it’s ordinary housekeeping. 6 THE STALL A calm follow-up keeps you reassured while the funds are pulled out the other end. THEN: GONE. The real vendor still expects to be paid. EXIT AT EVERY STAGE: verify any banking change on a number you already had.
The victim never sees stages 1–3; the email in stage 4 is the first visible sign. Sources: FBI IC3; Abnormal Security.

How the vendor’s mailbox got opened

The unsettling part of vendor email compromise is that the fraud often flows from a real account, not a spoofed one. Your supplier’s login gets phished, or an attacker steals a live session token and walks straight past multi-factor authentication — the same token-theft trick behind device-code phishing on Microsoft 365. From there, the first thing many intruders do is set up a quiet inbox rule that forwards or files away any message mentioning “invoice,” “payment,” “wire,” or “remittance,” so they can follow the money conversation without the real owner seeing a thing. Abnormal describes this reconnaissance step plainly: once inside, attackers watch billing threads and time their move to a real invoice.

That is why the message you receive can be flawless. It is written in the vendor’s voice because the criminal has read a month of the vendor’s emails. It references the correct invoice number because they are looking at it. It arrives the week payment is due because they know your cycle. When people say “but it came from their actual address,” that is not reassurance — with vendor email compromise, it is the entire method. This is the same playbook of patient, human-shaped manipulation covered in our guide to social engineering targeting small and mid-sized businesses: the tools are ordinary email; the craft is trust.

The cousin: a fake invoice from a company you never hired

Not every version requires breaking into anyone’s email. A lower-effort relative simply mails or emails an invoice for something you never ordered — tech support, a domain renewal, a directory listing, search-engine work — and hopes the person paying the bills processes it on autopilot. In May 2026 the FTC warned small businesses about exactly this, noting the invoices often carry a “past due” stamp to add urgency and sometimes impersonate a well-known brand. The FTC’s advice doubles as the antidote for the whole family of invoice fraud: give staff a clear procedure for approving purchases and paying only vendors you actually work with, and if an invoice comes from a company you don’t recognize, search its name alongside words like “scam” or “complaint” before paying anything. If a suspicious invoice arrives by email, you can paste it into our free email scam checker for a fast second opinion before you act.

The one control that stops every version

Strip vendor email compromise down and it depends on a single assumption: that you will treat an email as proof. Remove that assumption and the whole scheme collapses. The FBI’s guidance is one sentence worth taping to the monitor of everyone who can move money: “verify any change in account number or payment procedures with the person making the request” — using contact details you looked up yourself, never the ones in the message.

In practice that means a callback, and the direction of the call is everything. You are calling out to a number you already trusted — from a prior invoice, a signed contract, or the vendor’s official site — not calling back a number the email handed you. Reach a person you know at the vendor and read them the new account number so they can confirm or deny it. A thirty-second call kills a five-figure loss. The verification is not paperwork; it is the product.

Figure 02 · The payment-change verification checkpoint
TRIGGER Any email to change a bank account, add a payee, or rush a wire. 1 STOP Don’t reply in the thread. The email is not proof. 2 CALL OUT Use a number from your own records — a prior invoice or contract, never the one in the email. 3 TWO-PERSON SIGN-OFF A second employee approves the change before any record is edited. No solo changes. 4 RELEASE Only now update the record and pay. NEVER •  Reply to the email to “confirm” the new details •  Call the number the message gave you •  Treat a PDF remittance form as verification •  Let one person both change and pay a vendor A 30-second outbound call kills a five-figure loss.
Adapt the sign-off threshold to your size, but never drop the outbound call. Source: FBI IC3 verification guidance.

“But scammers can fake voices now”

They can, and it is worth being precise about what that does and doesn’t break. Cloning a convincing voice takes only a short sample of someone speaking — the kind of audio sitting in any conference talk or social clip — and criminals increasingly pair a compromised email with a follow-up call in a familiar voice to close the deal. We cover the mechanics in our guide to AI voice-cloning scams, and the same trick now shows up in business video compromise, where the “person” on a video call is synthetic.

Here is the thing a cloned voice cannot beat: an outbound call to a number the attacker doesn’t control. Voice cloning defeats a lazy callback — dialing the number in the email, or accepting an inbound call as proof — because the criminal is on the other end either way. It does not defeat you dialing a known number and reaching the real person, and it does not defeat a control a voice can’t satisfy. For larger changes, add one: a countersignature from a second employee, a shared verification phrase agreed with the vendor in advance, or confirmation through a separate channel like a supplier portal. Make the money contingent on something no single phone call can fake.

Build it into the process, not the person

The reason vendor email compromise keeps working is that it targets a moment, not a mind. Anyone — sharp, experienced, well-rested or not — can approve a plausible banking change on a busy Friday. So the fix can’t be “be more careful.” It has to be a rule that survives a busy Friday, applied the same way whether the request looks suspicious or not.

A few controls do most of the work, and none of them require new software:

What a legitimate banking change actually looks like

  • The vendor expects your verification call and welcomes it — a real finance contact is glad you checked, not offended
  • The new account is in the vendor’s own business name, not a personal name or an unrelated company
  • The change survives a callback to a number you already had, not one supplied in the request
  • Two of your people signed off before the record was edited — and the timing wasn’t tied to a payment due this week

Give your team the words before the email arrives

The hardest part isn’t knowing to verify — it’s saying “let me call you back on the number we have on file” to a supplier you like, without feeling like you’re accusing them of something. Practice that sentence. A team that has said it out loud a few times uses it under pressure; a team that has only read about it freezes. That reflex is exactly what a simulation program is built to install, before a real attacker tests it.

If a payment already went to the wrong account

If this already happened to your business, the people who approved the payment are not the failure — they did their job, on a request engineered to look exactly like their job. Sort the feelings later. In the first hour, speed is the only thing that meaningfully changes the outcome, so move in this order:

  1. Call your bank now and use the exact words. Say “business email compromise” and “fraudulent wire” or “fraudulent ACH,” and ask them to attempt a recall and to contact the receiving bank to freeze the funds. Minutes matter more than anything else on this list.
  2. Report it to the FBI at ic3.gov. For qualifying domestic wires reported fast, the IC3’s Financial Fraud Kill Chain can help freeze funds before they’re withdrawn. File even if you’re unsure — it also feeds the national picture that gets the next business warned.
  3. Tell the real vendor. Their mailbox may be compromised and still spraying the same request at their other customers. Your call might be the first they hear of it — and it protects the businesses behind you in line.
  4. Preserve everything and widen the circle. Keep the emails, headers, and the fraudulent account details, and alert everyone on your team who touches payments. These crews often work several invoices from one break-in, so assume this wasn’t the only attempt.
  5. Work the full sequence. Our business scam incident-response guide walks the rest — internal notifications, insurance, and closing the hole the attacker used.

Recovery is possible but never guaranteed, and the odds drop with every hour. It does happen when the alarm is fast: the FBI announced in April 2026 that it had helped recover $4.8 million diverted from a North Dakota school district in a business email compromise. But most BEC money is gone before anyone notices, which is why every dollar of effort is better spent stopping the payment than chasing it.

The email came from their real address. With vendor email compromise, that’s not the reassurance — it’s the whole trick.

Teach the callback reflex before a real supplier email tests it.

ScamDrill runs realistic simulations for your finance and AP teams — including vendor banking-change requests — so “let me verify that on the number we have on file” is a trained habit, not a lucky instinct. See how it works for your business.

Explore ScamDrill for organizations →

The one line to give your AP team today

Most businesses meet vendor email compromise for the first time with the fraudulent invoice already open and a payment already due. The whole scheme dies on contact with one standing rule — so send this to whoever pays your bills, today: “If any vendor emails to change their bank account, routing number, or where we send payment — we don’t update anything until someone calls them on a number we already had, and a second person signs off. Every time, no exceptions, no matter how normal the email looks.”

It takes ten seconds to send and it holds up on the busiest Friday of the quarter.

Frequently asked questions

What is the difference between business email compromise and vendor email compromise?

Business email compromise (BEC) is the umbrella term for fraud that uses email to trick a company into sending money or data. Vendor email compromise (VEC) is the variant that impersonates a supplier rather than an executive. Instead of a fake CEO demanding gift cards, a real-looking supplier uses a genuine invoice thread to say their bank account changed. VEC is harder to catch because the request is exactly the kind of routine housekeeping accounts payable handles every week, and in large datasets it now makes up the majority of BEC activity.

How do criminals get into a vendor’s email account in the first place?

Usually a phishing email that harvests the vendor’s password, or a token-theft attack that walks past multi-factor authentication. Once inside, the attacker often creates a hidden inbox rule that auto-forwards or auto-files any message mentioning invoices, payments, or wires, so they can read billing conversations without the real owner noticing. They watch quietly for weeks, learn the tone and timing, then reply inside a genuine thread at the moment a payment is due. Nothing about the address is spoofed, because it is the vendor’s real mailbox.

A supplier emailed to say their bank account changed. How do I verify it safely?

Do not reply to the email and do not call the number in it — both may lead back to the attacker. Instead, phone the vendor using a number you already had on file from a previous invoice, a signed contract, or their official website, and speak to a known contact to confirm the change. The FBI’s guidance is explicit: verify any change in account number or payment procedures with the person making the request, using contact details you looked up yourself. Treat email as a request to verify, never as the verification itself.

We already paid the wrong account. What do we do in the first hour?

Speed is the single biggest factor in whether any money comes back. Call your bank immediately, say the words ‘business email compromise’ and ‘fraudulent wire or ACH,’ and ask them to attempt a recall and to contact the receiving bank to freeze the funds. Then report it to the FBI’s Internet Crime Complaint Center at ic3.gov, which can trigger its Financial Fraud Kill Chain for qualifying domestic wires. Preserve the emails, keep the real vendor informed, and tell anyone else on your team who touches payments, because the same crew often targets several invoices at once.

Can we get the money back?

Sometimes, but there is no guarantee, and the odds fall sharply with every hour. When a fraudulent transfer is caught quickly, banks and the FBI’s kill-chain process can occasionally freeze or claw back funds before they are withdrawn — the FBI announced recovering $4.8 million diverted from a North Dakota school district in April 2026. But most BEC money moves by wire or ACH and is gone before anyone notices. Plan as if recovery will not happen: the reliable protection is preventing the payment, not reversing it.

Isn’t a phone callback enough? I’ve heard scammers can fake voices now.

A callback to a number you looked up yourself is still the strongest single control, and you should keep doing it. The nuance is that a cloned voice can defeat a naive callback if you dial the number the attacker gave you, or if you accept an inbound call as proof. Call out to a known number, not back to an unknown one. For high-value changes, add a second factor a voice can’t fake: a countersignature from a second employee, a known verification phrase, or confirmation through a separate channel such as a portal or an in-person check.

What controls actually stop vendor email compromise?

Make the banking-change process boring and rule-bound so no single rushed person can move money. Require out-of-band verification for every change to payment details, using contact information from your own records. Require two people to approve any new or changed payee (dual control). Ask your bank about ACH positive pay or debit blocks so unexpected accounts are flagged before money leaves. Turn on phishing-resistant multi-factor authentication for your own email, and give the finance team realistic practice so the pause-and-verify habit exists before a convincing message arrives.