Vendor Email Compromise: When “Our Bank Details Changed” Drains Your Accounts Payable
Bottom line up front
A supplier you have paid for years emails inside a real invoice thread to say their bank account changed — please update the details before the next payment. The message looks right and the thread is genuine, but the account belongs to a criminal who quietly took over the vendor’s mailbox, and the money leaves by wire or ACH and rarely comes back. One habit beats every version: never accept a change to payment details by email. Call the vendor on a number you already had — not the one in the message — and require a second person to approve the change before anything moves.
The email arrives on a Tuesday, in the middle of a thread you have had open for a week. Same supplier, same invoice number, same signature block, same slightly-too-formal tone the account manager always uses. There is one new line near the bottom: “Please note we’ve switched banks — kindly update our remittance details so this month’s payment isn’t delayed.” New account number, new routing number, a fresh remittance form attached on company letterhead.
Nothing about it trips an alarm. The address is the real one. The reply lands in the real thread. Your accounts-payable clerk has processed forty invoices from this vendor without a hitch, the payment is due Friday, and a delayed payment means an awkward call with a supplier you like. So the clerk updates the record and schedules the wire. The work is done in ninety seconds, the way it is supposed to be.
Everything in that email is real except the bank account. A criminal has been sitting inside the vendor’s inbox for weeks, reading the billing conversation, waiting for exactly this moment. This is vendor email compromise, and it has quietly become the most common way businesses lose money to email fraud — not the cartoonish “CEO needs gift cards” note, but a routine housekeeping request from a partner you trust.
Seven red flags in a “we changed our bank” request
You are not looking for a typo or a broken logo. Modern vendor-impersonation email is clean. You are looking for the shape of the request — and any one of these is enough to stop and verify before a cent moves:
- A change to bank or payment details, full stop. This is the whole game. Any email that updates an account number, routing number, remittance address, or payment method deserves an out-of-band check — every time, even from a vendor you have paid for years.
- The change rides in on a real thread. Attackers reply inside genuine invoice conversations because it inherits all the trust. The presence of prior legitimate messages is not proof the newest one is legitimate.
- A reason that sounds administrative and dull. “We’re switching banks,” “our account was flagged for maintenance,” “consolidating to one processor.” Boring is the point — it invites a quick yes.
- Gentle time pressure tied to the relationship. Not “wire in 20 minutes” but “so the payment isn’t delayed” or “before the month closes.” The FBI notes you should be especially wary when a requester presses you to act quickly.
- A reply-to or CC that is subtly off. Sometimes the mailbox is genuinely compromised and everything matches; sometimes it is a look-alike domain — john.kelly versus john.kelley, or .co in place of .com. Read the address character by character.
- “Don’t call the old number — use this one.” Any nudge that steers you toward a phone number, contact, or form supplied in the same message is steering you back to the attacker.
- It targets the person who can pay. These emails land on accounts payable, a controller, an office manager, a bookkeeper — whoever can move money without a committee. If that is you, you are the target, not because you are careless but because you hold the checkbook.
Definition
Vendor email compromise (VEC): a form of business email compromise in which criminals take over or convincingly impersonate a supplier’s email account, then use the genuine invoice thread to send updated banking details. The payment looks routine; the account belongs to the attacker. Losses move by wire or ACH and are rarely recovered.
Why this beats the fake-CEO email
For years the classic business email compromise was the fake executive: an urgent note from “the CEO” asking a junior employee to buy gift cards or push through a wire before a board meeting. It still happens, and it still works on new hires. But finance teams have gotten wise to it. Sudden urgency from the boss now gets a second look.
Vendor impersonation sidesteps all of that suspicion because it doesn’t feel like an attack — it feels like Tuesday. Paying suppliers is the job. A banking-change request from a known vendor is unremarkable enough that questioning it can feel rude. That mismatch between how dangerous the request is and how ordinary it looks is exactly why it lands. In one large analysis of email attacks, the security firm Abnormal found that vendor-impersonation activity made up the majority of business email compromise it observed, and that employees engaged with those vendor messages at far higher rates than with fake-executive ones — a pattern it has described as a silent, high-dollar threat because so little about the email looks wrong.
The FBI puts the same scenario at the very top of its list of what BEC looks like in practice. Its first example isn’t the CEO at all — it’s “a vendor your company regularly deals with sends an invoice with an updated mailing address.” The costume looks like a supplier because a supplier is who criminals have learned to be. And the money is real: across all forms of BEC, the FBI logged more than $3 billion in reported losses in 2025, and industry group Nacha has noted the IC3 tallied almost $8.5 billion lost to BEC over three years. Small and mid-sized businesses feel it hardest, because a single diverted invoice can equal a payroll run.
How the vendor’s mailbox got opened
The unsettling part of vendor email compromise is that the fraud often flows from a real account, not a spoofed one. Your supplier’s login gets phished, or an attacker steals a live session token and walks straight past multi-factor authentication — the same token-theft trick behind device-code phishing on Microsoft 365. From there, the first thing many intruders do is set up a quiet inbox rule that forwards or files away any message mentioning “invoice,” “payment,” “wire,” or “remittance,” so they can follow the money conversation without the real owner seeing a thing. Abnormal describes this reconnaissance step plainly: once inside, attackers watch billing threads and time their move to a real invoice.
That is why the message you receive can be flawless. It is written in the vendor’s voice because the criminal has read a month of the vendor’s emails. It references the correct invoice number because they are looking at it. It arrives the week payment is due because they know your cycle. When people say “but it came from their actual address,” that is not reassurance — with vendor email compromise, it is the entire method. This is the same playbook of patient, human-shaped manipulation covered in our guide to social engineering targeting small and mid-sized businesses: the tools are ordinary email; the craft is trust.
The cousin: a fake invoice from a company you never hired
Not every version requires breaking into anyone’s email. A lower-effort relative simply mails or emails an invoice for something you never ordered — tech support, a domain renewal, a directory listing, search-engine work — and hopes the person paying the bills processes it on autopilot. In May 2026 the FTC warned small businesses about exactly this, noting the invoices often carry a “past due” stamp to add urgency and sometimes impersonate a well-known brand. The FTC’s advice doubles as the antidote for the whole family of invoice fraud: give staff a clear procedure for approving purchases and paying only vendors you actually work with, and if an invoice comes from a company you don’t recognize, search its name alongside words like “scam” or “complaint” before paying anything. If a suspicious invoice arrives by email, you can paste it into our free email scam checker for a fast second opinion before you act.
The one control that stops every version
Strip vendor email compromise down and it depends on a single assumption: that you will treat an email as proof. Remove that assumption and the whole scheme collapses. The FBI’s guidance is one sentence worth taping to the monitor of everyone who can move money: “verify any change in account number or payment procedures with the person making the request” — using contact details you looked up yourself, never the ones in the message.
In practice that means a callback, and the direction of the call is everything. You are calling out to a number you already trusted — from a prior invoice, a signed contract, or the vendor’s official site — not calling back a number the email handed you. Reach a person you know at the vendor and read them the new account number so they can confirm or deny it. A thirty-second call kills a five-figure loss. The verification is not paperwork; it is the product.
“But scammers can fake voices now”
They can, and it is worth being precise about what that does and doesn’t break. Cloning a convincing voice takes only a short sample of someone speaking — the kind of audio sitting in any conference talk or social clip — and criminals increasingly pair a compromised email with a follow-up call in a familiar voice to close the deal. We cover the mechanics in our guide to AI voice-cloning scams, and the same trick now shows up in business video compromise, where the “person” on a video call is synthetic.
Here is the thing a cloned voice cannot beat: an outbound call to a number the attacker doesn’t control. Voice cloning defeats a lazy callback — dialing the number in the email, or accepting an inbound call as proof — because the criminal is on the other end either way. It does not defeat you dialing a known number and reaching the real person, and it does not defeat a control a voice can’t satisfy. For larger changes, add one: a countersignature from a second employee, a shared verification phrase agreed with the vendor in advance, or confirmation through a separate channel like a supplier portal. Make the money contingent on something no single phone call can fake.
Build it into the process, not the person
The reason vendor email compromise keeps working is that it targets a moment, not a mind. Anyone — sharp, experienced, well-rested or not — can approve a plausible banking change on a busy Friday. So the fix can’t be “be more careful.” It has to be a rule that survives a busy Friday, applied the same way whether the request looks suspicious or not.
A few controls do most of the work, and none of them require new software:
- Out-of-band verification, every time. No change to payment details takes effect without a callback to a number from your own records. Write it down as policy so it isn’t a judgment call in the moment.
- Dual control on payees. One person requests a new or changed bank account; a different person verifies and approves it. Splitting the two steps means a single compromised inbox or rushed employee can’t move money alone.
- Ask your bank about ACH positive pay and debit blocks. These let you approve which accounts can pull from or receive company funds, so an unexpected destination gets flagged before the money leaves. They pair naturally with the new fraud-monitoring duties banks are taking on — see our explainer on the 2026 Nacha ACH fraud-monitoring rule.
- Phishing-resistant MFA on your own email. You can’t force a vendor to secure their mailbox, but you can make sure yours isn’t the one that gets taken over and used against your customers. Hardware keys or passkeys beat codes that can be phished.
- A named owner for banking changes. Decide in advance who is allowed to approve a payment-detail change, and make it a rule that nobody else may — no matter how routine the email looks or how gentle the deadline.
What a legitimate banking change actually looks like
- The vendor expects your verification call and welcomes it — a real finance contact is glad you checked, not offended
- The new account is in the vendor’s own business name, not a personal name or an unrelated company
- The change survives a callback to a number you already had, not one supplied in the request
- Two of your people signed off before the record was edited — and the timing wasn’t tied to a payment due this week
Give your team the words before the email arrives
The hardest part isn’t knowing to verify — it’s saying “let me call you back on the number we have on file” to a supplier you like, without feeling like you’re accusing them of something. Practice that sentence. A team that has said it out loud a few times uses it under pressure; a team that has only read about it freezes. That reflex is exactly what a simulation program is built to install, before a real attacker tests it.
If a payment already went to the wrong account
If this already happened to your business, the people who approved the payment are not the failure — they did their job, on a request engineered to look exactly like their job. Sort the feelings later. In the first hour, speed is the only thing that meaningfully changes the outcome, so move in this order:
- Call your bank now and use the exact words. Say “business email compromise” and “fraudulent wire” or “fraudulent ACH,” and ask them to attempt a recall and to contact the receiving bank to freeze the funds. Minutes matter more than anything else on this list.
- Report it to the FBI at ic3.gov. For qualifying domestic wires reported fast, the IC3’s Financial Fraud Kill Chain can help freeze funds before they’re withdrawn. File even if you’re unsure — it also feeds the national picture that gets the next business warned.
- Tell the real vendor. Their mailbox may be compromised and still spraying the same request at their other customers. Your call might be the first they hear of it — and it protects the businesses behind you in line.
- Preserve everything and widen the circle. Keep the emails, headers, and the fraudulent account details, and alert everyone on your team who touches payments. These crews often work several invoices from one break-in, so assume this wasn’t the only attempt.
- Work the full sequence. Our business scam incident-response guide walks the rest — internal notifications, insurance, and closing the hole the attacker used.
Recovery is possible but never guaranteed, and the odds drop with every hour. It does happen when the alarm is fast: the FBI announced in April 2026 that it had helped recover $4.8 million diverted from a North Dakota school district in a business email compromise. But most BEC money is gone before anyone notices, which is why every dollar of effort is better spent stopping the payment than chasing it.
Teach the callback reflex before a real supplier email tests it.
ScamDrill runs realistic simulations for your finance and AP teams — including vendor banking-change requests — so “let me verify that on the number we have on file” is a trained habit, not a lucky instinct. See how it works for your business.
Explore ScamDrill for organizations →The one line to give your AP team today
Most businesses meet vendor email compromise for the first time with the fraudulent invoice already open and a payment already due. The whole scheme dies on contact with one standing rule — so send this to whoever pays your bills, today: “If any vendor emails to change their bank account, routing number, or where we send payment — we don’t update anything until someone calls them on a number we already had, and a second person signs off. Every time, no exceptions, no matter how normal the email looks.”
It takes ten seconds to send and it holds up on the busiest Friday of the quarter.