
Your email security filters are working exactly as designed. The message cleared DMARC, passed DKIM authentication, came from a real domain you've done business with for years, and landed in your accounts payable manager's inbox without a single warning flag.
There's just one problem: the person who sent it wasn't your vendor.
Welcome to Vendor Email Compromise (VEC) — one of the fastest-growing and least-discussed threats in business email security right now. Unlike traditional phishing, which arrives from suspicious domains and relies on urgency and deception, VEC attacks begin with a real breach of a legitimate third-party email account. By the time a fraudulent invoice or wire transfer request reaches your team, the attacker has already done months of reconnaissance. They know your vendor's billing cycles, your contact names, your payment terms, and how your communications typically read.
In 2026, as AI tools make it trivially easy to mimic writing styles and automate reconnaissance at scale, VEC has moved from a niche financial fraud technique into a mainstream threat that businesses of every size need to take seriously.
What Is Vendor Email Compromise — and Why Is It Different From BEC?
You may be familiar with Business Email Compromise (BEC), which we've covered previously on this blog. BEC typically involves attackers spoofing or directly compromising an internal executive's email account to authorize fraudulent payments or redirect payroll.
VEC is a specific and particularly dangerous evolution of that threat. Instead of targeting your organization's own accounts, attackers:
- Compromise a legitimate vendor or supplier email account — often through credential stuffing, phishing, or purchasing stolen credentials from dark web marketplaces
- Conduct silent reconnaissance — reading months of email threads, learning communication patterns, invoice formats, payment terms, and key contacts
- Insert themselves into ongoing business relationships — sending fraudulent invoices, updated banking instructions, or urgent payment requests that appear entirely legitimate
Because the email originates from a real, verified domain belonging to a real business partner, it bypasses most conventional email security controls. There's no domain spoofing to detect. The DMARC record validates. The email looks, reads, and feels exactly like every other message you've received from that vendor for years.
The FBI's Internet Crime Complaint Center (IC3) reported that BEC and related vendor fraud schemes accounted for $2.9 billion in adjusted losses in 2023 — a figure that has continued to rise through 2024 and 2025 as attackers have refined their techniques. Industry analysts tracking VEC specifically estimate that third-party account compromise now represents more than 40% of all business email fraud incidents — a dramatic increase from just a few years ago.
How a Vendor Email Compromise Attack Actually Unfolds
Understanding the anatomy of a VEC attack is the first step toward defending against it. Here's how a typical campaign plays out:
Phase 1: Initial Vendor Compromise
The attacker doesn't target your business first — they target one of your vendors. This vendor might be a smaller company with weaker security controls: no multi-factor authentication on email, employees who reuse passwords across services, or an unpatched Microsoft 365 tenant.
The attacker gains access to a legitimate employee's inbox, often without the vendor even knowing. Modern attackers are patient. They may sit inside a compromised inbox for 30 to 90 days before taking any action, simply reading and learning.
Phase 2: Reconnaissance and Pattern Mapping
Inside the vendor's compromised inbox, the attacker builds a detailed picture:
- Which businesses does this vendor serve?
- Who are the key contacts at each client?
- What do invoices look like, and how are payment instructions typically communicated?
- Are there any upcoming large transactions, contract renewals, or one-time payments?
- What is the communication tone and style of the compromised employee?
This intelligence allows the attacker to craft communications that are virtually indistinguishable from legitimate ones — not because they've used AI to generate generic text, but because they're copying real language from real conversations.
Phase 3: The Strike
At the right moment — often timed to coincide with a real invoice cycle or an expected payment — the attacker sends a fraudulent communication from the compromised account. Common scenarios include:
- Banking detail updates: "We've recently changed our banking provider. Please update your payment records and route your next invoice to the following account..."
- Fraudulent invoices: A fake invoice for services rendered, with modified ACH or wire transfer details
- Urgent payment requests: "We've noticed an outstanding balance from last month — please process this before end of week to avoid a service interruption"
Because the message is coming from a real account, replies go directly to the attacker. They can carry on an entire email conversation, answering questions and addressing concerns, for as long as it takes to get the payment authorized.
Phase 4: The Cover-Up
Once funds are transferred, the attacker often deletes the sent messages and relevant threads from the compromised inbox, buys additional time before the fraud is discovered, and moves on. By the time your finance team notices something is wrong, the money has already been moved — often internationally, across multiple accounts, and largely unrecoverable.
Why Traditional Email Security Tools Miss VEC
This is the part that makes VEC particularly dangerous: most of the security controls businesses rely on are simply not designed to catch it.
- SPF/DKIM/DMARC validates that the email came from an authorized mail server for that domain. With VEC, it did — because the attacker is using a legitimately compromised account on that domain.
- Anti-phishing filters look for suspicious links, mismatched display names, and malicious attachments. A plain-text invoice with a legitimate bank account number doesn't trigger any of these heuristics.
- URL reputation scanning has nothing to scan — there are often no links in a VEC attack at all.
- Domain reputation tools see a known, trusted sender with a clean history.
Even sophisticated email security platforms that use behavioral AI to flag anomalies can struggle with VEC, because the behavioral pattern of the compromised account may not change significantly — especially if the attacker is careful to mimic the account owner's communication style and timing.
The Role of AI in Making VEC Attacks Harder to Detect
In 2026, the VEC threat has been significantly amplified by AI tooling that's now available to low-sophistication attackers.
Tools trained on scraped business communications can now analyze a compromised inbox and automatically generate contextually appropriate follow-up messages — matching writing style, sign-off conventions, and even the specific formatting quirks of the compromised employee. What once required a skilled social engineer who could fluently mimic business communication now takes minutes and costs almost nothing.
This means VEC attacks are no longer confined to high-value targets like enterprise finance teams. Small and mid-size businesses are being targeted because their vendors — often other SMBs — tend to have weaker email security postures and because their AP teams may have less rigorous verification procedures.
How to Defend Your Business Against Vendor Email Compromise
VEC requires a layered defense strategy that goes beyond any single technical control. Here's what business leaders and IT teams should be implementing right now.
1. Implement and Enforce Callback Verification for Payment Changes
This is the single most effective process control you can put in place. Any request to change banking details, routing numbers, or payment methods must be verified via a phone call to a number you already have on file — not a number provided in the email requesting the change.
This sounds simple, but it's consistently where businesses fail. Train your AP and finance teams that this is a non-negotiable step, every single time, without exception. The inconvenience of a phone call is trivial compared to the cost of a fraudulent wire transfer.
2. Deploy Behavioral Email Security That Monitors Third-Party Communication Patterns
Modern email security platforms can build behavioral baselines for your most frequent communication partners. Anomalies — a vendor account that suddenly starts discussing payment changes after months of only sending project updates, or an email thread that changes tone or formatting — can trigger alerts for human review.
This is an area where platforms built on behavioral AI analytics genuinely add value that signature-based tools cannot. Layer27's Protect Pro service includes advanced email threat protection that extends this kind of behavioral analysis to your business communications environment.
3. Include Vendor Security in Your Third-Party Risk Assessments
You can't control whether your vendors have strong email security — but you can factor it into your vendor risk management process. When onboarding or renewing major vendor relationships, ask:
- Do you require MFA on all email accounts?
- Have you implemented DMARC with a reject or quarantine policy?
- Do your employees receive regular security awareness training?
Vendors who can't answer these questions confidently represent elevated risk to your business. This kind of third-party risk evaluation is a component of Layer27's Compliance services, particularly for businesses operating under frameworks like SOC 2, ISO 27001, or NIST CSF.
4. Build Security Awareness Training That Covers VEC Specifically
Most security awareness programs do an adequate job of teaching employees to spot suspicious emails from unknown senders. Far fewer train employees on the specific risk profile of VEC — trusted senders, real domains, familiar communication patterns.
Your finance, AP, and procurement teams in particular need scenario-based training that covers:
- Recognizing red flags in "trusted" communications (sudden banking changes, urgency, slightly unfamiliar phrasing)
- Understanding that a verified sender domain does not equal a safe message
- Following payment verification procedures even under deadline pressure
Layer27's Security Awareness Training program includes customizable phishing simulations and training modules that can be tailored to include VEC-specific scenarios for high-risk roles. When employees understand exactly what these attacks look like in context — not just generic phishing examples — they're dramatically more likely to catch them in the real world.
5. Segment and Monitor Financial Workflows
Organizations that process payments through isolated, monitored workflows are significantly less exposed to VEC. Consider:
- Requiring dual approval for all payments above a defined threshold
- Implementing out-of-band approval notifications (a separate system that alerts a second approver via a different channel)
- Logging and reviewing all banking detail changes with a mandatory waiting period before implementation
These controls add friction — which is exactly the point. Attackers depend on the speed of normal business processes. Adding structured delays and secondary approvals to financial transactions significantly reduces the window for a successful attack.
6. Establish Threat Detection That Monitors for Compromised Credential Use
While you can't always prevent your vendors from being compromised, you can monitor for signals that your own accounts are being used in ways consistent with reconnaissance or exfiltration. Unusual login times, geographic anomalies, mass email reads, or new inbox rules that forward messages externally are all indicators worth detecting.
Layer27's Managed Detection & Response (MDR) service and 24x7 SOC provide continuous monitoring of your environment for exactly these behavioral indicators — flagging suspicious account activity before it becomes a full compromise, and responding in real time when threats are confirmed. If an attacker is inside one of your accounts conducting pre-attack reconnaissance, that's the moment you want to catch them — not after the wire transfer is sent.
7. Harden Your Own Email Environment to Prevent Becoming the Compromised Vendor
It's worth remembering that in every VEC attack, there's a victim on both sides: the business that receives the fraudulent payment request, and the vendor whose email account was compromised and weaponized.
Make sure your own organization isn't the weak link in someone else's supply chain:
- Enforce MFA on all email accounts, including shared mailboxes and distribution lists
- Deploy DMARC with a p=reject policy on all sending domains
- Audit inbox delegation rules and forwarding configurations regularly
- Use email security platforms that flag unusual bulk read or export activity
Layer27's Safe Start and Infrastructure Pro services include baseline email security hardening as part of their scope — ensuring MFA enforcement, DMARC configuration, and email platform hardening are done correctly from the ground up.
What to Do If You've Already Been Hit
If you suspect a VEC attack has already resulted in a fraudulent payment:
- Contact your bank immediately — wire transfer recalls have the highest success rate within the first 24 to 48 hours
- File a complaint with the FBI's IC3 at ic3.gov — they have a Financial Fraud Kill Chain process that can help recover funds in some cases
- Notify the compromised vendor so they can secure their account and alert other customers
- Preserve all email evidence — do not delete anything before your incident response team reviews it
- Engage your incident response process — if you don't have one, this is the moment to recognize why you need one
Having a tested incident response plan and a Backup-as-a-Service (BaaS) strategy in place before an incident occurs means you're not scrambling for forensic evidence or business continuity options in the middle of a crisis.
The Bigger Picture: Email Security in 2026 Requires Defense-in-Depth
VEC is a reminder that email security is not a problem you solve once with a single tool. No filter, no matter how sophisticated, eliminates the human element — and VEC is fundamentally an attack on human trust.
Effective email security in 2026 requires:
- Technical controls that detect behavioral anomalies, enforce authentication, and monitor for account compromise indicators
- Process controls that add verification steps to high-risk financial transactions
- People controls that ensure employees at every level understand the specific threats they face and what to do when something feels off
- Response capabilities that allow you to contain and investigate quickly when the inevitable happens
For businesses that don't have in-house security expertise to manage all of these layers, Co-Managed IT provides a way to augment your existing IT team with the specialized skills and tooling needed to close the gaps — without replacing the institutional knowledge your team already has.
Final Thoughts
Vendor Email Compromise is the threat that succeeds precisely because everything about it looks legitimate. The sender is real. The domain is trusted. The conversation feels familiar. And that's exactly why it's working — and why businesses that rely solely on technical email filters to protect their financial workflows are leaving a dangerous gap open.
The businesses that fare best aren't necessarily the ones with the biggest security budgets. They're the ones that combine smart technical controls with well-trained people and clearly defined verification procedures — and that treat email security as an ongoing discipline rather than a one-time configuration.
Want to know how your current email security stack holds up against VEC and other advanced threats? Layer27 can help you assess your exposure, harden your environment, and build the training programs your team needs to recognize these attacks before they succeed.

