A scenario more common than you think
Your accounting team receives an email from a regular supplier. The message is polite, the logo is right, the tone is familiar. It announces a simple change of bank account for upcoming payments. Nothing alarming. The next transfer goes to the new account, and the money vanishes.
This is vendor impersonation fraud, a form of what is called business email compromise. It does not rely on a virus, but on trust and routine.
Why it works so well
The attacker has done their homework
Often, the fraudster already has access to a compromised mailbox, yours or the supplier's. They read the exchanges, learn the amounts and wait for the right moment, such as the day before a scheduled payment.
No one wants to keep a supplier waiting
The pressure to pay on time works against you. A rushed employee approves without picking up the phone.
The controls that stop the fraud
What to do if you have doubts or the transfer is gone
Act fast. Contact your financial institution immediately to try to recall the funds, report the incident and keep all the evidence. The first few hours matter.
The best protection is the reflex
No software replaces a simple rule applied without exception: never change a payment account on the strength of an email alone. That reflex, shared across the team, is worth every firewall in the world.
Want to put these controls in place and train your team? Contact us to discuss.


