Third-party or contractor access
Vendor email compromise
Also called: VEC
Vendor email compromise is a form of business email compromise in which attackers take over or impersonate a supplier's email to defraud the supplier's customers. Using real invoice threads, they announce changed bank details, so the customer pays genuine invoices into an account the attacker controls instead of the vendor's.
How it works
The attacker phishes a supplier's mailbox, then reads ongoing conversations about orders and payments. At the right moment they reply in the existing thread, or from a lookalike domain, with new bank details. Because the message matches what the customer expects, the payment change often goes through without a call to confirm it.
A real example
In a related business email compromise pattern, a February 2023 sentencing release on the US Secret Service site described a scheme in which conspirators broke into victim companies' email, impersonated a business partner and claimed the partner's bank account details had changed, so victims sent money to accounts the conspirators controlled.
Source: Two Men Sentenced for Laundering Proceeds of a Business Email Compromise Scheme — US Secret Service (release published by the U.S. Attorney's Office), 2023-02-22
The Identity Attack Ledger holds 9 cited incidents for third-party or contractor access in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.
How to stop it
Require phishing-resistant MFA for supplier portal and mailbox access where you can, and verify every bank detail change through a contact number already on file.
Related terms
Sources
- Two Men Sentenced for Laundering Proceeds of a Business Email Compromise Scheme — US Secret Service (release published by the U.S. Attorney's Office), 2023-02-22
Last reviewed Oct 2, 2026