VEC Vendor Email Compromise
BEC variant where the attacker compromises a third-party vendor's inbox and uses it to attack the vendor's customers, leveraging existing trust between organizations.
In vendor email compromise the attacker takes over a mailbox at one of your suppliers and then attacks that supplier’s customers from inside it. The messages come from the genuine domain, pass SPF, DKIM and DMARC because they really are authentic, continue existing threads with accurate history, and arrive from a correspondent your finance team already trusts. Every signal a recipient normally uses to judge legitimacy is telling the truth.
The patient version is what makes it expensive. An intruder with mailbox access can read months of billing correspondence before acting, learn the amounts, the approval chain, the invoice format and the timing, then intervene at exactly the right moment with banking details changed. Mail rules are often planted to hide replies from the real account owner, so the supplier does not notice while it is happening.
Controls that help are procedural more than technical. Verify any change to payment details out of band, on a number you already held rather than one supplied in the message. Require a second approver for banking changes above a threshold. On the detection side, watch for anomalous mailbox rule creation, impossible-travel logins and unusual OAuth grants on your own tenant, because your mailboxes are somebody else’s supplier.
Common questions
What is the difference between BEC and VEC?
Business email compromise usually impersonates someone inside your own organization, often an executive, to push a payment through. Vendor email compromise operates from a genuinely compromised mailbox at a third party in your supply chain. The difference matters because VEC mail is authentic, so sender authentication and impersonation detection do not flag it.
Why does vendor email compromise bypass email security?
Because there is nothing inauthentic to detect. The domain is real, the sending infrastructure is authorised, SPF, DKIM and DMARC all pass, and the message often continues a legitimate existing thread. Controls built to spot spoofing and lookalike domains have nothing to catch, which leaves behavioral signals and payment process as the effective defences.
How do you protect against vendor email compromise?
Verify banking changes through a channel and contact details you already hold, never ones provided in the request. Require dual approval for changes to payment details. Monitor your own tenant for the signs of mailbox takeover, including suspicious forwarding or hiding rules, impossible-travel sign-ins and new OAuth grants, since preventing your own compromise protects your customers from the same attack.
VEC is one signal.
We watch the rest.
Vijilan runs a 24/7 SOC across endpoint, identity, cloud, network, SaaS and mobile, and acts on what it finds rather than forwarding an alert.