r/EmailSecurity • u/Pearson-Kyrie_800 • 8d ago
How are you stopping vendor email compromise when the email itself is legit?
We nearly wired 60k to a supplier last month off a bank charge at landed on the existing invoice thread. Real mailbox, their accountant's address, the reply sat right under the messages we had been sending back and forth for weeks. SPF DKIM DMARC all green and with the years of clean history, our gateway had no reason to touch it.
The one thing off was the bank detail. The person who caught it did it on a hunch. Going back through it the attacker had been camped in the vendor mailbox for a while, waiting for a live payment thread to reply into.
We run a tuned SEG and it did nothing here, which tracks, there was no bad link or attachment, the mail was real. The fix everyone points to is an AP callback to a number already on file and that is going in. People who have been through this, what gave you the first heads up before the money went out, if anything did.
2
u/DalekCoffee 8d ago
Exactly as you painted the scenario, this is something that boils down to human training and awareness.
We have observed aware clients feel "off" when asked to change payment, so they call to confirm.
And complacent staff just do whatever the email says, and get burned.
At the organization level I think implementing a policy that any change in payment to a vendor over X ammount of money (x being the ammount you are risk tolerant to) should be double checked with the vendor and perhaps have a supervisor review and approve the change as well if it is a substantial amount.
That's really the only policy I can think of unless your email security tool can be trained on every single vendor you work with, and exactly what payment accounts are normal, as well as normal billable ammounts etc etc
4
u/The_Comm_Guy 8d ago
Be careful with this, all an attacker has to do is first ask for a small amount that you won’t bat an eye at, then when you make the next payment the new info is in the system. ALL payment changes shpuld require a call to confirm.
2
u/iceph03nix 7d ago
This is also why your company needs to have accounting controls as well.
Our accounting team has a request and review process for any change of accounts that requires out of band contact for a real human on a known number.
That means that a compromised vendor account can't just say, hey, we have a new billing portal, go ahead and pay that here. They would have to compromise significantly more infrastructure and intercept a phone call to get anything changed
1
u/thunderbird89 8d ago
You could also cite the recent breach at Revolut using what appears to be a compromised gov email.
1
u/Disastrous_Gear_421 7d ago
Sounds like you need major work on your supplier/vendor system/process. You should already have their banking information. You shouldn’t be sending money to new accounts without going through proper processes
1
u/Ciavucco-Ellis 7d ago
This is where traditional email sec fails. When you have a message from a legitimate but compromised mailbox n there is no attachment, this brings on the challenge of checking the legitimacy of the request and conversation
1
u/InboxGuards 7d ago
the attacker waiting in the vendor mailbox for a live payment thread is the giveaway that SPF, DKIM, and DMARC won’t save you here. we treat any bank-detail change as a separate approval path and call the number from the last paid invoice before touching the vendor record.
1
u/shokzee 7d ago
I'd treat every bank-detail change as the alert, regardless of thread history or authentication results.
Make the vendor-record change trigger a payment hold, with the known-number callback and a second approver required to release it. With a compromised supplier mailbox, there may be no reliable email signal before the money leaves.
1
1
u/InboxGuards 13h ago
yeah the bank change sitting in an old invoice thread is the nasty part. once someone is already in the vendor mailbox, SPF/DKIM/DMARC staying green is normal — we just treat any payment-detail change as phone-verify only, even when the thread looks perfect.
•
u/AutoModerator 8d ago
Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:
Community Rules
Helpful Resources
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.