Vendor Email Compromise (VEC)
Vendor Email Compromise (VEC) is a type of attack in which legitimate email accounts of suppliers, service providers or partners are misused to inject fraudulent communication into ongoing business processes. The messages appear credible because they come from real business relationships – frequently involving invoice fraud, changed bank details or the targeted request for sensitive information.
The attack typically begins with the compromise of a real account at the supplier, for example via phishing. The attackers then observe the communication, learn about processes, contacts and invoicing cycles and intervene at the right moment. VEC is thus a special form of business email compromise: the deception does not take place via spoofed but via real, taken-over senders – classic checks of sender authenticity therefore come to nothing.
Protection requires behavior-based analysis of communication patterns, defined verification processes for master data changes (such as a call-back via known channels) and transparency about risky supplier relationships. For purchasing, finance and supply chain processes, VEC is one of the most relevant email risks.