How to train staff to spot vendor impersonation emails

Vendor impersonation emails redirect your supplier payments. Train finance staff on the six-second vendor check, the two-person rule and the verify-by-phone reflex.

Vendor impersonation is business email compromise where an attacker pretends to be a supplier you already pay: an updated invoice, a new bank account or an urgent overdue-notice email that routes your next payment to the attacker's account. It matters in 2026 because it needs no malware and no link click to succeed — just an accounts clerk doing a normal job on a convincing email — and it is the pattern behind a large share of Australian business email losses reported to the ACSC. Training closes it with one habit: payment details never change on the strength of an email.

TL;DR

Why vendor impersonation beats link-spotting training

Most phishing training teaches staff to inspect links. Vendor impersonation often contains no link at all: an attached PDF invoice, a plain-text request to update remittance details, a polite overdue reminder. The attacker does not need the reader to click — they need the reader to act, and the reader is acting because paying that supplier is a routine they perform every month.

The three shapes it takes:

The six-second vendor check

Train accounts and finance staff on this sequence, in order:

  1. Is the request a change to money? New bank details, a first-time invoice, an urgent overdue threat, a changed payment date. If no, normal process. If yes, keep going.
  2. Check the sender domain character by character. Not the display name — the domain. Lookalike swaps (rn for m, .com.au for .com, an added hyphen) hide in a three-second glance.
  3. Verify out of band. Call the supplier on the number you already have on file — never the number or reply-to in the email. One call resolves every case.
  4. Apply the two-person rule. No bank-detail change or first-time payment gets processed by one person. A second approver checks the verification happened.
  5. Report the email either way. If it verifies as fake, report it so IT can check whether other suppliers were contacted too.

The habit to drill: the email is never the evidence. The phone call on a known number is the evidence.

How to run the training

  1. One module, monthly rotation. A 5-10 minute vendor-impersonation module for finance and accounts staff, refreshed each quarter. Cyber Aware's awareness training covers payment-fraud modules in its monthly cadence.
  2. Walk through a real-shaped example. Show a realistic fake invoice thread and have staff call out where the tells were: the new details, the urgency, the domain, the reply-to that differs from the From address.
  3. Simulate it. Send a simulated supplier bank-change email and auto-enrol anyone who processes it into remediation. Cyber Aware's phishing simulations support invoice and payment-change lures.
  4. Write the process down. A two-person rule for any change to payee details, first-time payees, and emergency payment requests. Training that has no written process behind it fades; a process plus training sticks.
  5. Track it. Click and report rates per finance learner, trended monthly — human risk reporting gives you the per-learner numbers to show at the next board or client review.

Signals your supplier email is fake

None of these proves fraud alone — a real supplier can change banks. That is exactly why the rule is verify by phone, not spot the fake.

What to do if a payment already went out

  1. Call the bank immediately and request a recall on the transfer — speed decides whether the funds are recoverable.
  2. Report it. ReportCyber (cyber.gov.au) for the incident record, and your bank's fraud team the same hour.
  3. Freeze the pattern. Suspend pending payments to that supplier until verified by phone.
  4. Treat the mailbox as compromised if the fake arrived from the genuine supplier address, and tell the supplier so they can reset it.
  5. Debrief the process. Which check failed — the verification, the two-person rule, or the deadline pressure? Fix the process, not the person.

A security gap assessment will show where your payment-verification process and email controls have gaps before the next attempt lands.

FAQ

What is vendor impersonation? It is business email compromise aimed at your payments: an attacker posing as a real supplier asks you to pay an invoice or update bank details, and the money goes to the attacker's account.

How is it different from ordinary phishing? Ordinary phishing usually wants a click or a login. Vendor impersonation wants a payment processed, and often contains no link at all — it exploits trust in a routine, so link-spotting training alone misses it.

What is the single best defence? Verify every bank-detail change and first-time payment by phone, on a number you already had — never one printed in the email. Plus a two-person rule so no single person can process the change.

Can the sender's address look completely genuine? Yes. If the attacker has hijacked the supplier's real mailbox, the From address is authentic. That is why content and out-of-band verification matter more than sender inspection.

How often should finance staff be trained on it? One module per quarter at minimum, with a payment-change simulation in between. Payment fraud is the highest-loss email attack for Australian businesses, so the cadence should be tighter than general staff training.

Does anti-phishing software stop vendor impersonation? It catches lookalike domains and known-bad attachments, but a genuine hijacked mailbox with a normal-looking invoice can pass every filter. Software narrows the field; the human verification step is what stops the payment.

One last thing

Test the process, not just the people. The simulated email only matters if the real process — who verifies, who approves, who can say no — is written down and practised. Run the two-person rule in the drill exactly as it would run on a real Friday afternoon.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.