Vendor impersonation is business email compromise where an attacker pretends to be a supplier you already pay: an updated invoice, a new bank account or an urgent overdue-notice email that routes your next payment to the attacker's account. It matters in 2026 because it needs no malware and no link click to succeed — just an accounts clerk doing a normal job on a convincing email — and it is the pattern behind a large share of Australian business email losses reported to the ACSC. Training closes it with one habit: payment details never change on the strength of an email.
TL;DR
- Vendor impersonation is a supplier pretending (via a hijacked or lookalike mailbox) that their bank details, invoice or payment terms have changed.
- It exploits trust in routine, not curiosity — so it bypasses most link-spotting training.
- The core reflex for finance staff: verify every bank-detail change and first-time invoice by phone on a known number, never on the number in the email.
- Urgency, secrecy and new payment details appearing together are the alarm signature.
- Pair the training with a written two-person rule for payment changes and test it with a simulation.
Why vendor impersonation beats link-spotting training
Most phishing training teaches staff to inspect links. Vendor impersonation often contains no link at all: an attached PDF invoice, a plain-text request to update remittance details, a polite overdue reminder. The attacker does not need the reader to click — they need the reader to act, and the reader is acting because paying that supplier is a routine they perform every month.
The three shapes it takes:
- The hijacked mailbox. The attacker breaks into a real supplier's mailbox and sends from the genuine address. The invoice format, logo and tone are all right, because the attacker can see real history in the inbox.
- The lookalike domain. The sender registers suppliername-payments.com or suppliename-au.com and mimics the branding. Close enough to fool a busy reader.
- The fake update. A mid-stream change: same supplier, same conversation thread, but the attached invoice carries new account details, or a separate email explains the bank changed.
The six-second vendor check
Train accounts and finance staff on this sequence, in order:
- Is the request a change to money? New bank details, a first-time invoice, an urgent overdue threat, a changed payment date. If no, normal process. If yes, keep going.
- Check the sender domain character by character. Not the display name — the domain. Lookalike swaps (rn for m, .com.au for .com, an added hyphen) hide in a three-second glance.
- Verify out of band. Call the supplier on the number you already have on file — never the number or reply-to in the email. One call resolves every case.
- Apply the two-person rule. No bank-detail change or first-time payment gets processed by one person. A second approver checks the verification happened.
- Report the email either way. If it verifies as fake, report it so IT can check whether other suppliers were contacted too.
The habit to drill: the email is never the evidence. The phone call on a known number is the evidence.
How to run the training
- One module, monthly rotation. A 5-10 minute vendor-impersonation module for finance and accounts staff, refreshed each quarter. Cyber Aware's awareness training covers payment-fraud modules in its monthly cadence.
- Walk through a real-shaped example. Show a realistic fake invoice thread and have staff call out where the tells were: the new details, the urgency, the domain, the reply-to that differs from the From address.
- Simulate it. Send a simulated supplier bank-change email and auto-enrol anyone who processes it into remediation. Cyber Aware's phishing simulations support invoice and payment-change lures.
- Write the process down. A two-person rule for any change to payee details, first-time payees, and emergency payment requests. Training that has no written process behind it fades; a process plus training sticks.
- Track it. Click and report rates per finance learner, trended monthly — human risk reporting gives you the per-learner numbers to show at the next board or client review.
Signals your supplier email is fake
- New payment details in an attachment. The single most common tell in Australian invoice fraud reporting.
- Urgency plus a deadline. Account will be suspended today, delivery stops, credit hold.
- Reply-to differs from the From address. Check the actual reply destination before responding to any payment email.
- Thread continuation out of nowhere. A reply to an old invoice thread that you never sent, or a reply days after the matter closed.
- The contact path changed. Same supplier, new accounts-contact name and email, no prior warning.
None of these proves fraud alone — a real supplier can change banks. That is exactly why the rule is verify by phone, not spot the fake.
What to do if a payment already went out
- Call the bank immediately and request a recall on the transfer — speed decides whether the funds are recoverable.
- Report it. ReportCyber (cyber.gov.au) for the incident record, and your bank's fraud team the same hour.
- Freeze the pattern. Suspend pending payments to that supplier until verified by phone.
- Treat the mailbox as compromised if the fake arrived from the genuine supplier address, and tell the supplier so they can reset it.
- Debrief the process. Which check failed — the verification, the two-person rule, or the deadline pressure? Fix the process, not the person.
A security gap assessment will show where your payment-verification process and email controls have gaps before the next attempt lands.
FAQ
What is vendor impersonation? It is business email compromise aimed at your payments: an attacker posing as a real supplier asks you to pay an invoice or update bank details, and the money goes to the attacker's account.
How is it different from ordinary phishing? Ordinary phishing usually wants a click or a login. Vendor impersonation wants a payment processed, and often contains no link at all — it exploits trust in a routine, so link-spotting training alone misses it.
What is the single best defence? Verify every bank-detail change and first-time payment by phone, on a number you already had — never one printed in the email. Plus a two-person rule so no single person can process the change.
Can the sender's address look completely genuine? Yes. If the attacker has hijacked the supplier's real mailbox, the From address is authentic. That is why content and out-of-band verification matter more than sender inspection.
How often should finance staff be trained on it? One module per quarter at minimum, with a payment-change simulation in between. Payment fraud is the highest-loss email attack for Australian businesses, so the cadence should be tighter than general staff training.
Does anti-phishing software stop vendor impersonation? It catches lookalike domains and known-bad attachments, but a genuine hijacked mailbox with a normal-looking invoice can pass every filter. Software narrows the field; the human verification step is what stops the payment.
One last thing
Test the process, not just the people. The simulated email only matters if the real process — who verifies, who approves, who can say no — is written down and practised. Run the two-person rule in the drill exactly as it would run on a real Friday afternoon.