Business email compromise (BEC) generated US$3.05 billion in reported losses across 24,768 complaints to the FBI's Internet Crime Complaint Center in 2025, according to the IC3 Annual Report. Vendor payment fraud—where someone pretending to be a supplier emails new banking details, and your accounts-payable team wires the next invoice to a criminal—is one of the most common forms. By the time anyone notices, the money is gone.
This is not a high-tech exploit. It works because businesses trust the suppliers they pay every month and assume an email about updated bank details is routine. For Canadian and U.S. small and mid-sized businesses, a single successful wire diversion can mean tens or hundreds of thousands of dollars lost—money that is rarely recovered.
What is vendor payment fraud, and why is it so common?
Vendor payment fraud is a form of business email compromise (BEC) where an attacker impersonates a supplier your company regularly pays. The FBI's IC3 recorded 24,768 BEC complaints in 2025, up from 21,442 the year before, making it the second-highest-loss category of internet-enabled crime behind investment fraud. The Association for Financial Professionals' 2026 Payments Fraud and Control Survey found that 74% of surveyed organizations experienced BEC attempts in 2025.
The scam is common for three reasons. First, payment-detail changes happen legitimately—banks close, companies restructure, suppliers switch processors—so a request to update account numbers does not immediately raise alarms. Second, the attacker often has real context: they may have compromised a vendor's mailbox or researched your invoicing schedule from leaked data, so the timing and tone feel authentic. Third, AI tools now produce error-free, natural-sounding email in any language, eliminating the grammar mistakes that once helped staff spot fraud.
How does a vendor payment fraud attack actually happen?
The typical attack follows a predictable sequence. The Canadian Centre for Cyber Security and the FBI both describe variations of the same playbook, though details vary by industry and attacker sophistication.
- Reconnaissance. The attacker identifies your company's key vendors by scraping invoices from stolen mailboxes, examining press releases about partnerships, or buying lists on criminal forums. They learn who your accounts-payable contact is, what the invoicing schedule looks like, and how much the typical payment is worth targeting.
- Impersonation. The attacker sends an email that appears to come from the vendor—either by spoofing the domain (if your mail server does not enforce DMARC, DKIM, and SPF) or by compromising the vendor's actual mailbox. The email is professional, references a real invoice number or purchase order, and requests a routine-seeming change: "Our bank account has been updated. Please use the new details below for all future payments."
- Execution. Your AP clerk updates the payment record and processes the next invoice. The wire goes out to an attacker-controlled account, often overseas.
- Cash-out. The attacker moves the money immediately—splitting it across multiple accounts, converting to cryptocurrency, or wiring it to another jurisdiction. The FBI notes that once funds leave the originating bank, recovery rates are low unless the fraud is reported within hours.
Who is most at risk?
Any company that pays vendors by wire or electronic transfer is a potential target, but small and mid-sized businesses face disproportionate exposure. The AFP's 2026 survey found that 76% of U.S. organizations experienced attempted or actual payments fraud in 2025, with BEC the single largest category. SMBs are often targeted because:
- Fewer verification layers. In a larger company, changing a vendor's banking details may require dual approval, a call-back to a known number, and a waiting period. In a smaller firm, one person in accounting may handle the request alone.
- High implicit trust. Smaller teams know their vendors personally and are less likely to question an email that sounds familiar. Attackers exploit this by using casual language or referring to past conversations they have seen in a compromised mailbox.
- Limited email security. Many SMBs lack advanced email filtering, external-sender warnings, or enforced authentication protocols—the technical controls that would block or flag a spoofed message before it reaches an inbox.
Canadian businesses face the same risk profile. The Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025–2026 warns that fraud and scams remain "almost certainly the most common form of cybercrime impacting Canadians" and that AI-powered phishing will make these attacks harder to detect.
Why do employees fall for it if the tactic is so well-known?
Awareness is not the same as vigilance under pressure. The Canadian Competition Bureau's business fraud guidance notes that attackers deliberately exploit urgency—claiming a contract is at risk, or that a supplier will escalate to your CEO if payment is delayed. When an email arrives at a busy moment, references a real invoice, and comes from what looks like a trusted sender, even cautious staff may act before verifying.
Attackers also exploit organizational blind spots. If the person receiving the email is not the same person who set up the vendor relationship originally, they may have no reference for what a legitimate request should look like. And if your company has no written procedure for verifying payment-detail changes, there is nothing stopping the clerk from simply doing what the email asks.
What controls actually stop vendor payment fraud?
The most effective defenses are process controls—not just technical tools. The FBI, CCCS, and payments-industry bodies like NACHA all recommend variations of the same core measures.
Verify every banking-detail change through a separate channel
Before updating any vendor's payment information, call the vendor using a phone number you already have on file—not the one in the email requesting the change. Confirm the request with a person you know at the vendor. This single step defeats most vendor payment fraud because the attacker cannot intercept a phone call to a number they did not provide.
Require dual authorization for high-value or sensitive transactions
No single employee should be able to both approve a vendor-detail change and execute the payment. Separating these functions means an attacker would have to compromise two people—or two accounts—to succeed. For wire transfers above a threshold your organization defines, require sign-off from a second manager.
Tag external emails visibly
Configure your mail system to prepend a banner or tag (such as "[EXTERNAL]") to every email originating outside your domain. This reminds staff that the message is not from a colleague and should be treated with appropriate skepticism. Microsoft 365, Google Workspace, and most on-premises mail servers support this setting.
Implement and enforce DMARC, DKIM, and SPF
These email authentication protocols help prevent attackers from spoofing your own domain or your vendors' domains. They are not a complete defense—a compromised vendor mailbox will still pass authentication—but they raise the bar significantly. Ask your IT provider or managed service provider to confirm these are configured and set to "reject" or "quarantine" failures, not just "monitor."
Enable MFA on all email accounts
A vendor payment fraud attack is far more dangerous when the attacker operates from inside a compromised, legitimate mailbox—yours or the vendor's. Multi-factor authentication is the single most effective control against account takeover. Push it to every user, especially finance and executive accounts.
Train AP staff specifically for BEC, not just generic phishing
Generic security awareness training teaches employees to spot typos and suspicious links. BEC emails often have neither—they are well-written, contextually accurate, and ask for a routine action. Train accounts-payable staff to treat any request to change banking details as a verification trigger, regardless of how professional the email looks.
What should you do if a payment was already sent?
Speed is critical. The FBI's Recovery Asset Team (RAT) has frozen fraudulent accounts and recovered funds in cases where the victim reported within hours—but the window is narrow. If you suspect a wire was diverted:
- Contact your bank immediately and request a wire recall. Explain that the transaction may be fraudulent.
- Report the incident to the FBI's IC3 at ic3.gov (U.S.) or the Canadian Anti-Fraud Centre at 1-888-495-8501 (Canada). Both agencies track BEC and may be able to assist with cross-border recovery.
- Notify your IT team or provider so they can investigate whether a mailbox was compromised and whether other payment records need review.
- Preserve all evidence: the original email, headers, any attachments, and the payment record. You will need these for law enforcement and insurance claims.
Recovery rates improve when the report happens the same day as the wire. The FBI's Recovery Asset Team has demonstrated success in freezing funds when victims report quickly, but the window is narrow.
One question to ask your IT lead or provider this week
If a vendor emails requesting new banking details, what is our documented procedure for verifying the change before we update the payment record—and does every AP team member know it?
If the answer is "we don't have one" or "it depends on who's working that day," the gap is already there. A ten-minute conversation now is far cheaper than a six-figure wire loss later. If you'd like an outside perspective on where your email and payment controls stand, our free cybersecurity assessment takes about five minutes and covers business email compromise, MFA, and related risks.
This article is intended for general informational purposes only and does not constitute professional security, legal, or compliance advice. Statistics on business email compromise are based on the FBI IC3's 2025 Annual Report, the Association for Financial Professionals' 2026 Payments Fraud and Control Survey (reporting on 2025 data), and guidance from the Canadian Centre for Cyber Security. Organizations should consult qualified cybersecurity and legal professionals before making operational changes based on this article.