Glossary

Fraud methods

What is vendor impersonation fraud?

Vendor impersonation fraud is an attack in which a criminal poses as an existing supplier and submits new banking details so that legitimate invoice payments are redirected to an account they control.

Also called supplier fraud · invoice redirection · payment diversion fraud

Vendor impersonation is the operational form that most business email compromise takes. Rather than inventing a fake invoice, the attacker attaches themselves to an obligation the buyer already intends to pay, which removes every anomaly an approval workflow would normally catch.

The change request is usually accompanied by a plausible reason: a bank merger, an account under audit, a switch to a new treasury provider. Attackers frequently supply letterhead, a signed form, and a phone number, all of which are trivially fabricated and none of which are independently verified in most accounts payable processes.

The attack succeeds at the moment vendor master data is edited. Everything after that point is a correctly processed payment to an incorrect account.

Common questions

What is the most common trigger for vendor impersonation?

An emailed request to update remittance details on an existing supplier record, usually justified by a bank change and often arriving from a genuine or near identical domain.

How do you stop invoice redirection?

Treat a bank detail change as a privileged change: verify out of band against a number already on file, require a second approver, and hold the first payment for a short review window.

Primary sources

Citing this entry? Cite as Coffr, LLC and link to https://getcoffr.com/glossary/vendor-impersonation.

Read the longer research behind this in Insights, or browse the full glossary.