The Supplier Imposter: How a New Phishing Tactic Bypasses Standard Corporate Security
The Anatomy of the Invoice Hijack
Most of us have trained ourselves to spot the classic signs of a phishing email. We look for misspelled domain names, urgent threats about suspended accounts, or strange links that lead to sketchy login pages. But a new method targeting businesses bypasses these mental filters entirely by inserting itself into conversations you are already having.
Law enforcement officials in Belgium recently issued a warning about this highly targeted approach, which specifically aims at accounts payable departments. Instead of sending thousands of generic emails hoping someone clicks, these attackers patiently monitor compromised email accounts to find active business transactions. When they spot an invoice waiting to be paid, they step in with a subtle correction.
This is not a random attack; it is a coordinated effort that exploits the trust between established business partners. By the time the victim realizes what happened, the money is often long gone.
How the Trap is Sprung
The scam relies on a technique known as conversation hijacking. It does not start with a suspicious link, but with weeks of silent observation. Here is how the process typically unfolds:
- The Compromise: Attackers gain access to the email account of either a supplier or a client, often through a simple, leaked password.
- The Silent Wait: Instead of immediately stealing data, the intruders set up forwarding rules to quietly monitor incoming and outgoing messages.
- The Intervention: When they see an invoice sent to a buyer, the attackers intercept the thread or send a follow-up email from a lookalike address.
- The Pivot: They claim that the supplier has recently changed bank accounts due to an audit, a merger, or a technical issue, and request that the payment be sent to the new account.
Because the email arrives in the middle of an ongoing discussion about a real project, the recipient has no reason to doubt its authenticity. The invoice amount is correct, the project name is accurate, and the timing is perfect.
Why Standard Security Filters Fail
Traditional email security tools are designed to catch malicious attachments and known bad links. They struggle to detect this new wave of fraud because the emails themselves often contain nothing but plain text. There are no viruses to scan and no fake login portals to block.
The Power of Social Engineering
The attackers rely on human psychology rather than software exploits. They exploit our natural tendency to be helpful and efficient. When a regular supplier asks to update their billing details, a busy employee will often make the change quickly to keep the project moving forward.
The Lookalike Domain Trick
Sometimes, attackers do not even use the compromised account to send the final email. Instead, they buy a domain name that is nearly identical to the supplier's real domain. For example, replacing a lowercase letter "l" with a number "1" or adding a subtle "s" at the end of a company name. To a hurried eye, the sender address looks completely legitimate.
Protecting Your Cash Flow
Defending your business against this threat does not require expensive new software. Instead, it requires a shift in how your team handles financial changes. The most effective defense is a simple, non-negotiable protocol for updating payment details.
Organizations should establish a strict out-of-band verification policy. If a vendor requests a change to their bank account details, your team must confirm this change through a second, independent communication channel. This means calling a known, trusted phone number—not the number listed in the suspicious email—to verbally verify the request with a familiar contact.
Educating your finance team to recognize that any sudden change in payment instructions is a high-risk event is the best way to stop these attacks in their tracks. Now you know how these scammers operate, allowing you to protect your business before the next invoice arrives.
Social Media Planner — LinkedIn, X, Instagram, TikTok, YouTube