ScamLens
High RiskAverage Loss: $20,000Typical Duration: 1-14 days

Vendor Impersonation Scams: Protect Your Business

Vendor impersonation scams occur when fraudsters research a company's legitimate suppliers and then create fraudulent invoices, emails, or communications that appear to come from those vendors. The scammer typically targets accounts payable departments or finance teams, exploiting the routine nature of vendor payments and the urgency of business operations. According to the FBI's 2023 Internet Crime Complaint Center (IC3) report, Business Email Compromise (BEC) scams—which often involve vendor impersonation—resulted in over $2.7 billion in losses that year, with individual incidents averaging $20,000 to $150,000 for larger enterprises. Small and medium-sized businesses are particularly vulnerable because they may lack sophisticated email authentication systems and payment verification protocols that larger corporations implement. These scams have evolved significantly since they emerged in the mid-2010s. Early versions relied on crude email spoofing, but modern vendor impersonation attacks now incorporate detailed knowledge of company operations, legitimate vendor names, accurate payment terms, and even replicated company letterheads and logos. Scammers often conduct weeks of reconnaissance, monitoring a company's email communications and vendor relationships through data breaches, social engineering, or LinkedIn research. The average time from initial contact to fraudulent payment is just 1-14 days, creating a narrow window for detection before funds are transferred to offshore accounts that become virtually untraceable. The danger extends beyond immediate financial loss. Vendor impersonation scams can damage business relationships with legitimate suppliers, create accounting discrepancies that trigger audits, expose companies to legal liability if they fail to detect fraud, and undermine trust within finance departments. Repeat targeting is common—scammers often return to successfully compromised companies with new schemes, and businesses that fall victim once face a 20-30% higher risk of repeated attacks within the following 12 months.

Common Tactics

  • Sending invoices with slightly altered email addresses (e.g., vendorname@gmail.com instead of the legitimate corporate domain) or using domain names that closely mimic the real vendor's URL, such as changing 'supplier.com' to 'suppIier.com' or 'supplier-inc.com'.
  • Requesting urgent payment redirection due to 'bank account changes,' 'system updates,' 'tax compliance issues,' or 'merger/acquisition activities' that create time pressure and bypass normal verification procedures.
  • Replicating legitimate vendor communications by copying actual invoice formats, payment terms, purchase order numbers, and pricing from previous transactions discovered through email breaches or social engineering.
  • Targeting specific employees through spear-phishing emails that reference real projects, deadlines, or executives by name, making the communication appear authentic and time-sensitive.
  • Using legitimate payment methods like ACH transfers or wire transfers to bank accounts in the vendor's name but located in different countries, making recovery extremely difficult once funds clear.
  • Following up with multiple reminder emails or calls from fake vendor support lines, escalating pressure and urgency while answering questions about the fake invoice with surprisingly accurate details about the company's operations.

How to Identify

  • Invoice requests for significantly larger amounts than typical vendor payments, or requests to pay multiple invoices at once that differ from the vendor's normal billing patterns or frequency.
  • Email addresses or domain names that are nearly identical to legitimate vendors but contain subtle misspellings, different extensions (.net instead of .com), or use free email services instead of corporate domains.
  • Sudden requests to change payment methods, add new payees to your approved vendor list, or redirect payments to new bank accounts without accompanying official letterhead, purchase orders, or multi-party approval from the vendor.
  • Communications that create artificial urgency by citing tight deadlines, system maintenance windows, or one-time payment opportunities, especially when they bypass your established procurement workflows.
  • Invoice amounts that don't match historical transaction amounts with that vendor, include unusual line items, or lack detailed descriptions and itemization normally found in that vendor's legitimate invoices.
  • Email headers, metadata, or digital signatures that appear invalid when you forward emails to your IT security team, or requests sent to generic company email addresses rather than the specific accounts payable contact person who normally receives vendor communications.

How to Protect Yourself

  • Implement email authentication protocols including SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting and Conformance) to detect and flag spoofed emails from vendors or internal addresses.
  • Establish a mandatory verification protocol requiring finance staff to contact vendors directly using phone numbers from official company websites or previous invoices before processing any payment change requests, new vendor onboarding, or account redirection.
  • Use vendor management software that centralizes approved vendor lists, payment accounts, and contact information in a secure system that requires multi-level authorization before any changes are recorded.
  • Train accounts payable and finance staff quarterly on vendor impersonation tactics, including phishing recognition, email verification techniques, and procedures for flagging suspicious communications without processing payments first.
  • Implement dual approval requirements for any new vendors, wire transfers exceeding threshold amounts (typically $5,000-$50,000 depending on company size), or payment method changes, with secondary approval from a different department or manager.
  • Monitor bank accounts and accounting software for unusual activity including payments to new accounts, transfers to international banks, or invoice amounts significantly outside normal ranges, reviewing flagged transactions within 24 hours of processing.

Real-World Examples

A manufacturing company received an email appearing to come from their primary electronics supplier (a vendor handling approximately $300,000 in annual contracts). The email, sent to the accounts payable manager, referenced an urgent invoice for $47,500 related to a legitimate project and requested payment to a 'new account' due to recent banking consolidation. The email included the actual company logo and invoice format copied from legitimate previous transactions. Within 36 hours, the payment was processed via wire transfer to a bank account in Singapore. The actual vendor confirmed 14 days later that they never sent the invoice. By that time, the funds had been withdrawn and the originating account was closed.

A professional services firm with 150 employees received multiple invoices totaling $89,000 from what appeared to be their IT infrastructure provider, including one invoice supposedly for emergency server maintenance during a known outage the company had experienced. The email came from 'it-support@infrastruct-tech.com' (the real company uses 'itsupport@infrastructech.com'). Three separate invoices were processed over 8 days before the actual vendor inquired why they hadn't been paid for legitimate services they'd recently completed. The scammer had monitored the company's email security issues for three weeks and knew about the exact outage timing.

Frequently Asked Questions

How can I tell if a vendor invoice or payment request is actually from our legitimate supplier?
Always verify payment requests through a communication channel you initiated yourself—call your vendor's known phone number from a previous invoice or their official website, never use contact information from the suspicious email. Check for red flags like slight variations in the vendor's email domain (suppIier.com instead of supplier.com), requests to change established payment methods or bank accounts, and urgency language that pressures quick payment. Confirm the invoice amount and purchase order number against your internal records and the vendor's previous billing patterns before processing any payment.
What should I do immediately if I suspect I've received a fraudulent vendor payment request?
Do not pay the invoice and do not reply to the suspicious email. Immediately report it to your finance manager, accounts payable department, and your IT security team, then forward the full email headers to your email security provider so they can identify spoofing attempts. Contact your actual vendor through a verified phone number or official website to confirm whether they sent the request, and file a report with the FBI's Internet Crime Complaint Center (IC3) at ic3.gov within 24 hours to help law enforcement track the scammer.
If our company already paid a fraudulent vendor invoice, can we recover the money?
Recovery is difficult once funds are transferred, especially if they went to an offshore account, but you must act within hours. Immediately notify your bank to attempt to reverse the wire transfer or ACH transaction if processing is still pending—banks can sometimes halt transfers within a narrow window. Contact the FBI's IC3, your local law enforcement, and the receiving bank (if identifiable) to report the fraud and request a freeze on the account, though success rates are low once funds reach international accounts.
What systems and processes should we implement to prevent vendor impersonation scams?
Establish a mandatory dual-approval process for all new vendor payments or changes to existing vendor payment details, require verbal confirmation through verified phone numbers for any payment redirection requests, and implement email authentication systems like SPF, DKIM, and DMARC to detect spoofed vendor domains. Maintain an updated vendor master file with confirmed contact information and payment details, train your accounts payable team to recognize urgency language and inconsistencies, and conduct monthly reconciliation of vendor payments against purchase orders and receiving records.
Why are small and medium-sized businesses targeted more often than large corporations for vendor impersonation scams?
Smaller businesses typically lack the sophisticated email security filters, payment verification protocols, and multi-layer approval processes that larger enterprises use, making them easier targets for scammers. SMBs often have leaner finance teams with fewer resources to verify every payment request and less awareness training about these specific threats, combined with less complex vendor relationships that scammers can more easily research through public sources like LinkedIn and company websites. The lower average transaction values ($20,000-$150,000 versus millions) also create less suspicion and faster payment processing in smaller organizations.

Where to Report — United States

Official channels in your region for reporting this scam.

FTC ReportFraud

Reporting

Federal Trade Commission consumer fraud reporting portal.

FBI IC3

Cybercrime Unit

Internet Crime Complaint Center for online and crypto fraud.

CFPB Consumer Complaint

Financial Regulator

For bank, credit card, loan, and payment-related fraud.

AARP Fraud Watch Helpline

Hotline

Free helpline for victims of any age (English/Spanish).

Authoritative Resources

Recognized government and official anti-fraud bodies with guidance on this scam type.

Think you encountered this scam?

How to cite this guide

Use this when referencing ScamLens content in articles, research, AI responses, or social media.

According to ScamLens (scamlens.org), vendor impersonation scams: protect your business is described at https://scamlens.org/en/encyclopedia/vendor-impersonation.