Business Email Compromise (BEC) and Vendor Email Compromise (VEC) have emerged as significant threats to organizations, leveraging trusted relationships and sophisticated deception techniques to achieve financial and data theft. Attackers frequently gain unauthorized access to email accounts, often by compromising credentials or exploiting third-party vendors, and then use this access to monitor communications, create forwarding rules, and gather sensitive information. Once inside, adversaries may spend weeks or months surveilling email traffic, collecting intelligence on business processes, financial transactions, and supply chain relationships. This information is then weaponized to craft convincing fraudulent emails, such as fake invoices or requests to change bank account details, which are sent to employees or partners who are unlikely to question messages from familiar contacts. The use of AI-driven language models allows attackers to mimic the tone and style of legitimate correspondents, making detection by both humans and traditional secure email gateways (SEGs) challenging. Malicious content is often delivered via reputable file-sharing services, further reducing suspicion. Organizations that lack proper audit logging, such as Unified Audit Logging (UAL) in Microsoft Exchange environments, may be unable to determine which emails were accessed or what data was exfiltrated, hampering incident response and remediation efforts. Security teams are advised to ensure that audit logging is enabled and to regularly review configurations to support forensic investigations. Advanced detection tools, such as Darktrace / EMAIL, have demonstrated the ability to identify subtle anomalies in email behavior, flagging out-of-character messages even when they originate from trusted vendors. In one documented case, Darktrace detected four separate vendor compromise campaigns targeting a single customer within a two-week period, highlighting the prevalence and persistence of these attacks. The impact of BEC and VEC incidents can be severe, resulting in direct financial losses, reputational harm, and exposure of sensitive corporate data. Attackers may also use compromised information to launch further phishing campaigns or to infiltrate additional organizations within the supply chain. Effective defense requires a combination of technical controls, such as AI-powered anomaly detection, and procedural measures, including employee training and robust incident response planning. Organizations are encouraged to treat ongoing conversations with vendors and partners with appropriate scrutiny, especially when financial transactions or sensitive data are involved. Regular reviews of email security configurations and proactive monitoring for suspicious activity are essential to mitigate the risks posed by these evolving threats. The growing sophistication of BEC and VEC attacks underscores the need for continuous improvement in both technology and user awareness to protect organizational assets and relationships.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Initial story creation
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.