Loading Glossary...
Vendor Impersonation Fraud
Shweta Karve
August 6, 2026
Vendor impersonation fraud is a form of business email compromise in which an attacker poses as a trusted supplier to redirect payments, steal funds, or change bank account details. It relies on fake emails, forged invoices, and social engineering rather than hacking. It was the most common tactic behind business email compromise scams in 2024. (2025 AFP Payments Fraud and Control Survey)
Accounts payable teams rarely catch this at the point of failure. They catch it when the real vendor calls asking why an invoice went unpaid, or when a bank flags an account change that was never verified through a known channel. By then the wire has already gone out, often to an account that closes within days, and the recovery rate for that kind of loss keeps getting worse year over year.
Key Facts
- Vendor impersonation was cited by 60% of organizations hit by BEC scams in 2024, up 11 points from 45% in the prior year. (2025 AFP Payments Fraud and Control Survey)
- Third-party and vendor impersonation is the single most frequent BEC scam type, ahead of executive impersonation. (2025 AFP Payments Fraud and Control Survey)
- 79% of organizations experienced attempted or actual payments fraud in 2024. (2025 AFP Payments Fraud and Control Survey)
- Only 22% of organizations recovered 75% or more of funds lost to payments fraud in 2024, down from 41% in 2023. (2025 AFP Payments Fraud and Control Survey)
TL;DR
- Vendor impersonation fraud is a BEC scheme where an attacker poses as a trusted supplier to redirect payments.
- It relies on fake emails, forged invoices, and social engineering, not system intrusion.
- It overtook executive impersonation as the leading BEC tactic in the 2025 AFP survey.
- Attackers most often push a bank-detail change disguised as a routine vendor update.
- Recovery rates for funds lost to this fraud have fallen two years running.
- Callback verification through a known number and dual approval on bank-detail changes are the two controls that stop it.
What Is Vendor Impersonation Fraud?
Vendor impersonation fraud occurs when a fraudster impersonates a trusted supplier, contractor, reseller, or service provider to trick an organization into sending money, changing payment details, or sharing sensitive information. It is a subtype of business email compromise, distinguished from other BEC scams by who the attacker pretends to be: a supplier the target already trusts and already pays, not a colleague or executive.
Put simply: the fraud doesn’t need to break into a system. It only needs the finance team to believe the request came from someone it already does business with.
It typically shows up in three forms:
- Spoofed or lookalike vendor domains sending invoices that closely mimic real ones in logo, formatting, and invoice numbering
- Compromised vendor email accounts used to send genuinely-originated messages requesting a bank-detail change
- Urgent, time-pressured requests to update wire or ACH instructions ahead of a real payment due date
How Vendor Impersonation Fraud Works
The mechanism relies on trust already established between the organization and a real vendor.
- Attacker researches a real vendor relationship, often from a data breach, a compromised inbox, or public invoices.
- Attacker sends a message that looks like it’s from that vendor, requesting updated payment or bank details.
- The message applies urgency: a payment is overdue, an account is under review, action is needed today.
- If nobody performs independent verification, AP updates the vendor master file and processes the next payment against the fraudulent account. See vendor reconciliation for where this normally gets caught, if it gets caught at all.
- The fraud surfaces when the real vendor follows up on a missing payment, by which point the funds have usually left the fraudulent account.
Vendor Impersonation Fraud vs Executive Impersonation Fraud
| Vendor Impersonation Fraud | Executive Impersonation Fraud | |
| Who the attacker poses as | A trusted supplier or vendor | A senior executive, often the CEO or CFO |
| Typical ask | Update bank details or pay a fraudulent invoice | Urgent wire transfer, often framed as confidential |
| 2024-25 trend | Up 11 points, now the leading BEC tactic | Down 8 points as fraudsters shift tactics |
| Best control | Callback verification via a known vendor number | Out-of-band confirmation before any urgent wire |
Both are business email compromise. The shift toward vendor impersonation matters operationally: it means AP teams, not just executive assistants, are now the primary target. See KlearStack’s document fraud detection coverage for how forged or altered vendor documents get caught before payment.
Why Vendor Impersonation Fraud Matters for AP and Finance Teams
For accounts payable and treasury teams, this exposure shows up in four places:
- Direct financial loss, often unrecoverable once funds clear a fraudulent account
- Vendor relationship damage when a real supplier goes unpaid while the fraud is investigated
- Audit and compliance findings when bank-detail changes bypass a documented verification step
- Cycle-time tradeoffs, since manual callback verification on every change request slows legitimate updates too
Vendor Impersonation Fraud Benchmarks
Vendor impersonation’s share of BEC incidents rose from 45% to 60% of organizations surveyed between the 2024 and 2025 AFP reports, an 11-point jump in a single year. Over the same period, the share of organizations able to recover most of what they lost fell from 41% to 22%. Read together, the two numbers describe a fraud type that is both growing faster and getting harder to reverse once it succeeds.
- 60% of organizations hit by BEC in 2024 report vendor impersonation specifically. (2025 AFP Payments Fraud and Control Survey)
- 79% of organizations faced attempted or actual payments fraud of any type in 2024. (2025 AFP Payments Fraud and Control Survey)
- 22% recovered 75%+ of losses in 2024, down from 41% in 2023, a 19-point drop. (2025 AFP Payments Fraud and Control Survey)
Recovery odds on this fraud dropped 19 points in a year. Talk to us about catching it before the wire goes out.
Common Mistakes and Limitations
- Verifying a bank-detail change using the phone number or email in the request itself, instead of a number already on file
- Treating a familiar vendor name, logo, and invoice format as proof of authenticity
- Allowing a single approver to both receive the change request and process the payment
- Skipping verification on small-dollar invoices, which attackers use to test a compromised process before a larger request
- Assuming email authentication (SPF, DKIM, DMARC) alone stops it, when a compromised real vendor account passes all three
Real-World Example
A mid-size manufacturing supplier’s AP team received an email that appeared to come from a long-standing logistics vendor, requesting an update to ACH routing details ahead of a routine monthly payment. The message used the vendor’s real letterhead and referenced an actual outstanding invoice number.
Because the change request went through the standard vendor master update process without a callback to a previously verified contact, the next payment cycle sent funds to the fraudulent account. The scheme surfaced two weeks later when the legitimate vendor followed up on a missing payment. (Pattern consistent with the 2025 AFP Payments Fraud and Control Survey’s description of vendor impersonation as the leading BEC tactic.)
If your AP team verifies bank-detail changes over email instead of a known phone line, you already know which step gets skipped under deadline pressure. Let’s fix it.
Conclusion
Vendor impersonation fraud succeeds because it targets a relationship the organization already trusts, not a system it has to break into. A forged invoice with the right logo and the right invoice number gets past a distracted reviewer far more easily than malware gets past a firewall, and the 2025 AFP data shows attackers know it: vendor impersonation has overtaken executive impersonation as the default BEC tactic in just one survey cycle.
The controls that stop it are procedural, not technical. Callback verification through a number the organization already has on file, dual approval on any bank-detail change, and treating urgency itself as a red flag close most of the gap. Organizations still verifying vendor changes through the same channel the request arrived on are the ones showing up in next year’s recovery-rate statistics.
Frequently Asked Questions
What is vendor impersonation fraud?
It is a business email compromise scheme where a fraudster poses as a trusted supplier to trick an organization into redirecting payments, updating bank details, or sharing sensitive information, using fake emails and forged invoices rather than system hacking.
How common is vendor impersonation fraud compared to other BEC scams?
It is now the most frequent BEC tactic. The 2025 AFP Payments Fraud and Control Survey found 60% of organizations hit by BEC in 2024 reported vendor impersonation specifically, up from 45% the year before.
What’s the difference between vendor impersonation and invoice fraud?
Vendor impersonation is about who the attacker pretends to be. Invoice fraud is broader and covers any fraudulent or fabricated invoice, whether or not it involves impersonating a real vendor relationship.
How can accounts payable teams verify a vendor bank-detail change is legitimate?
Call the vendor using a phone number already on file, never one listed in the change request itself, and require a second approver before the vendor master record is updated.
Can email authentication protocols like DMARC stop vendor impersonation fraud?
Only partially. They help block spoofed domains, but they do nothing when the attacker has compromised the real vendor’s actual email account, which passes every authentication check