Vendor Impersonation: 3 Ways Criminals Get Paid Without Hacking Anything

What is vendor impersonation, and why do small businesses keep paying these invoices? Vendor impersonation is when an attacker emails you pretending to be a supplier, a contractor, or an executive your team already trusts, usually carrying an invoice or a request to update payment details. It works because nothing gets hacked. One believable email, one busy employee, one payment sent to the wrong bank account. The whole thing happens in normal daylight, inside your normal process.

The quick version:

  • Vendor impersonation is a form of business email compromise. It needs no malware. It needs one believable email.
  • These attacks spike in summer, when the person who normally approves payments is out and a stand-in is covering.
  • The fix that stops most of them is free: call the vendor back on a number you already had, never the one printed in the email.
  • Phishing targets distracted people, not careless ones. Culture beats software on this one.
  • Every vendor with system access is another door into your business. Very few owners have ever counted them.

I have spent 25 years in technology, and I built Entech into a team. What that time taught me is that the dangerous stuff almost never looks dangerous. On the surface, the water is calm. That is what makes those summer shark documentaries so watchable. The danger is never visible on top. It is already moving underneath. Cybercriminals work the same way, blending in with normal operations until money moves or systems go down. Here are the three that are circling small businesses in the Wiregrass right now.

What does vendor impersonation actually look like?

It rarely looks like an attack. That is the entire design. A vendor you have paid for years sends an invoice for an amount that sounds about right, on letterhead you recognize, from a person whose name is already sitting in your inbox history. The only thing different is one line near the bottom: updated remittance details, new bank, new routing number, effective immediately. Somebody in accounting reads that line, shrugs, and updates the record. No malware. No alarm. No forced entry. A fake invoice does not look like a crime. It looks like Tuesday.

Sometimes the attacker has already been sitting quietly inside a real mailbox for weeks, reading actual threads, learning how your people talk, waiting for a genuine invoice to reference. That patience is the part owners underestimate. By the time anyone realizes the request was never legitimate, the money has moved through two accounts and it is gone. Here is the uncomfortable part. The email that costs a business the most is almost always the one that looked the most ordinary.

Why vendor impersonation spikes when your people are out

Summer schedules do a specific kind of damage, and attackers count on it. The person who normally approves payments is at the beach. The office manager who would have squinted at that bank change is out for a week with the grandkids. The request gets rerouted to a stand-in who has done this three times total and does not yet know what normal looks like. That is the whole opening.

A temporary approver is far less likely to push back on urgency, because pushing back feels like being the new person who slows everything down. Attackers know your calendar as well as you do. They also know that your out-of-office replies tell them exactly who is gone, exactly how long, and exactly who is covering. That is free reconnaissance and your own email server hands it over politely.

Here in Dothan and Enterprise I watch the same rhythm every year. June through August, oversight thins out, inboxes stay just as full, and nobody is watching the things they watched in March. Then a payment goes out to an account nobody verified. The attack was not sophisticated. The timing was.

The call-back rule that stops most of this for free

Here is the fix, and it costs you nothing but a meeting. Any request to change payment details, add a new vendor, or move money gets confirmed by voice, on a number you already had before that email arrived. Not the number in the signature block. Not the number printed on the invoice. The number in the email is theirs. Pull it from your own records, your signed contract, or the vendor portal your team has logged into a hundred times, and call that.

Write it down as a rule, not a preference. A preference bends under pressure and a rule does not. Then give your team explicit permission to use it, especially your newest people, because the person least likely to question a rushed payment request is the one most worried about looking slow.

If somebody in accounts payable calls a vendor to verify a bank change and it turns out to be perfectly legitimate, that is not wasted time. That is the process working. The cost of one slightly awkward phone call is about two minutes. The cost of skipping it is a wire transfer you will never see again.

Phishing works because your people are busy, not careless

Phishing is engineered around how people behave when they are moving fast. It is not a test of intelligence. It is a test of attention, and attention is the thing your team has least of at four o’clock on a Thursday. A distracted employee sees a password reset notification and clicks it. Somebody gets a text that looks like it came from IT. An email lands two minutes before a meeting asking for urgent approval on a wire transfer. Nobody stops to verify, because stopping feels like losing time.

The most effective protection here is not a piece of software. It is culture. Your people need to feel genuinely safe slowing down when something feels off: an unexpected login request, a payment instruction that came out of nowhere, a link in an email nobody was expecting. Speed is the weapon being used against you, so slowing down is how you take it away from them.

Turning on multi-factor authentication closes the door on stolen passwords, and it is worth doing. But no login setting catches an employee who was politely tricked into paying the wrong person. That part is security awareness training, repetition, and a team that has been told out loud that asking is fine.

Which of your vendors can still get in?

Vendor access behaves like a door code you handed out once and never changed. Your line-of-business software has a standing support account. Your copier company has remote access to a machine sitting on your network. Your payroll provider holds credentials. The contractor who wired the new office two years ago still has a VPN account nobody disabled, because the project ended and disabling it was never on anybody’s list. None of that was meant to be permanent. All of it still works this morning.

When one of those vendors gets compromised, the problem does not politely stay with them. It travels straight into your environment through whatever connection they already have. That is supply chain exposure, and most small businesses carry more of it than they realize. Outsourcing a service does not outsource accountability.

Knowing where you actually stand means being able to answer three plain questions. Which vendors can reach your data or your systems? What exactly are they connected to? Who inside your business owns that relationship? If you cannot answer all three today, that is not a failure. It is an unmapped room, and mapping it is ordinary work a managed IT partner does with you in an afternoon.

By the time you see it, it is already moving

Sharks do not announce themselves, and neither do the people running these invoice scams. The businesses that get hit are usually not the ones ignoring obvious warning signs. They are the ones who assumed everything was fine because nothing looked wrong. Calm water is not evidence of safety. It is just calm water.

Here is your two-step. Start with the free one, this week, before you close this page. Write down a call-back rule for payment changes. Tell your team about it out loud. Then put the vendor phone numbers you actually trust somewhere your accounts payable person can reach without opening an email. That costs you one short meeting and it protects real money.

Then call us about the part you cannot settle in a meeting: which of your vendors can still get in. Schedule a free 10-minute IT assessment with someone at Entech who will actually pick up the phone. We are based in Dothan, and we work with owners across Southeast Alabama, Southwest Georgia, and the Florida panhandle. Ten minutes is not a sales pitch. It is a look under the surface, which is the only place any of this has ever happened.