What Happened?
An organisation had been working with a trusted supplier for several months, receiving invoices regularly, when another payment came due.
A finance employee received an email — apparently from the supplier — advising that its banking details had changed, with an updated invoice attached. The supplier name, invoice number and amount were all correct, and the message appeared inside an existing conversation thread.
Before paying, the employee independently called the supplier using the phone number already held on file. The supplier confirmed its banking details had not changed — its email account had been compromised, and a criminal had been monitoring the mailbox, waiting for a chance to redirect a legitimate payment. The independent call stopped the payment being sent to the fraudulent account.
Where Was the Supplier Risk?
The risk wasn't a fraudulent supplier slipping through onboarding — the organisation had a genuine, months-long relationship with a legitimate, already-verified supplier.
The vulnerability arose because criminals had inserted themselves into that trusted relationship, by compromising the supplier's email account and waiting for a real invoice cycle to intercept.
Verification completed at onboarding doesn't extend indefinitely: bank-account changes, ownership changes, contact changes and other material alterations create new risk events across the supplier lifecycle. Here, the apparent bank-detail change was the risk event — arising months after onboarding, not at it.
What Went Wrong?
Nothing went wrong at the point of decision — but the near-miss shows how thin the margin was. The compromised mailbox produced a request carrying every visible signal of legitimacy: correct supplier name, correct invoice number and amount, and a message sitting inside an existing conversation thread.
Had the employee simply accepted the updated invoice, or verified by replying to that same email account, the payment would very likely have been redirected. The channel that delivered the request was also the channel that had been compromised, so it could not be used to validate what it had just delivered.
The safeguard that caught this attempt — an independent phone call to a number already held on file — worked because it existed at all. The broader lesson is that businesses need a defined, independent verification process for material supplier changes, rather than a reliance on an individual employee's instinct to double-check.
What Should Businesses Do?
Make independent verification mandatory, not discretionary
This payment was protected because one employee chose to call before paying. Don't depend on individual initiative — build a defined, required verification step into the process for any change to supplier bank details.
Never verify through the channel that delivered the request
A reply to the same email thread, or a call to a number in the email signature, verifies nothing if that channel is compromised. Use contact details already held on file, not ones supplied with the change request.
Treat a long, trusted relationship as no guarantee
Months of legitimate invoices didn't make this request trustworthy. A supplier's history reduces the likelihood of fraud at onboarding — it says nothing about whether a specific instruction, months later, is genuine.
Re-verify at every material change, not just once
Bank detail changes, ownership changes and contact changes are each a new risk event in the supplier lifecycle. Re-verification belongs at the moment of change, not only at initial approval.
The ArayaPRO Response
How ArayaPRO Helps
This is exactly the type of supplier risk ArayaPRO is built to control.
Further Reading
