Detecting BEC Through a Compromised Vendor Domain

A business email compromise (BEC) attack does not always come from a fake address. In a more difficult scenario, criminals gain access to a genuine supplier’s mailbox or email system, then use the vendor’s real domain to request payments, redirect invoices or collect sensitive information.

This makes the message appear trustworthy at first glance. The sender may pass SPF, DKIM and DMARC checks, use an existing email thread and know details about a current project. For Australian businesses, the request might mention an ABN, an AUD payment, a BSB and account number, or a familiar purchase order.

The key is to assess the whole transaction rather than relying on the domain name alone. A trusted domain can still be operated by an attacker, and a technically authenticated message can still contain a fraudulent request.

Understand How The Attack Works

Criminals commonly compromise a supplier’s Microsoft 365 or Google Workspace account through stolen passwords, phishing or inadequate multi-factor authentication. They monitor conversations quietly, learn who approves invoices and wait for a payment milestone before acting.

The attacker may reply within a genuine thread with a believable explanation: a bank audit, an updated accounts team, a change in banking provider or an urgent settlement before an Australian public holiday. Because the message originates from the vendor’s actual domain, ordinary allowlists and reputation checks may not raise an alert.

Some campaigns create a new mailbox at the compromised organisation, while others take over an existing employee account. Watch for subtle changes in writing style, unusual sending times, unexpected pressure and requests that bypass the supplier’s established payment process.

Check The Message Beyond The Display Name

Inspect the complete sender address, Reply-To field and received headers. A display name such as “Accounts Payable” can hide an unrelated address, while a Reply-To value pointing to a personal mailbox is a strong warning sign. Check whether the email was sent through the vendor’s normal mail infrastructure and whether the message chain contains unexplained forwarding.

Authentication results provide useful evidence, but they do not prove that the request is safe. SPF confirms an authorised sending server, DKIM verifies a signed message and DMARC checks alignment with the visible domain. If a compromised account sends the email through the proper system, all three may pass.

Use sender trust checks to review domain reputation and authentication signals, then compare the result with previous legitimate messages. A sudden change in sending hosts, country, encryption pattern or domain configuration deserves investigation, especially when the email concerns money.

Verify Payment Changes Independently

Never confirm new bank details solely by replying to the email. Call the supplier using a number already held in your accounting system, on a signed contract or on the organisation’s official website. Do not use a phone number or link supplied in the suspicious message.

Australian finance teams should match the account name, BSB, account number, ABN, purchase order and GST details against existing records. A request to pay an invoice to a different state, an overseas account or an account with a mismatched business name should pause the transaction.

For large payments, use two-person approval and a known contact who is separate from the email conversation. If the supplier says the change is urgent, treat that urgency as a reason to slow down. A quick call to a Melbourne warehouse, Sydney office or regular account manager can prevent a costly transfer.

Investigate The Vendor’s Domain

Contact the supplier’s security or IT team through an independent channel and ask whether the account was compromised. They should review sign-in logs, mailbox rules, forwarding settings, OAuth applications and recent password or MFA changes. Attackers often create hidden forwarding rules so they can continue monitoring the conversation after access is restored.

Domain administrators can also check DNS records and mail configuration for unexpected changes. Reviewing DMARC policy, DKIM selectors and authorised senders helps establish whether the vendor’s infrastructure has changed recently. Teams responsible for multiple suppliers may use domain admin access to manage monitoring and verification more consistently.

If your organisation may have been involved in the exchange, preserve the original email with full headers, payment records and chat messages. Report suspected fraud promptly to your bank and relevant Australian authorities, including ReportCyber where appropriate. Speed matters if funds have already been transferred.

Separate Technical Trust From Business Trust

A domain reputation check answers a technical question: is this domain associated with suspicious sending behaviour or authentication problems? It does not answer the business question: is this person authorised to change payment instructions?

Security teams should combine email authentication with transaction controls, supplier call-back procedures and staff training. A review of your own domain can also reveal whether internal accounts, forwarding rules or DNS settings have been abused as part of the same campaign.

Signal What it may show Appropriate response
SPF, DKIM and DMARC pass The message was sent through an authorised, aligned system Continue with independent business verification
New bank details in a familiar thread A compromised vendor account or hijacked conversation Stop payment and call a known supplier contact
Reply-To differs from the sender Possible routing to an attacker-controlled mailbox Inspect headers and avoid replying
Urgent request involving AUD, BSB or ABN changes Social engineering aimed at accounts staff Require dual approval and call-back confirmation
New forwarding rule or unfamiliar login Possible mailbox compromise Revoke access, reset credentials and preserve evidence