← SecureAZ Blog

Phishing · 8 min read · Published 7 May 2026 · Reviewed 17 August 2026

Supply Chain Phishing: When the Attack Comes Through Your Vendor

When your supplier is compromised, the phishing email arrives from a real address with a real history. Here is how supply chain phishing works and how NZ SMEs defend against it.

Supply chain phishing is the attack pattern that gets past the trained user. The email arrives from a supplier the team has corresponded with for years. The thread references a real invoice, a real project, a real conversation. The sender's address is genuine, because the supplier's mailbox is the one that has been compromised. CERT NZ has tracked steady growth in this pattern across SME victims, and the Verizon DBIR continues to flag third-party involvement in a significant portion of breaches.

This post walks through how supply chain phishing actually unfolds, why it bypasses standard defences, and the controls that stop it.

---

The Anatomy of the Attack

The pattern, repeated across hundreds of NZ SME cases:

  1. The attacker compromises a real mailbox at a supplier — an accounting firm, a sub-contractor, a managed service provider — usually through phishing or password reuse
  2. The mailbox is monitored quietly for weeks. Invoice cycles, project milestones, and conversational style are observed
  3. When an invoice is due, the attacker either replies in-thread with new banking details, or sends a fresh invoice from the genuine address
  4. The customer pays. The supplier and customer often do not realise for days or weeks until reconciliation
  5. The funds are gone, having moved through multiple accounts within hours

The compromised mailbox may also be used to launch attacks against the supplier's other customers, multiplying the damage. This is how many of the more material NZ business email compromise cases have unfolded over the past two years. The general BEC pattern is covered in Business Email Compromise NZ.

Why Standard Defences Miss It

The reasons this attack lands when others do not:

  • The sender address is genuine, so SPF, DKIM, and DMARC pass
  • The thread history is real, so the email looks legitimate to any human review
  • The writing style matches because the attacker has been reading for weeks
  • There is no urgency tactic — the timing aligns with the genuine invoice cycle
  • Anti-phishing tools that flag unfamiliar senders see a familiar one

The defence has to assume that one or more supplier mailboxes will be compromised at some point. The question is what the customer-side controls do when that happens.

The Customer-Side Controls That Work

Three controls do most of the work:

Out-of-band verification of banking changes. Any change to supplier bank details is verified by a phone call to a known supplier contact on a known number. Not the number in the email signature. Not a number provided in the new invoice. The verification has to happen before the next payment, every time. This single control stops the majority of cases.

Master supplier records. Supplier banking details are stored in a master record that requires dual authorisation to change. Invoices are paid against the master record, not against the bank details on the invoice itself. A change request triggers verification before the master is updated.

Beneficiary cooling-off. New beneficiaries added in the banking platform wait 24 hours before the first payment can be released. This window catches the cases where verification was skipped or rushed.

These controls are simple and not expensive. They depend on policy discipline more than technology.

Detecting a Supplier Compromise Early

Even with strong customer-side controls, early detection of a supplier compromise reduces damage:

  • Anomaly monitoring on supplier email — unexpected changes in writing style, unusual login locations on the supplier's tenant
  • Encouragement of suppliers to enable MFA and report suspicious activity
  • Periodic review of the supplier register's contact details — does what we have on file match what the supplier publishes?
  • Customer communications that explicitly invite the supplier to flag any concern about a sent email

A supplier who suspects mailbox compromise is more likely to notify the customer if there is an existing channel for it. Most do not because they do not know who to call.

The Other Side — Protecting Your Own Mailbox

The customer's own mailbox can become the upstream supplier mailbox in someone else's attack. The same controls protect both directions:

  • MFA on every staff mailbox, with passkeys preferred where supported
  • Conditional access policies blocking unusual sign-in patterns
  • Email rule auditing — attackers commonly create forwarding rules to monitor or hide replies
  • Sender-side DMARC enforcement
  • Quick offboarding of departed staff to remove dormant credentials
  • Staff training on credential phishing — most mailbox compromises start with a credential capture

The credential capture pathway is detailed in phishing training for employees and the broader awareness programme model.

Cyber Insurance Considerations

Cyber insurance policies frequently exclude or limit cover for supply chain phishing claims if the customer's controls were insufficient. The clauses to read carefully:

  • Whether out-of-band verification is required for cover
  • Whether MFA on the customer's own mailbox is a precondition
  • Whether the policy covers funds transferred to genuine supplier-impersonating addresses
  • Whether sub-limits apply to BEC and social engineering claims

Customers with mature controls should be able to evidence them at renewal — both for cover and often for premium reduction.

Incident Response Window

If a fraudulent payment is identified:

  1. Call the bank within minutes — funds in transit can sometimes be recalled
  2. Notify NZ Police, CERT NZ, and the supplier
  3. Preserve all email evidence, including headers and any attachments
  4. Notify the cyber insurer within the policy notification window
  5. Audit the supplier's other recent communications for further compromise
  6. Review the company's own systems for any related compromise

The first hours matter. Recovery rates fall sharply once funds have moved beyond the first receiving account.

Practical Takeaway

  1. Mandate out-of-band verification for every change of supplier bank details
  2. Maintain master supplier records with dual authorisation for changes
  3. Apply a cooling-off period on first payments to new beneficiaries
  4. Train finance and AP teams specifically on supplier impersonation patterns
  5. Strengthen your own mailbox security — MFA, passkeys, conditional access
  6. Audit your supplier register annually for stale contact details
  7. Review your cyber insurance for BEC and social engineering cover
  8. Document the response process for a suspected fraudulent transfer

Start your free SecureAZ trial to train your finance team on supply chain phishing, run targeted simulations, and harden the controls that stop the wire transfer.

External references: