← All posts post

When the Real Vendor Is the Attacker

Third-Party RiskOctober 2026 · 1 min read

Verizon's 2026 DBIR: 48% of breaches involved a third party, up from 30% the year before.

In email, one of the nastiest versions of that is vendor email compromise. The attacker is inside a real supplier's mailbox, replying on real threads, from the real domain.

Which means SPF, DKIM and DMARC can all pass. Because it IS the real domain.

Authentication answers "did this come from that domain?" It can't answer "is the person at that domain who they say they are?"

So the investigation shifts:

  • Thread history: does this request fit the conversation?
  • Reply-to and routing changes
  • Payment detail changes, always
  • A phone call to a number you already had, not the one in the email

Passing authentication is evidence. It is not innocence.

Sources

  1. Verizon 2026 Data Breach Investigations Report
  2. eSecurity Planet coverage