Verizon's 2026 DBIR: 48% of breaches involved a third party, up from 30% the year before.
In email, one of the nastiest versions of that is vendor email compromise. The attacker is inside a real supplier's mailbox, replying on real threads, from the real domain.
Which means SPF, DKIM and DMARC can all pass. Because it IS the real domain.
Authentication answers "did this come from that domain?" It can't answer "is the person at that domain who they say they are?"
So the investigation shifts:
- Thread history: does this request fit the conversation?
- Reply-to and routing changes
- Payment detail changes, always
- A phone call to a number you already had, not the one in the email
Passing authentication is evidence. It is not innocence.