New Vendor Email Compromise Attack Seeks $36 Million

April 8, 2023

The new season is a great reason to make and keep resolutions. Whether it’s eating right or cleaning out the garage, here are some tips for making and keeping resolutions.

The details in this thwarted VEC attack demonstrate how the use of just a few key details can both establish credibility and indicate the entire thing is a scam.

It’s not every day you hear about a purely social engineering-based scam taking place that is looking to run away with tens of millions of dollars. But, according to security researchers at Abnormal Security, cybercriminals are becoming brazen and are taking their shots at very large prizes.


This attack begins with a case of VEC – where a domain is impersonated. In the case of this attack, the impersonated vendor’s domain (which had a .com top level domain) was replaced with a matching .cam domain (.cam domains are supposedly used for photography enthusiasts, but there’s the now-obvious problem with it looking very much like .com to the cursory glance).


The email attaches a legitimate-looking payoff letter complete with loan details:


 

According to Abnormal Security, nearly every aspect of the request looked legitimate. The telltale signs primarily revolved around the use of the lookalike domain, but there were other grammatical mistakes (that can easily be addressed by using an online grammar service or ChatGPT).


This attack was identified well before it caused any damage, but the social engineering tactics leveraged were nearly enough to make this attack successful. Security solutions will help stop most attacks, but for those that make it past scanners, the user needs to play a role in spotting and stopping BEC, VEC and phishing attacks themselves – something taught through continual Security Awareness Training.


Source: Abnormal Security, KnoweBe4 Cyberheist Blog

Business team using Microsoft Copilot Chat with managed IT support
By Michael Emdy September 20, 2025
Discover why Microsoft Copilot Chat is safer than public AI tools. Massive IT delivers full lifecycle planning, implementation, and ongoing support.
Defense contractor achieves NIST 800-171 compliance with Microsoft 365 GCC-High
By Michael Emdy August 4, 2025
A defense contractor used Microsoft 365 GCC-High to meet NIST 800-171 requirements in just three weeks, securing a Fortune 500 contract and strengthening cybersecurity.
Cannabis company improves compliance and efficiency with Dynamics 365 Business Central
By Michael Emdy July 7, 2025
A cannabis company unified compliance, inventory, and financial management with Microsoft Dynamics 365 Business Central, improving visibility and operational efficiency.
Illustration of Microsoft Authenticator app with a lock icon and a calendar showing August 2025
By Michael Emdy June 1, 2025
Microsoft is removing the password autofill feature from the Authenticator app by August 2025. Learn key dates, how to export your saved credentials, and how to transition to Microsoft Edge for password management.
By Michael Emdy May 5, 2025
Maximizing Microsoft 365 Copilot While Mitigating Oversharing Risks
Manufacturer improves efficiency and visibility with Dynamics 365 Business Central
By Michael Emdy April 18, 2025
A manufacturer improved financial visibility, production planning, and supply chain management by unifying operations with Microsoft Dynamics 365 Business Central.
City government improves efficiency and citizen services with Dynamics 365 Business Central
By Michael Emdy March 20, 2025
A city government modernized its operations with Microsoft Dynamics 365 Business Central, improving efficiency, transparency, and delivery of citizen services.
Microsoft office lobby – A modern, welcoming space reflecting Microsoft’s innovation.
By Michael Emdy March 3, 2025
Microsoft is updating pricing and billing for Microsoft 365, Teams Phone, and Power BI subscriptions effective April 1, 2025. Learn about the 5% price increase for monthly billing, new Copilot options, and how to prepare for these changes.
By Michael Emdy February 5, 2025
Dynamics 365 Industry Training Series with Massive IT
By Michael Emdy February 3, 2025
Dynamics 365 Industry Training Series with Massive IT