Fake Suppliers: Why Verification Is Now Mandatory
Fake suppliers and manipulated invoices threaten mid-sized firms. Learn how verification and NIS2 compliance protect you effectively.

Business Email Compromise: The Invisible Enemy in the Inbox
In many medium-sized enterprises, daily communication with suppliers and service providers runs largely without friction. Orders are coordinated by email, digital invoices are received in PDF format, and released for transfer after a brief formal review. Criminals systematically exploit precisely this established routine. In Business Email Compromise (BEC), attackers do not necessarily hack your own company's IT systems, but gain access to the email accounts of your business partners. From there, they operate completely silently using a trusted address.
The threat level for the economy has reached historical proportions. According to the Economic Protection 2024 study by the digital association Bitkom, the German economy suffered a total loss of 266.6 billion euros in 2024 due to data theft, sabotage, and espionage[1]. The share directly attributable to cybercrime climbed to a record sum of 178.6 billion euros[1]. BEC attacks play a central role in these damages, as they target the weakest link in the security chain: human trust in supposedly known senders.
- CEO Fraud and Fake President Fraud: Attackers impersonate executive management and instruct accounting employees to execute urgent wire transfers.
- Supplier Compromise: Criminals take over genuine supplier email inboxes and send fraudulent payment requests during ongoing business operations.
- Thread Hijacking: Criminals insert themselves directly into existing email threads and inject altered bank details shortly before invoicing.
For managing directors and IT leaders in SMEs, this development shows that traditional perimeter protection is reaching its limits. When a malicious message originates from the genuine inbox of a long-standing partner, standard filtering systems do not trigger an alarm. The risk shifts from a purely technical level to missing verification processes in daily financial accounting.
The Anatomy of Invoice Fraud: From Phishing to the Wrong IBAN
The execution of a successful invoice fraud usually follows a precise script prepared over months. Criminals first gain access to a supplier's Microsoft 365 account via phishing emails or leaked credentials. Instead of drawing attention immediately, attackers remain extremely inconspicuous. They set up automated forwarding rules and monitor incoming emails for weeks to analyze invoice cycles, contact persons, and payment terms.
As soon as a regular invoice is sent from your supplier to your company, the attackers step in. They intercept the email, replace the bank details specified in the PDF with their own IBAN, and forward the modified message to your accounting department. Because the body text, document layout, and sender address are authentic, the forgery is not noticeable at first glance. This pattern in invoice fraud in SMEs explains the high number of incidents. In its Cybercrime National Situation Report 2023, the Federal Criminal Police Office (BKA) recorded a total of 134,407 domestic offences, 82 percent of which were classified as computer fraud[2].
- Initial Access: Infection or phishing at the supplier enables unauthorized account access.
- Silent Observation: Setting up inbox rules to analyze contracts and cash flows.
- Manipulation: Intercepting genuine PDF invoices and replacing the IBAN with an account held by money mules.
- Delivery & Payout: Sending the forged invoice via the original inbox to accounting.
Standard spam and virus filters fail against this attack vector because the emails contain neither dangerous attachments nor suspicious links. Communication takes place via legitimate servers with valid DKIM and SPF records from the supplier. Without systematic content and IBAN verification prior to release, the fraud remains invisible in the inbox.
Why Blind Trust in Partners Becomes Dangerous and Expensive
In medium-sized businesses, commercial relationships are frequently built on long-standing personal cooperation and mutual trust. Cybercriminals deliberately weaponize this social component. When an email arrives from a familiar contact, accounting employees rarely question bank detail changes with necessary skepticism. A brief note such as 'New corporate account due to bank merger' is often accepted uncritically.
The financial and operational consequences of such fraud cases are usually severe for SMEs. Once payment is made to the fraudulent bank account, the funds are instantly transferred by perpetrators via international money mules or cryptocurrencies, making them irrevocably lost. At the same time, the genuine supplier's outstanding claim remains active. The affected enterprise effectively pays the invoice twice while civil recovery attempts lead nowhere.
| Feature | Traditional Approval | Structured Verification |
|---|---|---|
| Basis of review | Visual check of invoice PDF | Automated cross-check of master data and IBAN |
| Reaction to IBAN change | Adopting new details from email body | Mandatory out-of-band phone call to partner |
| Security level | Highly vulnerable to BEC and phishing | Resistant to compromised email accounts |
Recent Bitkom data emphasizes that this threat is by no means a fringe phenomenon: 80 percent of German companies recorded an increase in cyberattacks over the past twelve months[1]. Timely detection of anomalies in documents such as forged documents and manipulated master data is therefore no longer a mere administrative task, but a core element of self-defense.
Verification as the New Norm: Processes Against Fraud
Effective protection against invoice fraud requires organizational processes that supplement pure visual invoice checks. Central to this is out-of-band verification. Whenever a supplier requests a change to bank account details or payment methods, an independent confirmation must occur via a second, established channel, such as a phone call to a known telephone number stored in master data, never using numbers provided in the request email.
In addition, automated master data matching in ERP and accounting systems creates indispensable safeguards. By verifying whether the IBAN provided matches the recipient name stored in official registers or previous transactions before authorizing payment, suspicious deviations are flagged immediately. Dual control mechanisms for payments exceeding defined thresholds further reduce vulnerability to single points of failure.
- Out-of-Band Verification: Mandatory telephone confirmation using verified contacts whenever banking details change.
- Automated IBAN-Name Matching: Software-supported cross-checking of payment details against official databases.
- Four-Eyes Principle: Dual authorization required for all transfers above established threshold values.
- Role Segregation: Clear separation between master data maintenance and payment release.
Establishing these structured verification procedures transforms fraud prevention from reactive panic management into a standardized daily workflow. Employees gain clear guidelines for handling unexpected payment adjustments without delaying routine operational settlements.
NIS2 and Supply Chain Security: Regulatory Pressure Is Rising
The imperative for rigorous supplier verification is no longer just a financial best practice, but a legal requirement. Under the NIS2 Directive (Directive (EU) 2022/2555), covered entities in critical and important sectors must implement comprehensive supply chain risk management policies. Managing directors face personal liability risks if mandatory security and verification protocols are neglected.
Because attackers exploit third-party vulnerabilities to compromise primary targets, supply chain security under NIS2 mandates strict technical and organizational oversight of vendors. Audits focus on whether companies audit vendor communication, enforce multi-factor authentication, and maintain documented verification procedures for financial transactions.
- Mandatory Vendor Audits: Evaluating vendor cybersecurity and access management practices.
- Documented Controls: Maintaining verifiable trails of verification steps for compliance audits.
- Executive Responsibility: Direct accountability of leadership for supply chain risk governance.
Reality in the mid-market, however, often lags behind these legal requirements. According to the Bitkom study, 33 percent of companies are in close contact with their suppliers to minimize risk, but only 19 percent carry out regular security assessments at their partners[3]. In addition, 37 percent admit that their own organization lacks awareness of the risks of supply chain attacks[3]. Failing to demonstrate robust partner verification exposes organizations to regulatory penalties, mandatory public disclosures, and reputational loss. Implementing standardized verification mechanisms aligns daily financial workflows with statutory NIS2 expectations.
Technological Defense: M365 Security and Security Monitoring
While procedural controls protect financial workflows, technological defense secures the underlying communication channels. Since BEC attacks frequently begin with compromised cloud environments, proactive M365 monitoring is essential. Detecting unauthorized inbox forwarding rules, unusual login locations, and mailbox manipulation in real time prevents attackers from establishing persistent footholds.
Integrating Managed IT services and continuous Cybersecurity monitoring ensures that technical anomalies are addressed before financial damage occurs. Endpoint Detection and Response (EDR) coupled with automated Security Information and Event Management (SIEM) identifies suspicious activities across email, identity, and network endpoints.
- Inbox Rule Auditing: Real-time alerts for newly created auto-forwarding or deletion rules.
- Multi-Factor Authentication (MFA): Enforcement of phishing-resistant authentication across all accounts.
- 24/7 Security Operations Center (SOC): Continuous threat detection and automated incident response.
The need for active monitoring is underlined by the figures in the BSI situation report 2024: in the reporting period from mid-2023 to mid-2024, an average of 309,000 new malware variants became known every day, an increase of 26 percent over the previous year[4]. Combining robust cloud configuration, continuous endpoint surveillance, and employee security training builds defense-in-depth. Technology and organizational vigilance must work in unison to neutralize sophisticated Business Email Compromise campaigns.
Unifying Compliance and IT Security: Resilience as the Standard
Defending against supplier fraud and Business Email Compromise requires an integrated approach where IT operations, cybersecurity, and regulatory governance reinforce each other. Fragmented solutions leave coverage gaps that attackers exploit. Unifying monitoring, endpoint security, and audit-ready documentation builds sustainable enterprise resilience.
CAVRIX provides an integrated platform tailored for German mid-sized businesses, combining Managed IT, Cybersecurity, and Compliance into a cohesive defense framework. By incorporating automated evidence collection and continuous risk monitoring, companies achieve NIS2 compliance while maintaining active defense against BEC and document manipulation.
Through the AI-native Command Center, leadership and IT teams monitor security posture, manage tasks, and receive real-time alerts directly within familiar tools like Teams or Slack. This transparent overview ensures that verification workflows, threat mitigation, and regulatory standards are seamlessly maintained across daily operations.
Frequently Asked Questions
What is Business Email Compromise (BEC)?
In Business Email Compromise, criminals do not hack your own system but the email inbox of your business partner. From that trusted account, they send manipulated invoices or payment instructions that conventional spam filters do not recognize as a threat.
How does invoice fraud using fake suppliers work?
Attackers silently monitor the email traffic of a compromised supplier. As soon as a legitimate invoice is sent, they intercept it, change the IBAN in the PDF document to their own account, and forward it to your accounting department.
Why do conventional spam filters fail against these attacks?
Because the manipulated emails originate from the supplier's genuine, legitimate mail servers, all technical security features such as SPF and DKIM records are valid. The emails also contain neither malicious links nor viruses, only an altered PDF document.
How high is the damage caused by cybercrime in SMEs?
According to a Bitkom study, the damage caused by cybercrime to the German economy amounts to 178.6 billion euros per year. Invoice manipulation and BEC cases account for a considerable share of these financial losses.
What role does the NIS2 Directive play in supplier verification?
The NIS2 Directive obliges organizations to control cybersecurity risks along their entire supply chain. Systematic verification of suppliers and their security level therefore becomes a legal obligation for many mid-sized companies.
What is the best countermeasure when an IBAN has changed?
The most effective method is strict out-of-band verification. Every change of bank details should be confirmed by phone before the transfer, using a previously known, secure number, directly with the responsible contact person at the supplier.