Back to threat intel
Email

Business email compromise in Nordic supply chains

SBS Identity Team22 July 20267 min read

The most expensive email your finance team receives may come from a perfectly legitimate supplier address — one that an attacker quietly controls. Business email compromise in supply chains is patient, well-researched and hard to spot without the right controls.

Starting upstream

The attacker compromises a smaller supplier with weaker controls, then reads months of genuine invoice correspondence before acting.

When they strike, the fraudulent invoice matches the supplier's real formatting, tone and timing — because it is sent from the real account.

The payment-diversion kill chain

A single altered bank detail, introduced in a thread that already has trust, is all it takes.

Follow-up messages reinforce urgency and discourage the out-of-band verification that would expose the change.

Controls that work

Verify any change of bank details through a known, previously established phone number — never one supplied in the email.

Flag inbound mail where reply-to or bank details differ from historical norms.

Key takeaways

  • Your supplier's inbox is part of your attack surface.
  • Always verify bank-detail changes out-of-band, on a known number.
  • Alert on deviations from a counterparty's historical patterns.