Business email compromise in Nordic supply chains
SBS Identity Team22 July 20267 min read
The most expensive email your finance team receives may come from a perfectly legitimate supplier address — one that an attacker quietly controls. Business email compromise in supply chains is patient, well-researched and hard to spot without the right controls.
Starting upstream
The attacker compromises a smaller supplier with weaker controls, then reads months of genuine invoice correspondence before acting.
When they strike, the fraudulent invoice matches the supplier's real formatting, tone and timing — because it is sent from the real account.
The payment-diversion kill chain
A single altered bank detail, introduced in a thread that already has trust, is all it takes.
Follow-up messages reinforce urgency and discourage the out-of-band verification that would expose the change.
Controls that work
Verify any change of bank details through a known, previously established phone number — never one supplied in the email.
Flag inbound mail where reply-to or bank details differ from historical norms.
Key takeaways
- Your supplier's inbox is part of your attack surface.
- Always verify bank-detail changes out-of-band, on a known number.
- Alert on deviations from a counterparty's historical patterns.
