Skip to main content
ITSIGNSolutions
Email Security

When the phish comes from a vendor you trust

Their tenant, your payment. Callback still wins. So does knowing who is allowed to change details.

ITSIGN Administrator · October 22, 2025 · 2 min read

PhishingBecVendors

You cannot MFA a supplier. You can refuse to change bank details from email alone. You can keep a vendor register with a known phone number.

When a long-standing plumber's "bookkeeper" writes from a new domain, that is the test.

Train AP with security awareness. Review vendor risk in GRC.

Want this applied to your environment?

A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.