Short answer. Manufacturing is the #1 industry targeted by Business Email Compromise (BEC) attacks, with annual US losses exceeding $2 billion. The dominant attack vector is vendor email compromise — a cybercriminal impersonates or hijacks a supplier's email and sends a fake invoice with updated banking details. The buyer pays the invoice, often six figures, before discovering the change was fraudulent. The single most effective control is a 60-second phone call to verify banking changes using a previously known phone number. Additional controls: multi-factor authentication, vendor portal verification, segregation of duties on payments, cyber insurance, and incident response planning. Ransomware is the second major threat, with manufacturing increasingly targeted because downtime is highly visible and costly.
Managing Supply Chain & Email Cyber Security Risks in Digital Manufacturing Procurement
A working guide to the cybersecurity risks that hit manufacturing procurement hardest — and the practical controls that prevent six-figure losses.
The cybersecurity threat landscape for manufacturing
Manufacturing is the #1 industry targeted by Business Email Compromise (BEC) attacks in the United States, accounting for approximately 25% of all reported BEC losses. Total US manufacturing losses from cybercrime exceeded $50 billion in 2024, with BEC and ransomware responsible for the majority.
The reason manufacturing is targeted is economic:
High-value transactions: Manufacturing invoices are typically $10,000-$1M+, much larger than consumer transactions. A single successful attack yields significant payoff.
Time pressure: Production schedules depend on materials arriving on time. Procurement officers are motivated to pay invoices quickly, reducing scrutiny.
Long supply chains: Manufacturing involves 50-200+ vendors per facility, providing many entry points for attackers.
Email-centric communication: Despite EDI and procurement portals, email remains the primary communication channel for vendor management.
Lower cybersecurity maturity: Manufacturing IT has historically been less sophisticated than financial services, making it an easier target.
The five most common attack types
| Attack type | Frequency | Typical loss per incident | Annual industry loss (US) |
|---|---|---|---|
| Business Email Compromise (BEC) | Very high | $50,000-$1,000,000 | $2+ billion |
| Ransomware (encryption + data theft) | High | $500,000-$50,000,000 (incl. downtime) | $20+ billion |
| Supply chain / vendor compromise | Medium | $100,000-$10,000,000 | $5+ billion |
| Phishing / credential theft | Very high (but lower individual loss) | $5,000-$500,000 | $3+ billion |
| Data theft / IP exfiltration | Medium | $100,000-$50,000,000 | $15+ billion |
The two attacks that hit procurement specifically are BEC and supply chain compromise. The two attacks that hit operations specifically are ransomware and data theft. All five are interconnected — a phishing attack that steals credentials can enable BEC, ransomware, or data theft.
Business Email Compromise (BEC): the dominant attack
BEC attacks come in several forms, all involving email-based impersonation or compromise:
| Variant | Description | Typical target |
|---|---|---|
| Vendor email compromise (VEC) | Attack compromises or spoofs supplier email; sends fake invoice with changed banking details | Buyer's AP department |
| Executive impersonation | Attack spoofs CEO/CFO email; requests urgent wire transfer or vendor payment change | AP clerk or finance staff |
| Title/role impersonation | Attack impersonates a specific person (e.g., "controller Jane Smith") to request action | Any employee handling payments or sensitive data |
| Real estate / wire fraud | Attack impersonates title company or seller; sends new wire instructions for real estate transaction | Buyer or seller in real estate transaction |
| Data theft / W-2 scam | Attack impersonates executive; requests employee W-2 data or other sensitive PII | HR or finance staff |
The most common manufacturing variant is Vendor Email Compromise (VEC). The attack sequence:
Attack gains access to a supplier's email account (via phishing, credential theft, or compromised vendor)
Attack sends a fake invoice to a known customer — typically with a slight change to banking details
The change is small enough to be plausible (different bank, slightly different account number) but large enough to redirect funds to the attacker's account
The buyer's AP department processes the invoice, often with segregation-of-duties approval
Funds wire to the attacker's account — typically overseas or to a money mule in the US
Real vendor calls weeks later asking why payment is late
By then, funds are unrecoverable
The financial impact is total loss of the payment plus reputational damage and the cost of forensic investigation. Recovery from wire fraud is rare — funds are typically transferred through multiple accounts and withdrawn within hours of receipt.
How a BEC attack works step by step
A typical Vendor Email Compromise attack on a manufacturing buyer:
Phase 1: Reconnaissance (days to weeks)
The attacker researches the target organization and its vendors:
Identifies suppliers to the buyer (from public sources, LinkedIn, industry directories)
Identifies AP department contacts (from website, social media, professional networks)
Identifies the supplier's email format (firstname.lastname@vendor.com)
May compromise a supplier's email account via phishing, password reuse, or third-party breach
Phase 2: Impersonation (1-3 days)
The attacker sends the attack email:
From an email address similar to the vendor's (typo'd domain, lookalike domain)
OR from the actual compromised vendor email account (hardest to detect)
Invoice attached or referenced, often with subtle banking change
Justification provided: "We've moved to a new bank" or "Our accounting system updated"
Urgency added: "Please process by Friday" or "We have a payment discount if paid this week"
Phase 3: Payment (1-7 days)
If the buyer processes the invoice:
AP clerk enters invoice per normal process
Approval routing (if segregation of duties in place)
Wire transfer or ACH payment to "new" account — actually attacker's account
Payment recorded as complete in vendor's account
Phase 4: Discovery (days to weeks)
The fraud is discovered when:
Real vendor sends statement showing overdue balance
Real vendor's collections team calls about non-payment
Real vendor contacts AP to reconcile
Bank reconciliation catches the discrepancy (sometimes months later)
Phase 5: Recovery attempts (often unsuccessful)
The buyer attempts to recover funds:
Bank recall request — typically too late, funds already withdrawn
Law enforcement report (FBI IC3 for US-based incidents)
Insurance claim (if cyber or crime coverage exists)
Civil litigation against the mule (limited recovery potential)
Recovery rate for BEC funds after 24 hours:<5%. 72="" recovery="" rate="" after="" hours:="">
Ransomware in manufacturing
Ransomware is the second major cybersecurity threat to manufacturing. Unlike BEC (which targets financial transactions), ransomware targets operations:
How ransomware attacks manufacturing
Initial access: Phishing email with malicious attachment or link, or exploitation of unpatched internet-facing software (VPN, RDP, firewall)
Lateral movement: Once inside, the attacker explores the network, escalates privileges, identifies critical systems
Data theft: Before encryption, attackers copy sensitive data (often hundreds of GB) for double-extortion leverage
Encryption: Attackers encrypt all accessible files, including production data, backups (if reachable), and operational systems
Demand: Ransom note demands payment (typically $500,000-$50M in cryptocurrency) for decryption key and non-publication of stolen data
Decision: Company decides whether to pay, restore from backups, or both
Manufacturing-specific impact
Manufacturing is increasingly targeted because:
Downtime is highly visible: Production stoppage is immediately visible to employees, customers, and suppliers
Downtime is costly: Lost production at $50,000-$500,000/day for many manufacturers
Data theft leverage: Manufacturing designs and customer lists are high-value IP
OT/IT convergence: Modern manufacturing connects operational technology (OT) to IT networks, expanding the attack surface
High-profile manufacturing ransomware incidents
Colonial Pipeline (2021): $4.4M ransom paid (partial recovery by FBI)
JBS Foods (2021): $11M ransom paid, all US plants temporarily shut down
Norsk Hydro (2019): $71M total cost, manual operations for weeks
Honda (2020): Production halted at multiple plants
TSMC (2018): $250M cost from WannaCry variant, TSM Chip production impacted
These are exceptional cases. Typical mid-size manufacturing ransomware attacks cost $1-5M including ransom, recovery, downtime, and remediation.
Supply chain attacks
Supply chain attacks compromise a trusted software or service vendor to attack downstream manufacturing customers. The attacker exploits the trust relationship between the vendor and its customers.
Notable manufacturing-relevant supply chain attacks
SolarWinds (2020): Russian state actors compromised SolarWinds Orion software update. 18,000+ organizations received the malicious update, including multiple US government agencies and defense manufacturers.
NotPetya (2017): Russian state actors compromised M.E.Doc accounting software (Ukraine). Spread globally; Merck ($870M), Maersk ($300M), FedEx/TNT ($400M), and multiple manufacturing companies suffered massive damage.
Kaseya VSA (2021): Ransomware attack on Kaseya VSA MSP software. Affected 1,500+ downstream businesses via MSPs using Kaseya.
3CXDesktopClient (2023): North Korean state actors compromised 3CX desktop client software, affecting customers globally.
Manufacturing-specific supply chain risks
CAD/CAM software compromise: Mastercam, CATIA, Siemens NX — if compromised, malicious code could reach production
ERP/MES software: SAP, Oracle, Infor — contain sensitive production and financial data
Industrial control systems: Siemens, Rockwell, Honeywell — direct access to production lines
Quality management software: If compromised, FAI and inspection records could be falsified
Mitigation is at the IT/security level: software bill of materials (SBOM), supplier security audits, network segmentation between IT and OT, and software update verification.
The 7 controls that prevent most attacks
The seven controls below, implemented together, prevent the vast majority of manufacturing cyber attacks:
1. Phone verification of banking changes
The single most effective control against BEC. Any banking detail change requested via email must be verified by phone to a previously known number (not the number in the email). For high-value changes, require a signed form.
Cost: $0 (just time). Effectiveness: prevents ~95% of VEC attacks.
2. Multi-factor authentication (MFA)
MFA on all email, financial, and procurement systems. Even if credentials are stolen via phishing, MFA prevents account access.
Cost: $5-15/user/month for cloud MFA. Effectiveness: prevents ~99% of credential-based attacks.
3. Segregation of duties on payments
No single person can both approve and execute payments. AP clerk enters invoice, controller approves, treasurer executes. This ensures that even if one person is compromised, fraudulent payments cannot be processed alone.
Cost: organizational discipline. Effectiveness: catches most BEC attacks before payment.
4. Vendor portal or system of record
Maintain vendor banking details in a portal or system of record, not in email. Changes are made through the portal, verified by dual control, and locked for 30 days after change. Email is not the source of truth for banking.
Cost: $5k-50k for portal implementation. Effectiveness: prevents most VEC attacks.
5. Email authentication (DMARC, DKIM, SPF)
Email authentication protocols verify that email claiming to be from your domain actually is from your domain. DMARC, DKIM, and SPF prevent most email spoofing.
Cost: implementation effort. Effectiveness: prevents most email spoofing attacks.
6. Backup and recovery discipline
For ransomware protection: offline backups, tested recovery procedures, immutable backups. The 3-2-1 backup rule (3 copies, 2 different media, 1 offsite) is the minimum.
Cost: $5k-50k depending on data volume. Effectiveness: enables recovery without paying ransom in most cases.
7. Cyber insurance
Cyber insurance covers investigation, recovery, business interruption, ransom payment, and liability. For manufacturing, limits of $5M-50M are typical. Premium: $10k-100k/year depending on revenue and risk profile.
Cost: $10k-100k/year. Effectiveness: financial recovery after incident; does not prevent attacks.
| Control | Primary threat addressed | Effectiveness | 5-yr cost |
|---|---|---|---|
| Phone verification of banking changes | VEC / BEC | 95% | $0 |
| MFA on email/finance systems | Credential theft / BEC | 99% | $5k-$20k |
| Segregation of duties | BEC | 80% | $0 |
| Vendor portal | VEC | 90% | $20k-$200k |
| Email authentication | Email spoofing | 85% | $5k-$15k |
| Backup/recovery | Ransomware | 95% | $25k-$150k |
| Cyber insurance | All | Financial recovery only | $50k-$500k |
| Total | $100k-$1M |
The total 5-year cost of all seven controls ($100k-$1M) is small compared to the potential loss of a single major incident ($500k-$50M).
Incident response when an attack succeeds
Despite controls, attacks will occasionally succeed. The incident response plan determines whether the loss is $50k or $50M.
First 24 hours — the critical window
Hour 0: Attack discovered. Activate incident response team.
Hour 1: Contain the attack — disconnect affected systems, preserve evidence.
Hour 1-2: Notify bank if wire transfer involved. Request recall. (Low success rate but must be attempted.)
Hour 2-4: Engage external incident response firm (specialized cyber IR with manufacturing experience).
Hour 2-6: File FBI IC3 report (US), law enforcement report in jurisdiction.
Hour 4-8: Notify cyber insurance carrier. Engage their approved vendors.
Hour 8-24: Begin forensic investigation. Determine scope of compromise.
First week
Restore from clean backups (if ransomware)
Implement workarounds for impacted operations
Notify customers and suppliers of any disruption
Engage legal counsel for regulatory and contractual notification obligations
Communicate with employees (be careful not to compromise investigation)
Consider ransom payment decision (involve law enforcement, insurance, external counsel)
Post-incident
Complete forensic investigation and root cause analysis
Implement corrective controls to prevent recurrence
Document lessons learned
Update incident response plan based on experience
Consider regulatory disclosure (SEC for public companies, GDPR for EU residents, etc.)
Most organizations that have been through a major incident wish they had tested the response plan before the incident. Tabletop exercises (where the team walks through a scenario without actual compromise) are valuable annual preparation.
A real BEC attack case
Scenario
A mid-size aerospace machining shop ($25M annual revenue) was purchasing titanium bar from a long-standing supplier. The supplier's controller's email account was compromised (phishing attack on the controller two weeks earlier, undetected).
The attacker, using the actual compromised email account, sent an invoice to the buyer's AP department. The invoice:
Looked identical to prior invoices (same template, same PO reference)
Had a new bank routing number and account number (justified as "banking system migration")
Requested urgent payment ($187,000) by Friday for an early-pay discount
What happened
The buyer's AP clerk processed the invoice per normal procedure:
Entered invoice into AP system
Matched to existing PO and receiving report
Routed for controller approval (segregation of duties)
Controller approved (no red flags — vendor was known, invoice looked normal)
Wire transfer executed Friday afternoon
The real supplier's collections team called three weeks later asking why the payment was late. Investigation revealed the wire had gone to the attacker's account, not the supplier's.
The impact
$187,000 direct loss
$25,000 forensic investigation cost
$15,000 legal counsel
5 days of management time on incident response
Total cost: approximately $240,000
What would have prevented it
A 5-minute phone call to verify the banking change with the supplier's controller using the phone number on file (not from the email) would have caught the fraud. The legitimate controller would have confirmed the supplier had NOT changed banks.
What the company did after
Implemented mandatory phone verification for all banking changes (written policy, training, AP system enforcement)
Required dual approval for any wire over $25,000
Implemented MFA on all email and financial systems
Purchased cyber insurance with $5M limit
Conducted annual phishing training and tabletop exercises
The company has had no BEC incidents in the 4 years since implementing these controls.
Frequently asked questions
What is a Business Email Compromise (BEC) attack in manufacturing?
A Business Email Compromise (BEC) attack is when a cybercriminal impersonates a trusted business partner (typically a vendor or executive) via email to trick the recipient into transferring funds to a fraudulent account. In manufacturing procurement, the most common form is vendor email compromise: the attacker spoofs or hijacks a supplier's email account and sends a fake invoice with updated banking details to the buyer. The buyer pays the invoice — to the attacker's account — without realizing the change. BEC losses in manufacturing exceed $2 billion annually in the US alone.
How do I verify vendor banking changes safely?
Never trust banking change instructions received via email alone — even from known contacts. Always verify by calling the vendor at a phone number you already have on file (not the number in the email, which may be fake). For high-value changes, require a signed authorization form from a known vendor contact. For small changes, a phone call to a known contact using a previously verified number is adequate. The 60-second phone call is the single most effective control against BEC losses.
What are the most common cyber attacks on manufacturing companies?
Based on FBI IC3 and industry data, the most common attacks on manufacturing are: (1) Business Email Compromise (BEC) — fake invoices with changed banking details, leading to wire fraud. (2) Ransomware — encrypting production data and demanding payment for the decryption key, often with double-extortion (data theft + encryption). (3) Vendor/supply chain attacks — compromising a trusted software vendor to attack downstream manufacturing customers. (4) Phishing — credential theft from employees that leads to broader network compromise. (5) Data theft — stealing intellectual property, customer lists, or pricing data for competitive advantage.
Does my small manufacturing company need cyber insurance?
Yes, if your revenue exceeds $5M annually. The cost of a single BEC incident ($50k-$500k) or ransomware attack ($500k-$5M including downtime) far exceeds typical premiums ($10k-$50k/year for small to mid-size manufacturers). Look for policies that cover: funds transfer fraud (covers BEC losses), social engineering, data breach response, business interruption, and ransomware payment. Confirm the policy covers manufacturing-specific risks (operational technology, industrial control systems) not just IT.
What should I do if my company has been hit by a BEC scam?
In the first 24 hours: (1) Contact your bank immediately to request recall of the wire transfer — low success rate but must be attempted. (2) File an FBI IC3 report (ic3.gov) for US-based incidents. (3) Engage external incident response firm with BEC experience. (4) Notify your cyber insurance carrier. (5) Preserve all evidence — emails, invoices, bank records. After 24 hours, recovery is unlikely. Focus shifts to: investigating how the compromise occurred, implementing controls to prevent recurrence, and (if applicable) pursuing civil recovery against identified bad actors.
Should we pay a ransomware demand?
The decision involves legal, ethical, financial, and operational factors. Most law enforcement agencies (FBI, Europol) advise against paying because it funds the criminal ecosystem and does not guarantee recovery. However, some companies pay when: (1) backups are insufficient or also encrypted, (2) downtime cost exceeds ransom quickly, (3) stolen data creates unacceptable liability. If paying: engage law enforcement, use insurance carrier resources, negotiate through professional negotiators (most ransoms are reduced 30-60% through negotiation), and never negotiate directly without expert help. No decision should be made without involving legal counsel and your cyber insurance carrier.
Cybersecurity as operational discipline
Manufacturing procurement sits at the intersection of high-value transactions and limited cybersecurity maturity — making it the prime target for cybercrime. The cost of controls ($100k-$1M over 5 years) is trivial compared to the cost of a single incident ($240k for a small BEC, $1M-$50M for a ransomware attack). The seven controls outlined here prevent the vast majority of attacks.
The most important control is free: a 60-second phone call to verify any banking change. Any organization that processes wire transfers and does not have this control is exposing itself to inevitable loss.
Baoji Boze Metal Products Co., Ltd. maintains cybersecurity controls aligned with NIST CSF and ISO 27001, including mandatory multi-factor authentication, segregation of duties on all payments, vendor portal for banking management, and email authentication (DMARC/DKIM/SPF). Customers can verify our security posture through our supplier security questionnaire responses and SOC 2 documentation.
Need a cybersecurity-conscious titanium supplier? Request our supplier security questionnaire response and SOC 2 documentation from info@bozemetal.com. Our security and compliance team will respond within two business days with documentation aligned to NIST CSF, ISO 27001, and CMMC requirements.
View titanium supplier security and compliance documentation →