The procurement team of a manufacturer in Anatolia with annual revenue in the billions received a familiar email from a European raw-material supplier they had worked with for three years: "Due to a factory audit, our bank account has changed; please send future payments to the new IBAN." The email thread quoted previous genuine correspondence; even the subject line matched an ongoing order number. That month's EUR 140,000 raw-material payment went to the new account. The truth emerged two weeks later when the supplier called to say "your payment is overdue."
Manufacturing is an almost ideal target for email-based attacks: a wide supplier network, high-value and often foreign-currency payments, tight production schedules, and increasingly interconnected OT (operational technology) and IT networks. In this article we explain why manufacturing forms a special attack surface, the four threat vectors we see, and how to defend against them.
1. Why Does a Manufacturer's Workflow Create an Attack Surface?
In a manufacturer, money and information are constantly in motion: simultaneous correspondence with dozens of suppliers, proforma invoices, order confirmations, quality certificates, technical drawings. This intensity has three natural consequences:
- A supplier IBAN change doesn't look unusual. If a company pays hundreds of different suppliers, an "our account has changed" email is perceived as a routine request.
- A culture of urgency weakens the confirmation reflex. Pressure like "the line will stop, the raw material must be paid today" is tailor-made to bypass the second-channel verification step.
- OT/IT convergence widens the attack surface. Systems on the production line (SCADA, MES, ERP) are now intertwined with the corporate email network. The takeover of a user's email account carries risk not only for accounting but for production operations.
2. The Four Threat Vectors We See in Manufacturing
2.1 Vendor / Invoice Fraud
The opening scenario. The most common and most expensive vector. A real supplier's account is compromised or impersonated with a similar domain; the IBAN in the payment instruction is changed. Because foreign-currency, high-value, cross-border transfers are standard in manufacturing, losses are large and recall is often impossible.
2.2 Procurement / CEO Pressure (BEC)
An urgent transfer request from the "General Manager" to procurement or finance. Because the decision chain in manufacturers is clear, reflexive obedience to hierarchical authority is easily exploited. The attacker usually strikes when the executive is away from the plant (site visit, trade fair, travel).
2.3 Technical Drawing / Intellectual Property Leakage
In manufacturing, competitive advantage often lies in the design, the mold, the production parameter. Through targeted phishing or account takeover, technical drawings, product specifications, and cost tables can be exfiltrated. That means direct competitive harm.
2.4 Account Takeover and Production Disruption
When a user's email account is taken over, the attacker can write to suppliers and customers from it; redirect orders, change payment details. Due to OT/IT convergence, in some scenarios this can turn into a disruption reaching production planning.
3. Field Note: The Pattern We See Most in Manufacturing
There's a recurring pattern among our manufacturing customers in Türkiye: the attack almost always inserts itself into the middle of a supplier conversation. The attacker watches real email traffic for weeks (via a compromised account), learns the right order number, the right amount, the right supplier tone; then, exactly at the payment stage, slips in the "IBAN has changed" message. There's no malicious link or attachment in the content — which is why classic filters see it as clean.
A second common pattern: manufacturers have often recently moved to Microsoft 365 and rely only on built-in protection. Built-in protection catches ordinary spam but structurally can't see these targeted, clean-content BEC attacks. We covered the detailed analysis in our why Microsoft 365's built-in email security falls short article.
4. Defense: Three Layers Specific to Manufacturing
Process (the most critical, independent of technology)
Supplier bank/IBAN changes and transfers above a certain amount are not processed without confirmation through a second channel independent of email (a call-back to a pre-registered phone number). This single rule prevents the majority of invoice-fraud losses in manufacturing.
Technology
Check Point Harmony Email & Collaboration catches these signals in manufacturing scenarios:
- Flags look-alike / newly registered supplier domains ("this domain was registered 5 days ago and closely resembles your real supplier").
- Learns the correspondence pattern; contextually detects deviation from a years-long style with a supplier (sudden IBAN change, tonal shift).
- Shows display name / real address mismatches as a visible warning banner to the user.
- Scans all inbound and outbound email (including internal correspondence after account takeover) — covering the internal phishing gateways can't see. For the architectural difference, see our API vs Gateway article.
People
Regular, realistic BEC simulations for procurement, finance, and accounting teams. The key message must be clear to the manufacturing team: "urgency + a change in payment details" is always a reason to pause and confirm — even if the line stops.
Frequently Asked Questions
If the supplier IBAN change is real, doesn't calling every time slow down the business?
A confirmation rule that applies only to bank/IBAN changes and payments above a certain amount barely slows the daily workflow; yet it prevents a single EUR 140,000 loss. The cost-benefit balance is clear.
Our OT network is already separate from IT — why should email risk concern us?
Full separation (air-gap) is increasingly rare; MES, ERP, and reporting systems connect to the corporate network. The takeover of an email account can jump to other systems via credential reuse. Email is the first entry door for most attacks.
We're a small/mid-sized manufacturer — are we a target?
Yes. Attackers look not at company size but at the size of the money movement and the weakness of confirmation processes. Mid-sized manufacturers are frequent targets because they make high-value transfers but haven't yet matured their security processes.
Can we see how much of the manufacturing scenarios our current Microsoft 365 protection misses?
Yes. In a 14-day free "monitor mode" trial, without touching your existing protection, we report the missed threats — including supplier impersonation and BEC.
What Should You Do Now?
If your manufacturing company makes high-value supplier payments and you've seen at least one "IBAN has changed" email in the past year, it's worth measuring how much of these your current protection catches.
- Free Field Audit: Your domain's SPF/DKIM/DMARC status, look-alike domain risks, and supplier-impersonation exposure are reported.
- 14-Day Check Point Trial (monitor mode): Without touching your existing protection, missed supplier/BEC threats are reported.
About this article: Kinetik Bilişim is the Türkiye partner of Check Point Software Technologies at the Advanced Partner 2026 level, holding Email, Endpoint & Browser, Mobile, and SASE Solution Specialization accreditations. The author, Kemal Özleyen, is a cybersecurity engineer certified as a Check Point Workspace Security Expert. Field scenarios are shared in anonymized form from cases seen among our manufacturing customers in Türkiye.