The Vendor Risk Questionnaire Was Never Designed to Catch This

Bottom Line Up Front (BLUF): In June 2023, a hacker compromised the email account of a furniture vendor that supplied Children’s Healthcare of Atlanta (CHOA). Posing as a vendor employee, the attacker convinced CHOA to update the vendor’s banking details on file. CHOA wired $5.3 million to an account controlled by a former CPA who had agreed to launder the money. He was sentenced to federal prison in July 2026. Every vendor risk questionnaire CHOA had ever run on that vendor would have passed cleanly. The questionnaire measures whether a vendor’s stated policies exist. It was never built to catch a scenario where the vendor’s own identity becomes the attack surface. That gap, not vendor negligence, is the real story, and it points to a different kind of control than most procurement processes currently require.

The Compliance Ritual

Somewhere in CHOA’s vendor files sits a completed risk assessment for the furniture vendor whose email got compromised. A questionnaire was sent. Someone at the vendor answered it: yes to a security policy, yes to basic access controls, probably yes to encryption at rest. A box got checked. Onboarding proceeded. None of that mattered on the day an unknown attacker gained access to the vendor’s email system, impersonated one of its employees, and contacted CHOA directly to change the bank account tied to that vendor’s ACH payments.

CHOA wired $5.3 million based on instructions that looked, from the inside, exactly like routine vendor correspondence. The money landed in the account of Ronald Deabler, a business owner and former CPA who had agreed to move the funds in exchange for a commission. He converted roughly $3.5 million into cashier’s checks and mailed them out as directed before CHOA and its bank caught the fraud within days and traced the money back. Deabler was convicted by a jury in February 2026 and sentenced in July to four years in federal prison, with restitution ordered at $682,860.

Nothing in that sequence involved a technical failure on the vendor’s side. The vendor’s systems were not the target. The vendor’s identity was.

What The Questionnaire Actually Measures

A vendor risk questionnaire asks a vendor to describe its own controls: does it require multi-factor authentication, does it encrypt data, does it run a formal incident response program. These are reasonable questions, and the answers are usually true at the moment they are given. But an answer of “yes” to “do you have an information security policy” confirms that a policy exists. It says nothing about whether that policy holds up against a targeted social engineering attempt, whether the vendor’s finance team has a verification step for banking-detail changes, or whether the vendor would even know its own email account had been compromised.

Self-attestation is a report from the vendor about the vendor. It is not independent verification, and it was never designed to be. That distinction matters more than it usually gets credit for, because procurement teams tend to treat a completed questionnaire as due diligence performed rather than a data point collected. The CHOA vendor may well have answered every question on file honestly. None of those answers addressed the actual failure mode that occurred.

What It Structurally Can’t Capture

This is the part of vendor risk assessment that gets the least attention, because it falls outside what a questionnaire is built to ask in the first place. A standard vendor risk questionnaire, whether it is a custom form or something built on the SIG framework, is scoped to the vendor’s own environment and controls. It has no line item for “can an attacker convincingly impersonate you well enough to redirect a customer’s payment.” That is not a gap in how thoroughly the questionnaire was completed. It is a gap in what the instrument measures.

The CHOA case is a clean illustration because the vendor’s own security posture may not have been the point of failure at all. Business email compromise attacks like this one do not require breaching a target’s systems. They require compromising one mailbox somewhere in the vendor relationship and using the trust already built into that relationship to move money. A questionnaire assessing the vendor’s stated controls cannot see that risk, because the risk lives in the interaction between two organizations’ finance processes, not inside either organization’s technical environment. This is a practitioner observation grounded in how these attacks actually unfold, not a hypothetical: the trust relationship itself is the exploit path, and no self-attestation form currently in wide use is built to probe it.

Why Point-in-time Fails On Its Own Terms

Even where questionnaires do capture something real, they capture it once. Most vendor assessments run at onboarding and then annually at best. A vendor’s infrastructure, staffing, and email security posture change continuously in between. IBM’s 2025 Cost of a Data Breach Report found that third-party and supply chain involvement in breaches roughly doubled year over year, and that these incidents took an average of 267 days to identify and contain, longer than almost any other attack category the report tracked. Breaches involving compromised credentials averaged $4.67 million, reflecting how much damage can accumulate once an attacker is operating inside a trusted channel before anyone notices.

That extended timeline is not incidental. It is a direct consequence of assessing vendor risk once and treating the result as durable. A vendor can pass a review in January and have a materially different risk profile by June, with zero visibility into that change on the customer’s side. CHOA’s own detection, to its credit, ran faster than the industry average: the fraud was caught within days, not months, and roughly $4 million of the $5.3 million was eventually recovered. That outcome says more about CHOA’s bank monitoring and incident response than about anything a vendor questionnaire contributed.

What A More Honest Risk Picture Looks Like

None of this argues for abandoning vendor questionnaires. It argues for pairing them with something that verifies rather than only asks. Evidence requests, such as a current SOC 2 report or a recent penetration test summary, provide more than a self-reported yes or no. Risk tiering by potential blast radius, meaning how much financial or operational damage a compromised relationship with this specific vendor could cause, matters more than whether every vendor completed the same generic form. Contract language requiring notification of material changes in a vendor’s environment closes some of the point-in-time gap.

For payment-specific risk, the more direct control is procedural rather than assessment-based: any request to change banking details, regardless of how legitimate the requesting channel appears, gets verified through a separate, previously established contact method before funds move. That single control would have interrupted the CHOA fraud regardless of what any questionnaire said about the vendor’s security program. It is not a glamorous fix. It is also the one that actually addresses the failure mode that occurred.

Close

The vendor risk questionnaire answers a narrower question than most organizations think they are asking. It confirms that a policy exists somewhere on paper. It cannot confirm that the policy holds up under a determined attempt to exploit trust, and it cannot see what changes in a vendor relationship between one review cycle and the next. CHOA’s questionnaire, whatever it said, was never going to catch an attacker who simply became the vendor for one wire transfer. The harder question, and the more useful one, is whether an organization would catch that same attempt today, and whether its controls depend on a form being filled out correctly or on a verification step that holds regardless of how convincing the request looks.


References

  1. U.S. Attorney’s Office, Northern District of Georgia. “Former CPA Sentenced to Federal Prison for Laundering Funds Stolen from Children’s Healthcare of Atlanta.” July 23, 2026. justice.gov/usao-ndga
  2. IBM. “2025 Cost of a Data Breach Report: Navigating the AI Rush Without Sidelining Security.” ibm.com/think/x-force

Final CTA Section
GET STARTED

Ready to Strengthen Your Defenses?

Whether you need to test your security posture, respond to an active incident, or prepare your team for the worst: we’re ready to help.

📍 Based in Atlanta | Serving Nationwide

Discover more from Satine Technologies

Subscribe now to keep reading and get access to the full archive.

Continue reading