Red Kite said that domain-spoofing and convincing scam emails claiming to be from suppliers were the cause.
Source: Threadpost