New research around vendor email compromise (VEC) has uncovered that enterprise businesses based in European, Middle Eastern, and African countries (EMEA) are particularly vulnerable to VEC attacks, with post-read interaction and repeat engagement rates significantly outpacing other regions.
The enterprise business-focused report from Abnormal AI revealed overall how employees frequently struggle to differentiate between legitimate messages and attacks, especially when those emails appear to come from a trusted vendor.
Across all regions, 72% of employees at large enterprises who read a VEC message went on to engage with it further, taking follow-up actions such as replying or forwarding the email on.
However, the data shows that VEC threats are especially pronounced in EMEA—despite exercising higher vigilance around business email compromise (BEC) attacks. For instance, the VEC engagement rate exceeds BEC engagement by 90%, and repeat engagement with VEC is the highest of any region, and twice that of BEC.
This suggests that employees trust external parties (e.g., vendors) more than internal sources, making them vulnerable to vendor impersonation. What’s more, EMEA-based organisations record the lowest reporting rate of VEC across all regions (0.27%), yet the highest reporting for BEC (4.22%).
Abnormal AI’s Read, Replied, Compromised: Employee Engagement Trends Across VEC Attacks report also uncovered findings such as the telecommunications industry seeing the highest VEC engagement rate at 71.3%, dwarfing the second-ranked energy/utilities sector at 56%.
Further, sales roles, especially entry-level positions, were among the most vulnerable, with junior sales staff engaging with read VEC attacks at a rate of 86%.
Recommended reading
- 80% of Firms Say Their AI Agents Have Taken Rogue Actions
- NCSC Launches Two New Cyber Resilience Initiatives
- Vatican In Need of a Divine Defender Against Digital Demons
“Email-based social engineering has never been more convincing or more effective,” said Mike Britton, CIO at Abnormal AI. “Today’s attackers are hijacking legitimate vendor threads and crafting sophisticated messages that pass undetected through legacy defences.”
“While VEC volume remains lower than phishing or ransomware, its success rate—and potential financial impact—is far greater, especially as weaponised AI makes it easier than ever for attackers to impersonate trusted vendors.”
“To prevent costly human error, organisations must move beyond reactive training and adopt proactive defences that block threats before they reach the inbox,” Britton advised.
Don’t Miss Scotland’s Biggest Tech Event!
Join us at DIGIT Expo West on 5th June at the SEC Glasgow. Get leading industry insights across AI, Cyber Security, and Data, and grow your network at Scotland’s largest gathering of tech leaders – with 1500+ attendees, 50+ speakers, and 50+ exhibitors.
Register your FREE place now at: www.digitexpowest.com





