Attackers are shifting from technical exploits to manipulating people and trusted relationships, according to new research from Abnormal AI, with these higher‑effort schemes promising bigger financial rewards.
The AI security firm’s 2026 Attack Landscape Report, based on analysis of almost 800,000 email attacks across more than 4,600 organisations, reveals an emerging shift in cybercrime as threat actors increasingly rely on highly tailored attacks that exploit routine workflows.
The data show that malicious actors are attempting to exploit internal relationships between colleagues and third parties, with vendor email compromise (VEC) now accounting for the majority of business email compromise (BEC) attacks (61%).
Abnormal found that as attackers shift toward impersonating these trusted vendors, they are using high-stakes financial workflows to maximise the impact of their scams.
Billing account update requests stand out as the most dangerous vector, carrying a 27% compromise rate, notably higher than routine invoice inquiries, which stand at less than 1%.
Unlike invoices, which can blend into high-volume payment workflows, billing updates require organisations to reroute legitimate, ongoing payments, prompting greater scrutiny from finance teams. Â
As a result, attackers are more likely to compromise real vendor accounts or convincingly replicate trusted relationships and individuals. For instance, in smaller organisations, VIP impersonation accounts for 43% of internal impersonation attacks because executives are more accessible, and often directly involved in financial decisions, making authority-based requests plausible and effective.Â
In large enterprises, however, layered approval processes and greater awareness of executive impersonation reduce the effectiveness of this approach, prompting attackers to shift toward the targeting and impersonation of lower-level employees to maintain the illusion.
These attacks are grounded in phishing tactics, which remain the most prevalent threat, accounting for 58% of all incidents tracked by Abnormal, with more than a fifth now using redirect chains routing victims through multiple URLs to obscure malicious destinations.Â
Recommended reading
- How Worried Are Brits About AI-Fuelled Phishing?
- ‘Stealth’ Phishing Attacks Rise As Over Half Evade Detection
- 82% of Phishing Toolkits Use Deepfakes
Abnormal said such patterns show that attackers are investing in credible, higher-effort scenarios where the financial payoff is greatest, with the likelihood of success justifying the added complexity.
“Attackers are no longer just trying to circumvent security; they are exploiting the very mechanics of how we work,” said Piotr Wojtyla, head of threat intel at Abnormal AI.Â
“Whether it’s a fake SharePoint notification in a finance department or a lateral attack from a compromised student account, these threats succeed because they are difficult to distinguish from legitimate business as usual.Â
“When that happens, detection becomes a behavioural challenge, requiring AI that continuously learns how people and organisations actually operate.”





