Site navigation

Report: Vendor Impersonation Now Dominates BEC Attacks

Tom Quinn

,

vendor phishing
“Attackers are no longer just trying to circumvent security; they are exploiting the very mechanics of how we work,” said Piotr Wojtyla, Abnormal AI.

Attackers are shifting from technical exploits to manipulating people and trusted relationships, according to new research from Abnormal AI, with these higher‑effort schemes promising bigger financial rewards.

The AI security firm’s 2026 Attack Landscape Report, based on analysis of almost 800,000 email attacks across more than 4,600 organisations, reveals an emerging shift in cybercrime as threat actors increasingly rely on highly tailored attacks that exploit routine workflows.

The data show that malicious actors are attempting to exploit internal relationships between colleagues and third parties, with vendor email compromise (VEC) now accounting for the majority of business email compromise (BEC) attacks (61%).

Abnormal found that as attackers shift toward impersonating these trusted vendors, they are using high-stakes financial workflows to maximise the impact of their scams.

Billing account update requests stand out as the most dangerous vector, carrying a 27% compromise rate, notably higher than routine invoice inquiries, which stand at less than 1%.

Unlike invoices, which can blend into high-volume payment workflows, billing updates require organisations to reroute legitimate, ongoing payments, prompting greater scrutiny from finance teams.  

As a result, attackers are more likely to compromise real vendor accounts or convincingly replicate trusted relationships and individuals. For instance, in smaller organisations, VIP impersonation accounts for 43% of internal impersonation attacks because executives are more accessible, and often directly involved in financial decisions, making authority-based requests plausible and effective. 

In large enterprises, however, layered approval processes and greater awareness of executive impersonation reduce the effectiveness of this approach, prompting attackers to shift toward the targeting and impersonation of lower-level employees to maintain the illusion.

These attacks are grounded in phishing tactics, which remain the most prevalent threat, accounting for 58% of all incidents tracked by Abnormal, with more than a fifth now using redirect chains routing victims through multiple URLs to obscure malicious destinations. 


Recommended reading


Abnormal said such patterns show that attackers are investing in credible, higher-effort scenarios where the financial payoff is greatest, with the likelihood of success justifying the added complexity.

“Attackers are no longer just trying to circumvent security; they are exploiting the very mechanics of how we work,” said Piotr Wojtyla, head of threat intel at Abnormal AI. 

“Whether it’s a fake SharePoint notification in a finance department or a lateral attack from a compromised student account, these threats succeed because they are difficult to distinguish from legitimate business as usual. 

“When that happens, detection becomes a behavioural challenge, requiring AI that continuously learns how people and organisations actually operate.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI Infrastructure

Scottish Parliament Votes to Pause All AI Data Centre Applications

Cybersecurity Editor's Picks Security

Cyber Essentials Certifications Rise as SME Uptake Remains Limited

AI Editor's Picks Funding

Edinburgh Graduates’ AI Infrastructure Firm Expanse Raises $5.3m

Featured Finance

Fintech Summit 2026 Countdown Enters Final Three Weeks