Skip to main content

Jul 23, 2026

The 2026 Attack Landscape: Why “Business as Usual” Is Your Biggest Risk

Abnormal's analysis of nearly 800,000 attacks across 4,600 organizations points to one conclusion that security leaders can’t afford to ignore: today’s most damaging attacks are designed to look completely legitimate, and most defenses are not built to catch them.

Modern email attacks don't succeed through volume as much as they succeed through familiarity.

That’s the finding of Abnormal’s 2026 Attack Landscape Report, which draws on 800,000 attacks across 4,600+ customer accounts spanning three regions in the second half of 2025. The data comes directly from the environments we protect, reflecting real attacks organizations are facing today.

Defending against volume is hard enough, but our data shows the deeper problem is how surgically these attacks are tailored to the specific environment they target. Modern attackers are fluent in organizational workflows, communication styles, and trusted relationships. They calibrate their tactics to the way their targets actually operate, leaving security tools designed for static rules and signatures largely blind to their arrival.

Business Email Compromise: Size Dictates the Strategy

Business email compromise (BEC) represents roughly 11% of attacks by volume, a fraction of phishing's 58%. But volume is not the same as impact, and BEC attacks are among the costliest an organization can face. Almost 40% of BEC attacks involve internal impersonation, where employees are manipulated into authorizing massive and often irreversible wire transfers.

How that manipulation manifests, however, depends on the size of the organization.

In a 200-person firm, the CEO is reachable and often directly involved in payment approvals. Our research shows that VIP impersonation dominates here, making up 43% of identity attacks in smaller companies. Why? Because an urgent personal request from a known leader carries real weight.

In one case, an attacker posing as a managing director asked an employee for help updating a tracking sheet of outstanding invoices. The message looked legitimate—it was phrased as a routine cash-flow check, the kind a busy executive might fire off from their iPhone between meetings. The employee, having no reason to question it, pulled the report and sent it back, effectively handing over a complete map of the company's vendors and payables.

Compare that scenario to a 50,000-person enterprise, where the same request would be considered a major red flag. Employees don't expect cold emails from the C-suite, and attackers know this. VIP impersonation accounts for only 7% of attacks in enterprise organizations, with employee impersonation and lateral attacks originating from compromised accounts filling the gap.

Lateral BEC is nearly 100 times more common in large firms, where employees can’t know everyone, and a request appearing to come from a peer or middle manager may seem believable. The vast web of internal accounts and integrations offers an almost limitless surface for an attacker to hide in plain sight.

Each of these tactics solves the same problem for the attacker. While the tactic changes with the size of the organization, the goal is to make a request that’s credible enough for the recipient to act on without verifying it.

Vendor Email Compromise: Attacks Disguised as Vendor Requests

While internal impersonation demands attention, it’s the supply chain that’s the true frontline of modern fraud. Vendor Email Compromise (VEC)—a subtype of BEC—now accounts for 61% of all BEC attacks. These threats take various forms, but the most common is invoice fraud, where the threat actor poses as a vendor to request payment of a plausible-looking, but fraudulent, bill.

Our research shows that in the vast majority of VEC attacks (87.5%), simple impersonation can convince an employee to push a payment through without verification. Often, that means little more than a spoofed address, a lookalike domain, a familiar vendor name, and a nudge of urgency. In the most brazen cases, attackers manufacture entire email threads, complete with fake executive sign-off, so the recipient pays the invoice believing it's been approved.

Billing account update requests, on the other hand, usually demand more than a convincing imitation. More than a quarter (26.5%) of these attacks involve account compromise, where fraudsters hijack a legitimate vendor account and inject their request directly into the established history of a real business relationship. The strategy makes sense: a request to change a vendor's bank account details will naturally evoke suspicion, while a fake email from a lookalike address is unlikely to survive scrutiny. A message from the vendor’s actual account—carrying the implicit legitimacy of a trusted relationship—is a different proposition entirely.

When the pretext demands total credibility, threat actors are willing to put in the effort to hijack a real account to gain that level of trust.

Phishing: Hiding in Your Shared Files

Today’s phishing emails are designed to blend into the workflows employees rely on every day. Two environments in particular have become fertile ground for attackers: document-sharing platforms and shared inboxes.

File-sharing phishing is a cyberattack where threat actors trick you into clicking malicious links by impersonating legitimate cloud storage platforms like Microsoft SharePoint, DocuSign, or Dropbox. Our research shows that this type of attack hits finance and accounting roles hardest at 25% of all attacks—more than double the 12.4% average—with legal and compliance roles close behind.

These departments process relentless volumes of contracts, purchase orders, and other files. The lure doesn’t prompt suspicion because document exchange is part of routine operations. “New document shared with you” notifications look so ordinary that busy recipients click without stopping to question the sender, the timing, or where the link actually leads. And why would they, when it comes directly from DocuSign?

Shared inboxes are another attractive environment for BEC attacks. Accounts Payable@, Invoicing@, or Purchasing@ inboxes sit at the intersection of high message volume and critical financial workflows. They’re also difficult to police: countless employees have access to them, but no one holds the full relationship context required to spot anomalies.

Attackers exploit that gap by crafting messages so forensically ordinary—the kind of paperwork that moves through an AP queue a hundred times a week—that payment requests get approved as routine. By the time anyone thinks to question the legitimacy, the payment is already made.

RFQ Fraud: Coming for Your Sales Team

Just as attackers prey on finance and legal workflows, they also target the core incentives of the sales department. Sales culture rewards speed and responsiveness; the faster a rep engages a lead, the better their chances of closing the deal. Attackers exploit this through RFQ (Request for Quote) fraud, which hits sales and business development teams at 2.6 times the rate of other departments.

RFQ fraud is a long-term strategy. Posing as a prospective customer, a fraudster issues a bid invitation or requests pricing and specifications for a high-volume supply order. They build a relationship with the rep, gaining their trust over time before making their final move. Usually, the endgame is to either secure goods on credit with no intention of paying or to deliver weaponized “bid documents” designed to harvest credentials or install malware.

What makes RFQ fraud so insidious is that it exploits a core expectation of the sales role: reps are measured by their ability to engage with strangers. The responsiveness and openness that make a top salesperson effective are precisely the qualities attackers are counting on to bypass the usual security checks.

What Should CISOs Do Now?

The findings in our report all share a common theme: attackers are tailoring their tactics to the target. Today’s email attacks look like a part of everyday operations, and that’s what makes them so hard to catch.

This has major implications for defense strategy:

  • Match defenses to company size: Be aware that small companies and enterprises face fundamentally different types of threats.

  • Treat the supply chain like your own network: Review any external relationships just as rigorously as internal ones.

  • Add friction to shared inboxes: Require verification for any payment-related request, no matter how routine.

  • Validate document workflows: Ensure the sender, platform, and timing align with a legitimate, ongoing relationship.

  • Build checks into lead intake: Implement lightweight verification steps for new inquiries.

These steps matter, but they rely on human judgment at moments of high pressure. And under pressure, humans can slip up, especially when they encounter email attacks that blend in perfectly with their routine habits.

The Abnormal Behavioral Security platform is built for this reality. It constructs a precise, continuously updated baseline of “normal” for every sender, recipient, relationship, tool, and workflow in your environment. When a request deviates from that pattern, even slightly, it’s caught before it ever reaches an inbox.

When it comes to security awareness training, Abnormal’s AI Phishing Coach takes the real attacks Abnormal intercepts in your organization's environment and turns them into personalized simulations delivered at the exact moment an employee encounters a similar risk. It’s an approach that trains people on the precise tactics that attackers are using against them in their daily communications.

What our research makes clear is that, above everything else, the most dangerous threats facing organizations today are those that look like “business as usual.” An effective defense requires flagging what isn’t normal before an employee has the opportunity to engage.

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.