AI Cyber Security

Abnormal AI 2026 Attack Landscape Report: Attackers Move Beyond Exploits to Target Human Behaviour and Trusted Relationships

AI  /  Cyber Security  |  4 min read


Abnormal AI (the leader in behavioural AI security), has released its 2026 Attack Landscape Report — analysing nearly 800,000 email attacks across 4,600+ organisations from July to December 2025. The findings document a fundamental shift in cybercrime: attackers are moving away from exploiting technical vulnerabilities and instead targeting behavioural and organisational ones — using highly tailored attacks that exploit trusted relationships and routine workflows. While attackers continue to exploit internal relationships between colleagues, vendor email compromise (VEC) now accounts for the majority of all business email compromise (BEC) attacks at 61%. As attackers shift toward impersonating trusted vendors, they are increasingly using high-stakes financial workflows to maximise impact — with billing account update requests carrying a 26.5% compromise rate, dramatically higher than routine invoice inquiries at less than 1%.

"Modern email attacks are shaped by the institutions they target. Attackers are no longer just trying to circumvent security; they are exploiting the very mechanics of how we work. Whether it's a fake SharePoint notification in a finance department or a lateral attack from a compromised student account, these threats succeed because they are difficult to distinguish from legitimate business as usual. When that happens, detection becomes a behavioural challenge, requiring AI that continuously learns how people and organisations actually operate."

— Piotr Wojtyla, Head of Threat Intel and Platform, Abnormal AI

Key Findings — Phishing, Redirect Chains, and the Higher Education Vulnerability

Phishing remains the most prevalent threat, accounting for 58% of all attacks, with evasion techniques deployed based on the specific target. More than one in five phishing attacks (21.6%) now use redirect chains — routing victims through multiple URLs to obscure malicious destinations and evade detection by legacy security tools. Higher education is uniquely vulnerable to lateral attacks: nearly one in eight phishing attacks reaching student inboxes originates from a compromised internal account, and 33% of all BEC in the sector is lateral — reflecting how open, high-turnover environments with low account hygiene create ideal conditions for internal spread. Attackers also calibrate their tactics to organisational size: in small organisations, VIP impersonation accounts for 43% of internal impersonation attacks — because executives are more visible, more accessible, and often directly involved in financial decisions, making authority-based requests both plausible and effective. The report finds that attackers are selectively investing greater time and effort in more credible, high-stakes scenarios — compromising real vendor accounts or convincingly replicating trusted relationships — where the financial payoff justifies the added complexity.

Abnormal AI — Behavioural AI Security for the Human Attack Surface

Abnormal AI is the leading behavioural AI security platform. Its anomaly detection engine analyses identity and behavioural signals to detect sophisticated attacks and compromised accounts across email and connected applications. The 2026 Attack Landscape Report's central finding — that modern attacks succeed by exploiting the mechanics of how organisations actually work, rather than by circumventing technical controls — directly maps to Abnormal AI's core thesis: that detecting these attacks requires AI that develops a continuous, dynamic model of normal human and organisational behaviour. When an attack is indistinguishable from legitimate business as usual based on content alone, only a platform that deeply understands behavioural baselines — who communicates with whom, how financial requests normally flow, what a vendor relationship actually looks like — can identify the deviation.

Key Takeaways

  • Abnormal AI (the leader in behavioural AI security; anomaly detection engine; identity and behavioural signal analysis) has released its 2026 Attack Landscape Report — based on analysis of nearly 800,000 email attacks across 4,600+ organisations, July–December 2025 (announced 22 April 2026, Las Vegas). Central finding: a fundamental shift in cybercrime from exploiting technical vulnerabilities to targeting behavioural and organisational ones — using attacks that exploit trusted relationships and routine workflows that are difficult to distinguish from legitimate business activity.
  • Vendor Email Compromise (VEC) now dominates BEC: VEC accounts for 61% of all business email compromise attacks — making vendor impersonation the primary BEC vector. Billing account update requests carry a 26.5% compromise rate — dramatically higher than routine invoice inquiries at less than 1%. The gap reflects attackers selectively investing in credible, high-effort attacks targeting high-stakes financial workflows (banking detail changes, payment rerouting) where the financial payoff justifies the complexity of compromising real vendor accounts or convincingly replicating trusted relationships.
  • Phishing and redirect chain evasion: phishing remains the most prevalent threat at 58% of all attacks. 21.6% of phishing attacks now use redirect chains — routing victims through multiple URLs to obscure malicious destinations and evade detection by legacy security tools. Evasion techniques are deployed selectively based on the specific target — indicating attackers are developing target-specific evasion strategies rather than applying generic methods.
  • Higher education as a high-risk lateral attack environment: nearly 1 in 8 phishing attacks reaching student inboxes originates from a compromised internal account; 33% of all BEC in higher education is lateral — not external. Open, high-turnover environments with frequent account changes and limited centralised security controls create ideal conditions for compromised accounts to spread attacks internally. In small organisations: VIP impersonation accounts for 43% of internal impersonation attacks — executives are more visible, accessible, and directly involved in financial decisions, making authority-based requests highly effective.
  • Why behavioural AI is the required defence: the report's findings validate the core detection challenge — when attacks are designed to be indistinguishable from legitimate workflows (a genuine-looking billing update from a trusted vendor, a plausible SharePoint notification, a lateral message from a compromised colleague), signature and rules-based detection fails. Abnormal AI's anomaly detection engine — continuously modelling identity and behavioural signals across email and connected applications — is positioned as the platform that detects the deviation from normal behaviour that content-based tools cannot see. Download the full 2026 Attack Landscape Report at abnormalsecurity.com.
Tags: AI News Cyber Security Email Security Machine Learning AI Tech Trends Artificial Intelligence News