PAYMENTS · VENDOR FRAUD2026-09-10·8 min read

Vendor email compromise now drives most business email fraud — 61% of BEC in 2026 is a fake supplier, not a fake CEO

The scam most businesses trained their staff to catch was the urgent email from "the CEO," asking finance to wire money right now. That is no longer where the money is. Attackers found a bigger opening: impersonate a vendor the business already trusts and already pays on a schedule, and ask for something that looks routine — a bank detail change, an updated invoice. Abnormal AI's newest attack data puts that tactic at 61% of all business email compromise in 2026, and most awareness training still isn't built around it.

By Amr Hossam
[ THE SHORT VERSION ]

An invoice email arrives from a supplier your business has paid for two years. Same logo, same tone, same reference number format. The only change is a line near the bottom: "Please note our banking details have been updated — kindly use the account below for future payments." The employee who processes it isn't reckless. They're doing exactly what they've done a hundred times before, for a vendor who has never once given them a reason to double-check.

That is the shape of the fraud that quietly overtook the classic fake-CEO email in 2026. Business email compromise used to mean an urgent, out-of-character message from an executive, and most fraud-awareness training was built to catch exactly that. Attackers moved on. Abnormal AI's 2026 Attack Landscape Report, drawn from roughly 800,000 email attacks across more than 4,600 organizations between July and December 2025, found vendor and supplier impersonation now accounts for 61% of business email compromise — the majority case, not the edge case.

This piece is about what changed and why it works better than the scam it replaced: the FBI's own numbers on how much BEC is costing businesses right now, what vendor impersonation specifically costs and how often it gets past someone, and the one process change — a call-back on a number you already had, not one in the email — that closes most of the gap.

[ FIGURES ]
Figure 1 · Vendor impersonation overtook the fake-CEO email as the majority of BEC
SHARE OF BUSINESS EMAIL FRAUD, 2026 Vendor / supplier impersonation 61% CEO impersonation + all other BEC types 39% Most security-awareness training still drills the fake-CEO email — the minority case in 2026 ABNORMAL AI, 2026 ATTACK LANDSCAPE REPORT (JUL–DEC 2025, 4,600+ ORGS)
Abnormal AI's 2026 Attack Landscape Report, built from roughly 800,000 email attacks across 4,600+ organizations (July–December 2025): vendor and supplier impersonation now accounts for 61% of all business email compromise, against 39% for CEO impersonation and every other classic BEC pattern combined.
Figure 2 · A vendor-impersonation email gets read, engaged with, and paid more often than the classic scam
WHAT ONE VENDOR-IMPERSONATION CAMPAIGN ACTUALLY COSTS Read by an employee, and engaged with rather than ignored 44% — 90% higher than classic BEC Compromise rate when the ask is a "billing account update" 26.5% — the single most effective ask Ever reported to authorities or disclosed publicly 1.5% — 98.5% go unreported $300M+ attempted through vendor email compromise in six months alone ABNORMAL AI, 2026 ATTACK LANDSCAPE REPORT — JUL–DEC 2025
Same report: vendor-impersonation attacks that get read see a 44% employee engagement rate — 90% higher than classic BEC — and when the ask is framed as a routine billing-account update, the compromise rate hits 26.5%, the single most effective tactic Abnormal tracked. Over $300M was attempted through vendor email compromise in the six-month window, and 98.5% of VEC scams are never reported.
[ EXPLANATION ]

Start with the scale of business email compromise overall, because vendor impersonation is a slice of a number that's still climbing. The FBI's Internet Crime Complaint Center logged 24,768 BEC complaints in 2025, totaling just over $3.05 billion in reported losses — up from 21,442 complaints and $2.77 billion the year before [1]. The average verified loss now exceeds $123,000 per incident, and roughly 86% of the money moved through wire transfer or ACH [1]. Zoom out further and the number gets harder to treat as background noise: the FBI's own data puts cumulative BEC losses at nearly $8.5 billion over the last three years [2]. Fewer complaints wouldn't be a relief if the average loss keeps rising — and it is.

What changed inside that number is the more useful finding. Abnormal AI's 2026 Attack Landscape Report — built from roughly 800,000 email attacks it observed across more than 4,600 organizations between July and December 2025 — found that vendor and supplier impersonation now makes up 61% of all business email compromise, ahead of CEO impersonation and every other classic BEC pattern combined [3]. The reason is not that vendor fraud is a cleverer lie. It's that most businesses built their defenses, and their staff training, around catching the fake-CEO message: an unusual sender, an unusual urgency, an unusual amount. A vendor email asking for a routine update to banking details, framed in the vendor's normal tone at the vendor's normal cadence, doesn't trip any of those instincts, because nothing about it looks unusual. It looks exactly like Tuesday.

The numbers on how well that works are specific. Of the vendor-impersonation emails employees actually opened and read, 44% saw some form of engagement — a reply, a click, a follow-up action — a rate Abnormal measured at 90% higher than classic business email compromise [3]. Narrow further to the single most effective request type, a message asking to update a billing or banking account, and the compromise rate reaches 26.5% [3]. Across the six-month window the report covers, attackers attempted more than $300 million through vendor email compromise specifically [3][4]. And the gap that lets this keep working: an estimated 98.5% of vendor-impersonation scams are never reported to authorities or disclosed publicly [3][4], which means the businesses hit by it rarely warn the next one, and the loop keeps running with almost no public feedback.

None of this requires the attacker to breach anything. Most vendor email compromise doesn't involve hacking the actual vendor's inbox at all — a look-alike domain one character off, a spoofed display name, or basic research on a company's real vendor list and invoice format is enough, because the target isn't a technical system. It's the habit of an employee who has processed the same vendor's invoice fifty times without incident and has no procedural reason to treat the fifty-first one differently. That's also why generic phishing training under-serves this problem: it teaches people to spot what looks wrong, and a well-run vendor impersonation is built specifically to look right.

The fix that actually closes this gap is not more suspicion of every email — it's a payment-side control that doesn't depend on an employee's judgment in the moment. The specific control security teams and payment-fraud researchers converge on is a call-back verification: before any change to a vendor's bank details or payment instructions takes effect, someone calls a phone number that was already on file before the email arrived — never a number supplied in the email itself — and confirms the change with a known contact at that vendor [5]. Pair it with dual approval on vendor-detail changes, where the person who requests the update isn't the same person who approves it, and the specific tactic driving 61% of 2026's business email compromise loses almost all of its leverage — not because the email got more convincing to spot, but because the payment can no longer move on the strength of an email alone.

[ PERSPECTIVES ]
Camp A — Our staff know what phishing looks like

This is true, and it's exactly why vendor impersonation works better than the fake-CEO email it replaced. Staff trained to spot urgency, unusual senders, and out-of-character requests have nothing to flag in a routine-looking invoice update from a vendor they've paid for years, sent in that vendor's normal tone. The 44% engagement rate on read vendor-impersonation emails — 90% higher than classic BEC — isn't a training failure. It's evidence the attack was built to clear the exact bar the training set.

Camp B — We'd never send money on an email alone

Most businesses believe this about themselves right up until the request looks like something they've approved forty-nine times before. The 26.5% compromise rate on billing-update requests specifically isn't happening at companies with no process — it's happening at companies whose process assumes a familiar-looking vendor request doesn't need the same scrutiny as an unfamiliar one. The assumption is the gap, not the absence of a process.

Camp C — This is a training problem, so more training is the fix

More awareness training helps at the margins, but it's fighting the wrong layer. An employee cannot reliably out-judge an email built to look identical to a legitimate one from a real vendor — that's a losing bet against attackers who researched the actual vendor relationship. The control that works doesn't ask an employee to spot the fake; it makes the payment itself impossible to move on an email's say-so, regardless of how convincing that email is.

Where we land

Treat every vendor bank-detail change as a payment-system event, not an inbox event. Call the vendor back on a number pulled from your own records — never one supplied in the request — before the new account is used, and require a second person's sign-off on the change independent of whoever received the email. That single control, applied without exception for urgency or seniority, removes the leverage behind the tactic now driving 61% of business email compromise, and it costs nothing close to what the 26.5% of billing-update requests that get through are costing the businesses that skip it.

[ OPEN QUESTIONS ]
  1. 01If a long-standing vendor emailed tomorrow asking you to update their bank details, does anyone at your business call them back on a number that wasn't in that email — or would the new account just get used?
  2. 02Is the person who'd approve a vendor payment-detail change the same person who'd receive the request, or is there a second, independent sign-off before the new account is ever paid?
  3. 03Given that 98.5% of vendor email compromise is never reported, would you actually hear about it if a competitor or a peer business in your sector got hit — or would you only find out the hard way?
  4. 04Does your fraud-awareness training still center on the urgent fake-CEO email, when the majority of 2026's business email compromise is now a routine-looking vendor request instead?
  5. 05If $123,000 is the average verified BEC loss and your business has never tested whether a fake billing-update email would get through, is that a risk you've accepted on purpose, or one nobody has actually checked?
[ REFERENCES ]
  1. [1]FBI Internet Crime Complaint Center (IC3) — 2025 Internet Crime Report: 24,768 business email compromise complaints and $3,046,598,558 in reported losses in 2025, up from 21,442 complaints and $2.77 billion in 2024; average verified loss exceeding $123,000; roughly 86% of losses moved via wire transfer or ACH.
  2. [2]Nacha — "FBI's IC3 Finds Almost $8.5 Billion Lost to Business Email Compromise in Last Three Years," summarizing cumulative FBI IC3 data on multi-year BEC losses.
  3. [3]Abnormal AI — 2026 Attack Landscape Report (analysis of ~800,000 email attacks across 4,600+ organizations, July–December 2025): vendor/supplier impersonation at 61% of business email compromise; 44% employee engagement rate on read vendor-impersonation attacks (90% higher than classic BEC); 26.5% compromise rate on billing-account-update requests; over $300M attempted through vendor email compromise in the period; 98.5% of vendor email compromise scams never reported.
  4. [4]CSO Online — "Vendor email compromise: The silent $300M threat CISOs can't ignore," reporting on the same Abnormal AI attack data and its implications for supply-chain-relationship fraud.
  5. [5]Mimecast — "Vendor Email Compromise: Risks, Tactics and Prevention," detailing call-back verification on a previously held phone number and dual-approval controls for vendor payment-detail changes as the standard prevention practice.
[ Could a fake vendor invoice get paid at your business right now? ]

We build vendor-payment workflows where a bank-detail change needs a second approval — not just an email.

Felukaa builds call-back verification and dual-approval sign-off directly into the CRM/ERP systems we set up, so a routine-looking vendor request can't move money on its own. If you don't know whether your current process would catch a convincing fake, we'll walk through it with you before a real one arrives.

Book a free 15-min consultation