By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “Cybersecurity Awareness in Action: How 44% of VEC Attacks Engage Employees” (June 26, 2026)

TL;DR: Up to 44% of vendor email compromise messages trigger a reply or forward, with engagement climbing higher in the largest enterprises, according to Abnormal AI, underscoring how routine-looking social engineering still bypasses human judgment and reporting discipline. The practical issue is not awareness alone but whether identity, process, and detection controls can interrupt action before trust turns into exposure.


At a glance

What this is: This is Abnormal AI’s analysis of BEC and VEC engagement, showing that up to 44% of messages trigger a reply or forward and that larger enterprises see even higher engagement.

Why it matters: IAM and security teams need to treat email trust as an identity-risk problem, because social engineering succeeds when human judgment, process controls, and detection fail together.


Context

BEC and VEC are email-based social engineering schemes that rely on trust, familiarity, and urgency rather than technical exploitation. The identity problem is not just whether a message is malicious, but whether a user, a process, or an approval path will treat it as legitimate long enough to act.

According to Abnormal AI, those interactions continue to work at scale: analyst noise, repeat engagement, and weak reporting discipline allow routine-looking messages to survive longer in the workflow than they should. That makes email trust part of the broader identity and access control surface, especially in vendor-heavy environments and high-pressure business roles.


Key questions

Q: How should security teams reduce business email compromise risk beyond secure email gateways?

A: They should add controls that operate after delivery and after user interaction, because BEC usually succeeds by exploiting trust and workflow, not by delivering obvious malware. That means mailbox monitoring, identity-aware verification for financial requests, and escalation paths that do not depend on a single email being trusted. The strongest programmes treat email as an identity and process problem, not just a filtering problem.

Q: Why do familiar-looking BEC and VEC emails still lead to action?

A: They work because the attacker exploits routine, urgency, and pre-existing trust in vendor communication. When the message fits the recipient’s normal workflow, people are more likely to reply or forward it before they verify the request. That is why controls need to interrupt action, not only improve awareness.

Q: What are the signs that email trust controls are failing?

A: Repeated replies to suspicious requests, high forward rates, weak reporting discipline, and inconsistent escalation around vendor changes are all warning signs. If analysts see lots of noise but few confirmed reports, attackers may be succeeding because the organisation is not distinguishing routine messages from risky ones quickly enough.

Q: What should teams do when BEC or VEC targets finance and procurement roles?

A: Prioritise those roles for contextual training, stricter approval checks, and behaviour-based detection because they sit closest to payment and vendor-change decisions. The issue is not just awareness. It is whether the workflow forces verification before the request can become a financial action.


Background and context

Why BEC and VEC succeed against human trust

BEC and VEC exploit the gap between message authenticity and human perception. The attacker does not need malware if the email looks routine, references a plausible vendor relationship, and creates enough pressure for a reply or forward. In identity terms, the sender is trying to borrow trust from the recipient’s working context, then convert that trust into an action that bypasses independent verification. The article’s 44% engagement figure shows that this is not a fringe outcome. It is a repeatable social engineering pattern that survives because business communication is built to move quickly.

Practical implication: Treat trust validation as part of access control, not just user awareness.

How engagement turns email into business risk

A reply or forward is often the first material compromise outcome in BEC and VEC because it confirms that the attacker has found a responsive target. From there, the conversation can shift into invoice fraud, impersonation, vendor detail extraction, or payment redirection. The problem scales in larger enterprises because more contacts, more vendors, and more delegated workflows create more chances for a plausible request to land. Analysts then face a second issue: repeated low-signal events can hide the real ones, which delays containment and lets the attacker keep iterating on the social path that worked.

Practical implication: Measure response-to-reporting gaps as a leading indicator of business email compromise exposure.

Why behavior-based detection matters more than inbox filtering alone

Traditional email filtering can reduce obvious spam, but BEC and VEC are designed to look legitimate enough to pass basic controls. Behavior-based detection focuses on the transaction patterns around the message, including unusual sender-recipient relationships, requests that deviate from normal vendor behavior, and replies that carry financial or credential risk. That is especially relevant when the attack targets high-pressure roles, because urgency can override caution even when the content is familiar. The technical lesson is that the detection problem is contextual, not purely content-based.

Practical implication: Combine contextual detection with vendor verification workflows before payment or data disclosure.


NHI Mgmt Group analysis

BEC and VEC are now identity control problems, not just email hygiene problems: The article’s central finding is that familiar-looking messages still produce action at meaningful rates, which means the weak point is the trust boundary around a human identity, not only the inbox. In practice, email verification, vendor callback procedures, and behavioural monitoring must be treated as part of access governance. The practitioner conclusion is simple: if a request can move a person into action without independent validation, it is already inside the control gap.

44% engagement is a workflow failure signal: When nearly half of messages can trigger a reply or forward, the issue is not isolated user error but a system that allows low-friction escalation from message receipt to business action. That is especially true in large enterprises, where scale increases the number of plausible relationships an attacker can imitate. The implication is that reporting, triage, and contextual blocking need to interrupt the action path before a human response becomes an operational decision.

Vendor-heavy industries create a higher-trust attack surface: The more external counterparties a team handles, the easier it is for attackers to disguise a request as business as usual. That makes vendor identity verification a governance requirement, not an optional awareness exercise. The practitioner takeaway is to align process controls with the actual communication pattern of the business, because attacker success depends on exploiting routine.

Human trust needs machine-assisted guardrails: Security teams cannot rely on training alone when urgency, familiarity, and noise are built into the workflow. Behaviour-based detection should flag unusual requests, but response procedures must also make it easy for staff to verify a request without slowing legitimate work. The conclusion is that BEC and VEC resilience comes from coupling human judgement with contextual controls, not from awareness messaging by itself.

What this signals

Email trust debt: Repeated exposure to routine-looking requests creates a trust pattern that attackers can reuse across vendors, roles, and business units. Security teams should treat every successful reply to a suspicious message as evidence that process friction is too low for the risk profile.

The practical response is to move verification closer to the decision point. If staff can change payment instructions or vendor details without independent confirmation, BEC and VEC will continue to scale faster than awareness programmes.

Behaviour-based detection matters because the decisive signal is not the text of the email alone. It is the combination of sender history, requested action, and whether the communication matches normal business context.


For practitioners

  • Strengthen vendor verification workflows Require callback or secondary-channel confirmation for any payment change, bank detail update, or sensitive vendor request before action is taken.
  • Instrument response-to-reporting metrics Track how often suspicious emails are replied to, forwarded, or escalated before they are reported so you can see where trust is turning into exposure.
  • Deploy behavior-based email detection Use contextual signals such as sender-recipient history, request type, and unusual timing to flag messages that look legitimate but deviate from normal business behavior.
  • Target high-pressure roles with contextual training Focus training on finance, procurement, executive support, and other vendor-heavy roles where attackers can exploit urgency and routine communication patterns.

Key takeaways

  • BEC and VEC remain effective because attackers exploit trust already embedded in normal business communication.
  • The article reports up to 44% of vendor email compromise messages trigger a reply or forward, with higher engagement in the largest enterprises.
  • Vendor verification, contextual detection, and fast reporting paths are the controls most likely to interrupt the attack before financial exposure occurs.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-10 — Human Use of NHIThe article centres on human trust being abused through business email workflows.
Recommendation — Reduce reliance on informal trust and require independent verification for risky email-driven actions.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe issue is when people are authorised by habit rather than verified intent.
Recommendation — Tighten approval and authorisation checks before email requests can trigger business actions.
NIST SP 800-63SP 800-63C — FederationVendor trust and identity assertions are central to email-based impersonation risk.
Recommendation — Treat cross-organisational trust assertions as verification points, not assumptions.
MITRE ATT&CKTA0001;TA0006 — Initial Access; Credential AccessBEC and VEC use trusted communication to obtain engagement and sometimes sensitive data.
Recommendation — Map suspicious reply and forward patterns to initial-access and credential-access tactics.

Key terms

  • Business email compromise: A form of social engineering where an attacker impersonates a trusted person or domain to manipulate payment, change banking details, or extract sensitive information. It often succeeds without malware because the attacker targets process trust and human judgement instead of technical controls.
  • Vendor Email Compromise: Vendor email compromise is a form of impersonation that targets supplier, contractor, or partner relationships. Attackers exploit routine vendor communication patterns to request payment changes, invoice redirection, or other sensitive actions, so identity and process verification must extend beyond internal users.
  • Behavioral Detection: A monitoring approach that looks for unusual activity rather than relying only on static inventories. For SaaS integrations, it detects drift in token use, data movement, timing, and endpoint behavior so teams can spot compromise, misuse, or automation that no longer matches its expected pattern.
  • Reusable Verification: Reusable verification is a model where a person completes an identity proof once and can then use that verified status across multiple services. It improves user experience and consistency, but only works well when the underlying trust model, consent, and privacy controls are strong enough to prevent unnecessary data sharing.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org