Legacy email security breaks when it depends on known bad indicators such as suspicious URLs, attachments, or obvious malware. Contextual phishing succeeds by looking like ordinary work, so the real failure is that the control stack does not verify the human decision behind the message. Detection has to shift toward identity, workflow, and behavioural anomalies.
When the email looks routine, what actually fails?
The break is not the inbox filter alone, it is the assumption that a suspicious URL or attachment is required before an attack deserves attention. When a message fits normal work patterns, the defender has to evaluate whether the request, sender relationship, timing, and workflow context are credible, not just whether the content contains obvious malware.
That is why ordinary-looking phishing often succeeds against controls built for malicious artifacts. The attacker is borrowing trust from everyday business communication, so the real weakness is a detection model that treats “looks clean” as the same thing as “safe.”
Why contextual phishing survives legacy controls
Contextual phishing works because it imitates the language and cadence of legitimate operations: invoice approvals, payroll changes, vendor updates, document shares, or internal handoffs. Those messages may never trigger attachment sandboxes, URL reputation checks, or malware signatures, so the control stack never gets a strong technical indicator to block.
In practice, the attack is aimed at the decision point, not the payload. A user who believes the message belongs to an existing workflow may approve an action, forward a file, disclose a code, or transfer funds without ever encountering a “bad link” warning. For that reason, Mailchimp breach 2022 is a useful reminder that social engineering can succeed by abusing ordinary internal processes, not just by delivering obvious malicious content.
Phishing also becomes harder to catch when it leverages trusted identities or trusted platforms. Microsoft verified publisher OAuth phishing 2022 shows how a message can look legitimate enough to obtain real access through consent rather than deception by link alone.
What detection has to measure instead
If the message body no longer gives you away, the detection problem shifts to anomalies in identity, workflow, and behaviour. Look for requesters who suddenly change payment details, accounts that receive unusual consent prompts, mailbox actions that diverge from normal business flow, or approvals that arrive from unexpected devices, locations, or time windows.
This also changes the value of email security telemetry. You still want authentication, filtering, and domain protections, but you need correlation with mailbox activity, identity events, and downstream business actions. For example, Email Identity and BEC Guide is directly relevant because it frames email authentication and payment verification as linked controls, not separate silos.
Where the message initiates a cloud or SaaS action, control the authorization path as well as the inbox. CoPhish OAuth phishing via Copilot Studio shows why consent, token issuance, and mailbox access are often the real exploitation steps behind a convincing message.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST SP 800-63 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Email-driven impersonation and consent abuse hinge on user authentication strength. |
| AU-6 — Audit Record Review, Analysis, and Reporting | Behavioral anomalies in mailbox and workflow activity require reviewable audit signals. | |
| IA-5 — Authenticator Management | Contextual phishing often targets credentials, tokens, and mailbox access paths. | |
| Recommendation — Enforce strong user authentication before allowing sensitive email-linked actions. Review mailbox and workflow logs for unusual approvals, consents, and transfers. Rotate and protect authenticators that can be used to approve or redirect business actions. | ||
| NIST SP 800-63 | Digital Identity Guidelines | Phishing-resistant authentication directly addresses trust failures in deceptive email-driven access. |
| Recommendation — Adopt phishing-resistant authenticators for sensitive user and administrator access. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Business email compromise frequently abuses access paths and approval authority. |
| Recommendation — Restrict and review access paths that can authorize payments, consents, or mailbox changes. | ||
Practitioner Guidance
What to verify: Treat any request that matches a known business process as suspicious until you can verify who initiated it, which workflow it belongs to, and whether the request path is normal for that relationship. The key question is not “does the email look malicious?” but “would this identity normally trigger this action this way?”
Decision rule: If the content is plausible but the requested action is high impact, require secondary verification outside the email thread before approving payment, access, token consent, or account change. If the action is low impact, monitor for reuse of the same wording, sender pattern, or timing across multiple targets, because that often signals an active campaign.
What practitioners underestimate: The most dangerous messages are often the ones that create no obvious security event at all. When the message simply nudges a human into doing the wrong thing, the best signal may be the business process itself drifting away from its normal pattern.
Practitioner takeaway: Defend the decision chain, not just the message content, because contextual phishing succeeds when legitimacy is inferred from routine business context rather than verified from independent evidence.
Related resources from NHI Mgmt Group
- How should security teams handle AI-generated phishing that looks like normal business mail?
- What breaks when email security only looks for malicious exfiltration?
- What breaks when phishing targets Signal or WhatsApp accounts instead of email?
- What breaks when a compromised mailbox is treated like a normal email problem?