TL;DR: EAB says its security team blocked thousands of phishing and business email compromise attacks across a partner ecosystem of 2,500+ education institutions after modernising email security and moving away from a legacy SEG, according to Abnormal AI. The case shows why email-layer controls now need to be judged on ecosystem reach, not inbox filtering alone.
At a glance
What this is: Abnormal AI’s webinar case study says EAB modernised its email security stack and blocked thousands of phishing and BEC attacks across a partner ecosystem of 2,500+ education institutions.
Why it matters: It matters because email security for distributed ecosystems has to reduce attack reach across partners and executives, not just filter inbox spam for one organisation.
Context
EAB’s case is about email security in a distributed partner ecosystem, not a single mailbox environment. The central problem is that phishing and business email compromise can target executives, IT teams, and partner institutions at the same time, so legacy SEG-era thinking often underestimates how far the blast radius extends.
For IAM and security teams, the governance question is whether email-layer controls are still being evaluated as inbox filters or as ecosystem controls. When the threat includes vendor email compromise and partner-facing scams, the control has to be judged on reach, behavioural detection, and operational overhead, not gateway throughput alone.
Key questions
Q: How should security teams reduce the impact of phishing and BEC on human users?
A: Combine user education with technical controls that limit what a mistaken click or reply can do. Focus on out-of-band verification for sensitive requests, mailbox restrictions, conditional access, and fast reporting paths. Awareness works best when the organisation assumes some users will be deceived and designs containment around that reality.
Q: Why do legacy SEG controls miss business email compromise in distributed organisations?
A: Legacy SEG controls are often tuned to content, reputation, and perimeter filtering, but BEC frequently uses legitimate-looking communication and trusted relationships. In distributed organisations, that creates a gap between what the gateway can see and how attackers actually abuse trust. When the ecosystem is large, the filter is not enough.
Q: What signs show that email security is not keeping up with partner-facing attacks?
A: Common signs include repeated phishing attempts that reach multiple institutions, heavy reliance on manual review, and growing executive or IT time spent handling suspicious email. If the programme only measures inbox filtering success, it may miss ecosystem-level abuse paths that attackers can keep reusing.
Q: How should security teams handle vendor email compromise in enterprise environments?
A: Security teams should treat vendor email compromise as a trust and lifecycle problem, not only a phishing problem. The practical response is to maintain a living inventory of active vendor relationships, tie approvals to behavioural risk signals, and add independent verification for payment or account-change requests that arrive through trusted third-party channels.
Background and context
Why legacy SEG filtering misses partner-facing email abuse
A secure email gateway is built to inspect mail at the perimeter, but that model assumes the main problem is malicious content arriving at a single inbox. In partner ecosystems, attackers can exploit trusted relationships, impersonation, and vendor email compromise to make malicious messages look operationally routine. Once that happens, the issue is not just detection of bad attachments or links, but whether the control can recognise suspicious behaviour across many connected domains, users, and workflows. That is why SEG-era controls often struggle when the attack surface is organisational rather than purely technical.
Practical implication: evaluate email control coverage against partner trust paths, not just inbound message filtering.
Behavioural email security versus pattern-based filtering
Pattern-based filtering looks for known signatures, sender reputation, or static indicators, which is useful but narrow. Behavioural email security instead looks for anomalies in sender behaviour, account usage, impersonation patterns, and unusual message intent. That matters for phishing and BEC because these campaigns often use legitimate infrastructure, social engineering, and patient staging rather than obvious malware. In a partner ecosystem, that behavioural layer becomes more important because the attack is often designed to blend in with normal operational traffic and to bypass controls that rely on content alone.
Practical implication: measure whether your email stack can detect abnormal behaviour before relying on indicators that attackers can mimic.
Why vendor email compromise is an ecosystem problem
Vendor email compromise is not just a mailbox event. It is a trust-chain problem where a compromise in one organisation can be used to reach many others through invoices, requests, approvals, or credential-reset workflows. In that model, identity and email security converge because the attacker is abusing trusted communication, not only a message channel. EAB’s case reflects that reality: if a partner ecosystem is large enough, the control objective shifts from blocking isolated phishing messages to limiting how much trust any single message can exploit across the ecosystem.
Practical implication: treat partner email trust as a governance boundary and map where one compromised sender can influence many recipients.
NHI Mgmt Group analysis
Legacy SEG design assumes the inbox is the unit of control. That assumption breaks in partner ecosystems where one sender relationship can influence many organisations at once. EAB’s case shows that email security is no longer a single-org filtering problem, but a trust-boundary problem across institutions. Practitioners should evaluate controls by how much of the ecosystem they can protect, not by how many messages they can scan.
Vendor email compromise is a governance issue, not only a detection issue. When a trusted partner channel is abused, the control failure is often the absence of ecosystem-level visibility into who can impersonate whom, and where message trust becomes unsafe. The practical implication is that email security programmes need to be measured against cross-organisational trust paths, not just mailbox hygiene.
Behavioural detection is now the baseline for email-layer resilience. Static filtering can still help, but it does not answer the modern question: can the control identify abuse when the message itself looks operationally normal? In large education ecosystems, that difference determines whether security teams are reacting to spam volume or actually reducing compromise opportunity.
Identity security and email security are converging at the trust boundary. BEC works because the attacker weaponises a believable sender, a believable request, and a believable workflow. That means the security model has to account for human identity, organisational trust, and messaging controls together. The implication for practitioners is clear: email defence must be designed as part of identity governance, not treated as a standalone gateway problem.
Ecosystem scale changes the economics of control selection. A control that is adequate for one inbox may be structurally inadequate when it has to protect thousands of partner relationships. The named concept here is ecosystem email blast radius: the number of organisations and workflows a successful email abuse attempt can touch before containment. Practitioners should use that lens when reviewing email security architecture.
What this signals
Ecosystem email blast radius: The useful metric is no longer how many suspicious messages a gateway blocks, but how many partner organisations and workflows a message could reach before containment. In distributed education, healthcare, and supply-chain environments, that shift changes how security teams justify email investment and evaluate residual risk.
Abnormal AI’s case reinforces a broader programme lesson: email security now sits inside identity governance because attackers abuse believable senders, believable requests, and believable trust. Teams that still treat SEG performance as the primary success metric will keep underestimating BEC exposure across partner networks.
For practitioners
- Measure partner blast radius Map how far a compromised or spoofed sender can reach across partner institutions, executives, finance teams, and support workflows before delivery controls intervene.
- Test for vendor email compromise paths Run scenarios that use trusted partner branding, invoice language, and approval requests to see whether the stack blocks abuse before a recipient can act.
- Shift from content filters to behaviour signals Check whether detection looks for unusual sender behaviour, abnormal communication patterns, and impersonation rather than only static indicators and known bad content.
- Review operational time saved by consolidation Confirm whether reducing email security tool sprawl actually frees up executive and IT time, and whether those gains hold during periods of elevated phishing and BEC activity.
Key takeaways
- EAB’s case shows that email compromise in partner ecosystems is a trust-boundary problem, not just an inbox-filtering problem.
- The article says thousands of phishing and BEC attacks were blocked, which underscores how large the attack surface can be in a 2,500+ institution network.
- Practitioners should evaluate email controls on behavioural detection and ecosystem reach, then map where trusted workflows can be abused.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-10 — Human Use of NHI | Email abuse succeeds by exploiting human trust in communication from systems and partners. |
| Recommendation — Reduce human reliance on email as an implicit approval channel for financial and operational requests. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about who can trigger operational actions through trusted messages and workflows. |
| Recommendation — Review who can trigger business actions from email and tighten PR.AA-05-style authorisation boundaries. | ||
| MITRE ATT&CK | TA0001; TA0006; TA0008 — Initial Access; Credential Access; Lateral Movement | Phishing and BEC are the primary attack paths discussed in the article. |
| Recommendation — Map phishing and BEC scenarios to TA0001, TA0006 and TA0008 to prioritise detection across the trust chain. | ||
Key terms
- Business email compromise: A form of social engineering where an attacker impersonates a trusted person or domain to manipulate payment, change banking details, or extract sensitive information. It often succeeds without malware because the attacker targets process trust and human judgement instead of technical controls.
- Secure Email Gateway: A secure email gateway is a control layer that inspects email before it reaches users and can also inspect outbound mail. It filters malicious content, enforces policy, and reduces exposure to phishing, malware, and data leakage, but it does not replace identity governance or account monitoring.
- Vendor Email Compromise: Vendor email compromise is a form of impersonation that targets supplier, contractor, or partner relationships. Attackers exploit routine vendor communication patterns to request payment changes, invoice redirection, or other sensitive actions, so identity and process verification must extend beyond internal users.
- Ecosystem Blast Radius: Ecosystem blast radius is the number of organisations, users, and workflows that can be affected when a trusted identity or communication path is abused. In distributed environments, it is a better measure of email and identity risk than inbox filtering rates alone.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org