TL;DR: Anticimex blocked more than 40,000 malicious emails that Microsoft missed between February and April, avoiding an estimated $169,000 in losses through AI Security Mailbox automation and graymail filtering, according to Abnormal AI. The bigger lesson is that email defence built for older threat volumes and patterns is no longer keeping pace with AI-accelerated attacks.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Threats without Borders: Insights from the Stockholm AI Roadshow”.
Key questions
Q: Why do native email protections miss AI-powered phishing campaigns?
A: Native email protections often depend on known indicators, reputation, and repeatable patterns.
Q: How should security teams respond when AI makes business email compromise harder to spot?
A: Teams should move beyond message inspection and verify the requester, the channel, and the business context before allowing action.
Q: What signs show that email identity controls are not keeping pace?
A: Watch for stale shared mailboxes, persistent delegated send permissions, accounts that remain active after role change, and alerts that show unusual sending behaviour from trusted identities.
Practitioner guidance
- Strengthen behavioural email detection Prioritise message analysis that looks at sender behaviour, conversation patterns, and abnormal intent rather than only known bad indicators.
- Reduce inbox noise with graymail controls Separate low-value mail from genuinely risky mail so analysts and users are not forced to inspect every message at full volume.
- Treat email as an identity risk signal Feed suspicious mail events into account monitoring, access review, and response workflows so phishing and compromise signals are not handled in isolation.
Bottom line: AI-powered email attacks are now outrunning controls built for static threat patterns and lower message volume.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Email security built for static threat volumes is now a governance problem, not just a filtering problem. AI-generated attacks shorten the defender’s decision window and increase the number of messages that must be evaluated. That shifts the burden from user judgement to control design, especially where email is an upstream identity control point. Security leaders should treat inbox filtering as part of identity risk management, not an isolated mail issue.
A question worth separating out:
Q: What should teams do after malicious email reaches users despite native protection?
A: Teams should review the message path, identify which detection stage failed, and connect mailbox events to account and identity monitoring. The point is to contain the exposure chain, not just delete the email after the fact. If the message was credible enough to trigger interaction, response should extend beyond the inbox.
👉 Read our full editorial: AI-powered email attacks are outpacing native Microsoft protections