TL;DR: Email-based cyberattacks are getting more convincing by combining public data, executive impersonation, vendor spoofing, and malicious third-party integrations, according to Abnormal AI. The governance gap is not just email filtering but identity trust across human, vendor, and application channels.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “3 New Ways Cybercriminals Are Targeting Your Organization”.
Key questions
A: Email alone does not prove who sent the message or whether the content was changed in transit.
A: These attacks work because familiarity lowers suspicion.
Practitioner guidance
- Harden executive-request verification Require secondary validation for payments, access changes, and sensitive approvals that appear to come from executives, even when the email style looks familiar.
- Validate vendor contact paths Maintain approved vendor contacts outside normal inbound email threads and compare any request against those records before acting on it.
- Inventory mailbox integrations Review every third-party application or integration with mailbox access, document its scope, and remove access that no longer has a current business purpose.
Bottom line: Email impersonation now succeeds by abusing trust relationships, not only by bypassing spam filters.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Email impersonation has become an identity governance problem, not just a phishing problem. The article shows that attackers now combine public data, executive mimicry, and vendor spoofing to make messages feel legitimate. That shifts the control question from message hygiene to whether organisations can verify sender identity, relationship legitimacy, and authority before action is taken. The practitioner conclusion is that email security, IAM, and third-party trust controls can no longer be managed as separate domains.
A question worth separating out:
Q: How should security teams govern email trust across users, vendors, and apps?
A: Treat it as a cross-domain identity problem. Human recipients, vendor relationships, and mailbox-connected applications all need separate verification, lifecycle review, and offboarding paths. If those controls are split across teams, attackers can exploit the gaps between them.
👉 Read our full editorial: Email impersonation risks are expanding across vendors and integrations