TL;DR: Secure email gateways struggle to detect modern socially engineered email attacks as cloud migration changes the threat model, according to Abnormal AI’s webinar on how its detection approach uses identity, behavior, and content analysis. The core issue is that email security still assumes static indicators will catch attacks that now exploit trust, context, and user behaviour.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “How Abnormal Blocks Socially-Engineered Attacks”.
Key questions
Q: Why do traditional email gateways miss some advanced email attacks?
A: Traditional gateways are built to detect known-bad content, infrastructure, and attachment patterns.
Q: How should security teams detect email attacks that look legitimate at first glance?
A: They should combine behavioural intelligence with identity and collaboration telemetry, then look for deviations from normal sender relationships, message timing, forwarding behaviour, and delegated access.
Practitioner guidance
- Correlate sender identity with message context Use sender reputation, account history, and recipient relationship data together so security decisions are not based on content alone.
- Add behavior signals to mail detection Track deviations in sending cadence, conversation patterns, and workflow timing to identify messages that look normal in isolation but abnormal in sequence.
- Review cloud email workflows for trust assumptions Map where users move between email, identity, and collaboration tools so detection controls can account for the broader context in which attacks succeed.
Bottom line: Socially engineered email attacks now succeed by exploiting trust, context, and normal communication patterns rather than obvious malicious indicators.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Legacy email security is breaking because it treats message content as the primary trust signal. That assumption worked when obvious phishing artifacts dominated, but socially engineered attacks now mimic normal business communication and exploit the credibility of cloud-based workflows. The practical conclusion is that mail security has become an identity problem as much as a content problem.
A question worth separating out:
Q: What is the difference between content-based email filtering and identity-aware detection?
A: Content-based filtering looks for malicious links, attachments, or known patterns inside a message. Identity-aware detection also evaluates who is sending, how they normally behave, and whether the communication pattern fits the organisation’s baseline. That broader view is better for spotting BEC, impersonation, and account takeover attempts that do not rely on obvious malware.
👉 Read our full editorial: Legacy email security fails against socially engineered attacks