Skip to main content

Sep 11, 2026

Open by Design, Vulnerable by Default: What Federal Security Leaders Need to Rethink About Email

The government's greatest strength as an institution, its accessibility, is also its greatest vulnerability. Behavioral AI closes that exposure without closing the door.

The federal government does not get to choose who reaches it. It exists to serve the public, whether they’re filing for benefits from a day-old Gmail account or requesting records through a decade-old AOL address. 

Openness is the design, and it's the right one. However, the consequence is a federal email perimeter that’s porous by definition. 

Email is still the primary channel through which the government engages with the public, meaning agencies have to defend an inbox open to hundreds of millions of people, many of whom carry no security posture of their own. 

Layer onto that a federal landscape more diverse than almost any private enterprise. Over 20 CFO Act agencies carry distinct missions, and what protects the Department of Agriculture looks nothing like the measures that protect the Department of Commerce. Budgets, meanwhile, are often locked in nearly a year before the threats they address even emerge, leaving agencies to defend against this year's problem with last year's money. 

So how does a security leader keep the doors open to everyone, as the mission demands, without handing attackers the run of the building?

You Can’t Lock an Open Perimeter

From nation-state espionage to supply-chain compromise, the inbox is where the most consequential attacks on federal systems tend to begin. Agencies have poured real investment into hardening the perimeter around it, adding multi-factor authentication and endpoint detection and response, yet attacks routed through email keep getting through. 

But openness and security aren’t opposing forces. The tension is a symptom of how security gets built.

Signature-based filters and content inspection—built around flagging known-bad senders, phrases, links, and domains—served agencies well when the threat landscape was slow-moving and predictable. Now it’s a losing battle. Artificial intelligence has brought an entirely new level of speed, sophistication, and polymorphism to cyberattacks, and it allows attackers to calibrate their tactics to the institution they're targeting. Federal processes tend to be public, well-documented, and thick with protocol. Those qualities give an attacker the org chart and workflows to exploit. 

This is why threats are more likely to come from a trusted sender that's been compromised or a convincing impersonation of one. Neither leaves a known-bad signal for a content filter to catch. And there’s no signature for a personalized attack that never repeats.

The Cost of a Compromised .gov Account

In 2025, the FBI IC3 Internet Crime Report identified $3 billion in business email compromise losses. The amount linked to phishing more than tripled, from $70 million to $216 million. Federal email breaches sit inside these figures, but what makes them different from corporate breaches is the trust architecture behind a government service. A message appearing to come from a .gov address is presumed legitimate by every recipient: citizens, contractors, partner agencies, and rule-based email filters. When that trust is weaponized, the blast radius is seismic.

The clearest example is the impersonation of Representative John Moolenaar, chair of the House Select Committee on the Chinese Communist Party. In a campaign attributed to the PRC-linked group APT41, attackers emailed trade groups, law firms, think tanks, and government agencies asking for input on a draft policy, timed to coincide with US-China trade negotiations. The attachment was malware. Moolenaar's own record as a known critic of Beijing gave the message its legitimacy, and the request for input on live policy gave it urgency. The emails also arrived through personal channels that were not protected by the traditional enterprise controls applied to .gov inboxes.

In another notable example, attackers phished their way into the Department of Health and Human Services’ grant payment system in 2023. Once inside, they used fraudulent emails that mimicked trusted personnel to alter payment instructions and redirect payments to themselves. The system's confirmation email for a bank account change went only to the person who had requested it: the fraudster. No one else was ever alerted. The scheme ultimately cost HHS $7.8 million.

Human Vigilance Can’t Keep Pace 

To protect the federal enterprise from attacks like these, agencies must shift their security mindset from safeguarding systems to safeguarding people. In practice, that has come to mean training people to protect themselves. Email is the one workplace application where employees are still expected to be the last line of defense.

That expectation was already unrealistic given the volume of digital communications flowing through an agency. No one can verify the authenticity of the thousands of messages they receive. AI, now generating the most sophisticated social engineering attacks in history, has pushed that expectation past breaking point. 

Microsoft has stated that phishing campaigns embedding AI see click-through rates jump from roughly 12% to 54%, meaning that even a phishing-aware federal employee who once caught nine out of ten attempts will now catch fewer than half.

The Case for Adaptive Defense

Together, these forces make a clear case for adopting defensive AI to strengthen cybersecurity posture across the federal landscape. Behavioral, identity-aware AI learns what normal behavior looks like inside an agency—sign-in locations, device fingerprints, communication styles, vendor networks—well enough to recognize when something deviates from the norm. Abnormal for Federal government stops the phishing, business email compromise, vendor fraud, credential theft, and other sophisticated attacks that legacy systems cannot, without blocking legitimate communication in the process. 

Policy is now catching up to that capability. Executive Order Promoting Advanced Artificial Intelligence Innovation and Security, signed on June 2, 2026, directs federal agencies to strengthen their cyber defenses by deploying frontier AI models defensively. That's a significant shift from where policy has stood for most of the past decade. 

It changes the question facing federal leaders from whether to adopt AI-native defenses to how.

What Federal Security Leaders Can Do Now

If there’s a challenge, it’s institutional inertia. Agencies have built workflows, trained people, and procured tools around the current binary of good and bad, identify and block. Replacing something familiar is a significant, costly ask, even if the replacement is materially better. That friction is how a dangerous status quo persists in good-faith hands.

Overcoming that inertia starts with changing the narrative surrounding defensive AI. Rather than a risk to be managed, it should be framed as a way to secure the ecosystem and improve the lives of the people who depend on it. Four steps can help leaders get there. 

1. Shift your mindset on risk

Agencies are used to producing a risk plan for every new tool they adopt, and an AI system whose reasoning can't be fully documented makes that process harder. The status quo carries risk too, but it feels less significant because it’s so familiar. 

When assessing the risk of behavioral AI, it’s important to recognize that the technology doesn’t remove humans from the loop. It simply handles the voluminous triage so that humans can use their judgment on the decisions that actually need it. 

2. Choose products anchored in depth

There's an assumption that AI-based products are recent bolt-ons, built to chase this year's trend. That assumption falls apart once you check the vendor's history. Abnormal, for example, has been doing behavioral anomaly detection for the better part of a decade, via a purpose-built, cloud-based, AI-native product that protects against novel threats as its core function. A vendor with that expansive track record offers something tried, tested, and proven at scale. 

3. Use ISO/IEC 42001 for assurance 

ISO/IEC 42001, the international standard for AI management systems, gives leaders a framework for evaluating whether a vendor governs its AI responsibly. Vendors that hold it meet rigorous standards for using AI safely, transparently, and in direct service of their customers. When evaluating vendors, look for ISO/IEC 42001 certification as evidence of responsible AI governance. 

4. Start with the simplest use case 

Agencies nudged to embrace AI often read this as a mandate to solve the most complex challenge on the board. The better approach is to start small. Select a well-documented, well-scoped problem—one with so much data that no person could realistically get through it by hand—and use the early win to build the case for the harder work ahead. 

Modern Threats Need Modern Defenses

In 2021, the State Department's cybersecurity team built a custom alert rule to watch for anomalous patterns in email access. It was an early, homegrown version of the behavioral approach to inbox protection. The so-called ‘Big Yellow Taxi’ was developed as a proactive ‘digital tripwire’ after a security analyst noticed a potential vulnerability involving unauthorized application access to cloud email accounts. 

When hackers broke into Microsoft's cloud email systems in the summer of 2023, the Big Yellow Taxi alert triggered. The State Department caught the threat actors downloading roughly 60,000 emails before Microsoft even knew they were in the system. The discovery helped expose a campaign that had reached the inbox of Commerce Secretary Gina Raimondo, along with tens of thousands of other State Department emails. That's a scenario worth learning from, and it's instructive about what proactive security requires: tools like Abnormal’s Behavior AI platform paired with an institutional willingness to invest in dynamic, intelligent defenses. 

Openness is a necessary feature of federal email systems. Their vulnerability comes from a reliance on rules-based security models that can’t keep pace with changing threats. Agencies that close that gap will be the ones still standing and open for business when the next attack arrives.

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.