Key Insights
In late 2025, security researchers began circling a phishing campaign that abused Microsoft Teams OAuth consent flows and was delivered through ordinary-looking calendar invites. It was clean by traditional signals: there was no malware, no flagged domain, no signature a rules engine had ever matched. Attune, Abnormal’s behavioral foundation model, had already been blocking the campaign for two months before external researchers documented it publicly, because the calendar invites and consent requests observed didn't match how those organizations actually behaved.
That gap, two months between "already stopped" and "publicly known," is a preview of where email security is right now.
The Old Defense Assumed Attacks Would Repeat Themselves
Signature-based detection has run on one assumption since the antivirus era: a threat has to exist somewhere first, then be caught, analyzed, and catalogued before a defense can be written for it. It's fast and precise for what it was built for: known-bad file hashes, IPs, domains, YARA patterns. It has also always had a fatal blind spot. It can only stop what it has already seen.
That blind spot used to be a liability. Generative AI turned that liability into a much larger problem by removing the constraints that once limited the scale, speed, and sophistication of novel attacks. What used to take a scammer hours of drafting and rewriting, from matching a company’s tone to referencing a specific vendor relationship and getting the invoice language right, an LLM can now do in seconds, differently every time. Malicious phishing, mobile, and browser-based messages are up 4,151% since ChatGPT's public release in November 2022, according to SlashNext's 2024 Mid-Year Assessment. Abnormal's own 2026 Attack Landscape Report found that more than one in five phishing attacks (21.6%) now route victims through redirect chains, multiple URLs strung together in a way that keeps the final malicious destination one step ahead of link-scanning tools.
Business email compromise (BEC) and vendor email compromise (VEC) make the challenge even harder because there is often no file or link to fingerprint at all. VEC alone now accounts for 61% of all BEC attacks, according to the same 2026 Attack Landscape Report, based on nearly 800,000 email attacks across more than 4,600 organizations. Just a well-timed request, in a familiar voice, asking for something ordinary like an updated bank account, a routine invoice, or a password reset. That ordinariness is what makes it work: billing-account-update requests, such as the ‘we've changed banks, please update our details’ email, carry a 26.5% compromise rate, dramatically higher than routine invoice inquiries at under 1%. That gap shows attackers have learned which lie works, and they're telling it more often. Wire fraud and impersonation are old crimes, but each instance can now be linguistically unique, tailored to its target, and structurally distinct, creating a scenario where a signature has nothing to match against.
When the Content Is Flawless, Behavior Is What's Left To Check
In early 2024, an employee at the engineering firm Arup joined what appeared to be a routine video call with the company's CFO and several colleagues to discuss a confidential transaction. As CNN and CFO Dive later reported, every person on that call besides the employee was an AI-generated deepfake: synchronized video, cloned voices, familiar faces. The employee, who had initially been suspicious, was talked out of that instinct by the call itself and proceeded to make 15 transfers totaling roughly $25 million to accounts in Hong Kong before anyone caught it. The technical signals in that workflow, from the video conferencing platform to the apparent identities of the ‘colleagues’ on the call, looked legitimate. What did not check out was the behavior: a transaction pattern, request type, and sense of urgency that had never appeared in this relationship before.
An attack can now appear flawless, with perfect grammar, accurate context, a legitimate vendor’s compromised inbox, or even a convincing synthetic face. Once that happens, content stops being a reliable signal. The question that still works is a different one: does this behave like the patterns we already trust for this person, this vendor, this relationship? Answering that is now a measurement problem. Measuring ‘normal’ at scale requires representing identity, relationships, and communication in a form that can be mathematically compared. That representation is called an embedding.
Signatures Are the Floor, Not the Ceiling
None of this makes signature-based detection worthless. Known-bad hashes and blocklisted domains still stop the high-volume, low-effort, commodity attacks efficiently. Abnormal’s position since its founding has been that signatures are the floor, not the ceiling. They handle what's already been seen. Everything above that floor, including sophisticated, targeted, AI-assisted attacks that are novel by construction, requires a system built to measure deviation from normal behavior, since there's often no attack pattern left to recognize in the first place. Behavioral detection reduces that risk; it doesn't eliminate it. It's built for the part of the threat landscape signatures structurally can't reach.
Eight years ago, before generative AI truly raised the stakes, Abnormal made the bet that behavior would prove to be a more durable signal than threat intelligence alone. Attune, Abnormal's behavioral foundation model, is the latest iteration of that bet. As of its March 2026 launch, Abnormal reported that Attune was trained on more than 1 billion derived behavioral signals, powered roughly 85% of attack detections across the platform, and operated with 50% higher precision than previous models. A model still has to learn what "normal" looks like for a specific person, a specific vendor relationship, and a specific organization well enough to catch a moment of abnormality inside an otherwise flawless message.
Embeddings are what make that possible: the mechanism that turns "this seems off" into something a model can actually compute. In the next post in this series, we'll open up what an embedding actually is, why embeddings became so important to modern language models, and how a wire-fraud email with completely different wording from a known attack can still stand a much better chance of getting caught because, mathematically, it sits right next to it.
Request a demo to watch the Abnormal behavioral model catching exactly this kind of attack against a live inbox.
Schedule a Demo
Part 2 of this series: "What Is an Embedding? The Math Behind Behavioral AI" is coming in October.
