U.S. Department of Energy National Lab Strengthens Email Defenses with Abnormal's Behavioral AI
A U.S. Department of Energy national laboratory closes gaps its native email protection defenses miss with behavioral AI.

emails analyzed per month by Abnormal
advanced attacks stopped by Abnormal in one month
calendar invite attacks stopped by Abnormal in one month
A U.S. Department of Energy national laboratory established in 1931 conducts open research across biosciences, computing sciences, earth and environmental sciences, energy sciences and technologies, and physical sciences. Its staff collaborates with students and researchers worldwide, many connecting electronically from outside institutions.
The Lab Challenge: An Open Mission, a Wide Attack Surface
The Lab's security team relied on native email protections, but sophisticated attacks increasingly slipped past them, matching no known signature or bad-reputation indicator. Closing the gap meant hand-tuning rules and allow-and-block lists, consuming time the team couldn't spare. Advanced attacks reaching inboxes included internal-domain spoofing and malware links disguised as trusted file-share services. Compromised supplier accounts and fraudulent invoices targeting procurement and grant staff were a growing concern, and grant administration and vendor communication flowing through email widened the attack surface further. That's when the Lab turned to Abnormal.
Customer Key Challenges:
- Advanced, first-seen attacks bypassed native filtering.
- Vendor and partner email compromise targeted procurement and grant staff.
- Manual rule-tuning and phishing triage consumed security engineers' time.
Abnormal Solution:
- API-native deployment, no mail routing or MX changes, no agents installed.
- Behavioral AI that builds a baseline of normal communication for every identity, vendor, and interaction.
- Autonomously detects and remediates advanced threats, including malicious calendar invites.
"We were seeing attackers use generative AI to create unique, targeted, and well-written phishing lures, and there wasn't any static IOC we could use to catch them. We needed to do text analysis of the email bodies and AI was the way we were going to do that at scale." — Michael Smitasin, Cybersecurity Engineer, US Department of Energy National Laboratory
The Abnormal AI Solution
The Lab deployed the Abnormal Behavioral Security Platform through an API-native proof of value that required no mail routing changes, MX updates, or agents. Abnormal's models learned what normal looked like for the Lab within 24 hours, and the evaluation surfaced techniques native filtering missed: spear-phishing messages spoofed from internal-looking domains to impersonate colleagues, and malware links disguised as trusted file-share services that returned zero detections against standard threat-intelligence scanning. Attackers also used calendar invites to place malicious content directly on employee calendars, a delivery method native filtering rarely inspects.
Why The Lab Chose Abnormal
Inbound Email Security now catches attacks carrying no known signature or bad-reputation indicator, the exact gap that let sophisticated threats slip past native filters before Abnormal arrived. Because detection runs on behavior rather than blocklists, the Lab doesn't have to restrict the external collaboration its research relies on, or add friction to a decentralized IT environment where every new dependency carries cost. Behavioral baselining is automated and continuously self-adjusting, reducing the security team's manual tuning workload. In August 2026, Abnormal autonomously remediated more than 3,200 malicious emails and 200 calendar invite attacks, all of which bypassed native security detection. This automated protection continues to free security engineers from the hand-tuned rules and allow-and-block lists that used to eat into their higher-value work.
Openness and Security, Without Tradeoffs
For a lab whose work depends on welcoming collaborators from outside its walls, security can't come at the cost of that openness. Abnormal gives the Lab's team a way to close gaps in its native defenses without adding friction to the grant administration, vendor communication, and cross-institution research that flow through its inboxes every day. As the Lab's impact continues to advance, Abnormal's behavioral AI continues to detect deviations from what is normal for every identity connected to the organization.
"This was the easiest POV and integration I've done in the last 8 years, and saving people's time and effort on spam and phishing emails has a real impact on the Lab community." — Michael Smitasin, Cybersecurity Engineer, US Department of Energy National Laboratory
Abnormal Products in Use:
- Inbound Email Security
- Industry
- Government
- Headquarters
- California
- Protected Mailboxes
- 5,000
Related Customer Stories

Sutter County Safeguards Critical Public Services with Abnormal AI
A California county government uses Abnormal AI to fight AI-driven email attacks with a small IT team across 1,100 users.

LCI Automates Advanced Email Defense with Abnormal AI
California's land use and climate agency built its own dedicated security program from scratch after being empowered to stand up independent IT infrastructure.
See What Abnormal Catches for You
Get a personalized demo mapped to your industry and risk profile.
