Key Insights
In our 2026 Attack Landscape Report, Abnormal analyzed nearly 800,000 attacks across thousands of organizations, finding that email threats are growing more personalized and tailored to their targets. Other flagship research, including Verizon's 2026 DBIR, shows email is one of several domains attackers now prioritize. Shadow AI has become the third most common non-malicious insider action in Verizon's data loss prevention dataset, a fourfold increase from the previous year.
Against this expanding threat landscape, email is where Abnormal's behavioral AI first proved its value in stopping sophisticated attacks. Here's how that same model now extends to identity, AI, and insider threats, the surfaces defining what's next.
Schedule a Demo
Email: The Proving Ground
Email gives attackers a direct line to every identity in an organization, along with access to sensitive communications and institutional knowledge. It’s also deeply embedded in how organizations verify identity and manage access, which makes it one of the most exploited attack vectors, historically and today.
Email is where Abnormal first developed the Abnormal Behavioral Security Platform, modeling normal behavior across employees, vendors, contractors, and partners by analyzing behavior, identity, and content together. It’s also where that approach has the longest track record.
Outcome: Abnormal uncovers more than 1,200 attacks per 1,000 mailboxes each month that bypass upstream gateways.1
Behavioral AI: The Differentiator
Many vendors bolt AI onto existing tools, so the model inherits those tools' blind spots. Abnormal was founded in 2018 as an AI-native company, with behavioral AI built into detection, investigation, and remediation from day one.
Attune, Abnormal's behavioral AI foundation model, brings identity, behavior, and content analysis together in a single model. Trained on more than 1 billion derived behavioral signals over 8 years, it powers roughly 85% of detections across the Abnormal Platform today, and it's what lets it stop breaches autonomously and free up time for higher-value work.2
Outcome: For customers like Knox County Schools, that same design helps automatically stop an average of 5,800 advanced attacks a month while freeing up more than 200 hours of manual triage on user-reported phishing emails.
One Model, New Surfaces
That same behavioral AI extends naturally beyond the inbox to identity systems, AI tools, and hiring pipelines. These surfaces are already popular targets, as Verizon's DBIR findings reveal, and like email, they resist detection based on known-bad signatures or indicators of compromise.
That continuity is what enabled Abnormal to unveil three new products, each built on the same behavioral foundation as email security:
Identity Threat Protection: Reduces identity risk and prevents compromise across email, identity, and SaaS.
AI Governance: Sees your AI tools, agents, and chat context using email, OAuth, identity, and browser signals to score the risk and enforce policy automatically.
Infiltration Prevention: Analyzes applicant tracking system (ATS) signals designed to catch fraudulent candidates, including synthetic identities and nation-state operators, before they gain access.
Outcome: The same behavioral model already protecting 4,500+ organizations' inboxes now covers identity, AI, and hiring risk, with no new platform to deploy.
The Advantage Multiplies
Fragmented tools create fragmented visibility, and attackers move fastest through the gaps that leaves. Every new surface Abnormal's behavioral AI covers—identity, AI tools, hiring—feeds the same model that started with email, making it sharper everywhere it runs. That's the advantage of one behavioral model over a stack of point solutions: it only gets better as it covers more ground.
See how one behavioral model can cover it all. Schedule a personalized demo.
Schedule a Demo
1, 2 Based on internal Abnormal data

