Skip to main content
Join Us at our First In-Person User Conference.Register for our Dallas event today

Sep 23, 2026

The New Email Attack Playbook: Weaponizing Trusted Behavior

Five emerging shifts in the attack playbook reveal how threat actors exploit the systems, identities, workflows, and behaviors employees already trust.

Email attacks are no longer defined by malicious attachments, obvious spoofing, or suspicious links. Increasingly, the most effective campaigns borrow trust from the identities, workflows, platforms, and authorization systems employees already use every day.

Abnormal’s 2026 Attack Landscape Report shows how significant this shift has become. Drawing on nearly 800,000 attacks observed across more than 4,600 organizations in the second half of 2025, the report found that threat actors adapt their tactics to the operational context of each target. They change who they impersonate, how they redirect victims, which channels they use, and how they pursue access based on the environment they are trying to enter.

The Common Thread: Attackers Hide in Normal Behavior

This environment-aware approach is the common thread across different emerging attack vectors. Attackers exploit something the organization already trusts: a vendor workflow, a familiar domain, a calendar event, a valid account, or an approved application.

A message, login, application, or authorization event can appear legitimate by conventional indicators while still being anomalous for the person, relationship, time, or workflow involved.

The five shifts below show how attackers are turning routine business activity into cover.

1. BEC and VEC Increasingly Borrow Trust From Real Relationships

Generative AI has lowered the cost of reconnaissance and personalization, making it easier for attackers to produce convincing impersonation emails at scale. Threat actors can mimic an executive’s communication style, reference a real vendor relationship, and tailor requests to an employee’s role and normal business processes.

Vendor email compromise (VEC) is particularly effective because it hides inside trusted external relationships. Abnormal’s analysis found that approximately 61% of business email compromise (BEC) attacks impersonate an external third party. These attacks are difficult for traditional security controls to detect because they often contain no malware, malicious attachments, or suspicious links.

2. Phishing Has Become Multi-Stage and Multichannel

Modern phishing campaigns increasingly unfold across multiple stages rather than relying on a single malicious message. Attackers use redirect chains, QR codes, cloud file-sharing notifications, legitimate platforms, and OAuth flows to move victims across channels and devices before credential theft or unauthorized access occurs.

Abnormal’s analysis of phishing tactics found that 21.6% of phishing attacks used redirect links, while file-sharing phishing represented 12.4% of all phishing attacks. These techniques are effective because they place malicious activity behind familiar workflows, such as opening a shared document, scanning a QR code, or reviewing an e-signature request.

3. Attacks Are Moving Beyond the Inbox

Email increasingly serves as the entry point before attackers pivot into Microsoft Teams, calendars, file-sharing systems, and other collaboration workflows where users routinely receive messages, files, invitations, and automated notifications. Because these interactions are expected, a malicious message can blend into normal work, then direct a user to a credential-harvesting site or malicious authorization request.

Microsoft’s Q2 2026 email threat landscape report found that Teams-based social engineering continued to increase throughout the quarter, while malicious calendar invitations surged 277% from May to June. Microsoft noted that attackers are expanding beyond email into trusted workplace communication platforms, where messages may appear more trustworthy to users.

4. Identity Compromise Turns Trusted Accounts Into Attack Infrastructure

Once compromised, a trusted account becomes attack infrastructure. Attackers can use it to send internal messages, access cloud applications, and reach recipients who would be more skeptical of an unfamiliar sender.

Abnormal’s 2026 Attack Landscape Report found that lateral BEC rises dramatically with organization size, from less than 1% of total BEC attacks at small organizations to 23.2% at large enterprises. The larger the organization, the greater the identity surface and the potential payoff from using one compromised account to reach trusted recipients across the business.

5. AI Creates New Attack Surfaces Through Non-Human Identities

As organizations deploy AI applications, copilots, and agents—and connect them to enterprise systems through service accounts and other non-human identities, along with OAuth grants and API credentials—they are creating a new layer of access relationships that attackers can target.

The risk extends beyond the AI application itself. An attack might begin with a phishing email, progress to a compromised human account, and ultimately result in unauthorized access through an AI-connected application, OAuth grant, or API credential. Because these systems can operate continuously and hold broad permissions across multiple applications and data sources, a single compromised identity or authorization path can create significant downstream risk.

How Abnormal Protects Against These Attacks

These shifts share a common trait: they exploit trusted behavior. The Abnormal Behavioral Security Platform applies behavioral AI across email, collaboration, identity, SaaS, and AI environments, learning what is normal for each user, relationship, application, and workflow so it can identify when legitimate-looking activity deviates from expected behavior.

BEC, VEC, and Phishing

Inbound Email Security analyzes identity, behavioral, and context signals to detect BEC, vendor fraud, AI-generated lures, and multistage phishing before delivery. This includes attacks that use QR codes, redirects, file-sharing lures, and brand impersonation to evade traditional controls.

Collaboration and Calendar Attacks

Messaging Security extends protection into Microsoft Teams, inspecting messages for malicious URLs and high-risk attachments and automatically remediating threats. Calendar Invite Remediation extends that protection to Outlook by removing malicious calendar events associated with phishing and spam messages.

Identity Compromise

Account Takeover Protection analyzes sign-in locations, devices, IP addresses, VPN usage, mailbox activity, and other behavioral signals to detect compromised email accounts. When compromise is confirmed, Abnormal can revoke sessions, block access, and force a credential reset to contain the attacker. Identity Threat Protection extends behavioral detection across email, identity providers, and SaaS applications to identify and contain hijacked sessions, abused OAuth grants, and privilege misuse.

AI and Non-Human Identities

AI Governance provides visibility into AI applications, agents, permissions, and sensitive data exposure, helping organizations identify and govern risky AI activity.

Together, these capabilities help security teams connect activity across the full attack path, from the initial message to collaboration, calendar, identity, authorization, and AI activity.

Schedule a demo to see how Abnormal uses behavioral AI to detect and stop attacks across email, identity, collaboration, and AI environments.

Schedule a Demo

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.