This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Stopping Advanced Email Threats in the Age of AI

Download resources

About this session

Ryan Sinclair, a sales engineer at Abnormal Security, argues that email remains attackers' easiest way to reach end users, and that generative AI is removing the grammar and spelling mistakes security-awareness training teaches people to spot. He walks the room through a live example of ChatGPT drafting a convincing direct-deposit-change email from a hijacked thread, then shows real AI-generated attacks Abnormal has blocked: a Meta-for-Business impersonation, a direct-deposit text-only email, and partially AI-written invoice fraud, explaining the signals used to catch each one, such as sender-domain mismatch and unusual topics for a given user. He argues signature and link-based email gateways fail open against text-only and multi-redirect attacks, and describes Abnormal's approach: plugging into Microsoft 365 or Google Workspace via API to baseline normal communication per user, then flagging deviations, including DocuSign lookalikes, VIP display-name spoofing, vendor email compromise, account takeover signals such as impossible travel, and QR-code phishing that evades link scanners. A short Q&A confirms detection models are built per user rather than organization-wide.

The widespread adoption of generative AI meant increased productivity for employees, but also for bad actors. They can now create sophisticated email attacks at scale—void of typos and grammatical errors that have become a key indicator of attack. That means credential phishing and BEC attacks are only going to increase in volume and severity. So how do you defend against this threat? Join this session to hear how generative AI is changing the threat landscape, what AI-generated attacks look like, and how you can use “good AI“ to prevent “bad AI“ from harming your organization.

Key takeaways

  • Stop training users to rely on spelling and grammar mistakes as red flags; generative AI removes those tells from phishing and BEC emails.
  • Treat text-only emails with no link or attachment as a real detection gap, since threat-intel and signature-based gateways have nothing to check against them.
  • Watch for display-name spoofing that swaps the sender name and subject line to slip past VIP-impersonation rules built on known executive names.
  • Build per-user behavioral baselines (who someone emails, what topics they discuss, typical sending geography for vendors) rather than one organization-wide policy, since finance and IT staff receive very different normal traffic.
  • Treat QR-code emails and multi-redirect credential-phishing pages (CAPTCHA gates, hosted forms) as evasion techniques designed to keep gateways from following the link to its final destination.

Speakers

Ryan Sinclair
Ryan Sinclair
Sales Engineer · Abnormal Security
Ryan Sinclair is a seasoned cybersecurity expert with 12+ years of experience, who transitioned from a law firm analyst to a leading professional in the field. With expertise from Symantec, Palo Alto Networks, CrowdStrike, and currently, Abnormal… Read moreRead less

Ryan Sinclair is a seasoned cybersecurity expert with 12+ years of experience, who transitioned from a law firm analyst to a leading professional in the field. With expertise from Symantec, Palo Alto Networks, CrowdStrike, and currently, Abnormal Security, Ryan specializes in strategic guidance and technical expertise, empowering audiences to enhance their security strategies.

Resources

Tags

More from GoSec 2024

Also from Ryan Sinclair

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.