Behavioral AI that stops business email compromise, phishing, and account takeover — the threats your email gateway was never designed to catch.
Traditional email security works by matching incoming messages against known threat signatures — lists of malicious links, known bad domains, and detected malware patterns. Sophisticated attackers know this, and they build attacks specifically designed to pass signature checks. A business email compromise attack from a compromised legitimate vendor account contains no malicious links, no known bad domains, and no malware — it is a legitimate email from a real person asking for a wire transfer to a different bank account. Abnormal Security’s behavioral AI detects this attack not by matching a signature but by recognising that this email — from this sender, to this recipient, with this request, at this time — is anomalous. The AI has built behavioural baselines for every identity in the organisation and knows what normal looks like.
Abnormal Security is an AI-native email security platform — trusted by over 25% of the Fortune 500 — that uses behavioral AI and its Attune 1.0 foundation model to detect business email compromise, vendor email compromise, phishing, account takeover, and AI-generated threats through API integration with Microsoft 365 and Google Workspace, with no MX change required and 4-click deployment, 14-day calibration, and enterprise custom pricing from approximately $36 to $80 per user per year.
Is it worth using? Yes for mid-market and enterprise organisations on Microsoft 365 or Google Workspace that face sophisticated social engineering attacks, BEC, and vendor fraud that traditional email gateways and Microsoft Defender miss — Abnormal’s behavioral detection is specifically designed for the attack types that signature-based tools cannot catch.
Who should use it? CISOs, security operations teams, and IT security leaders at mid-market and enterprise organisations facing high volumes of BEC, impersonation, credential phishing, and account takeover that bypass existing email security controls.
Who should avoid it? Organisations on on-premises Exchange who cannot move to cloud email — Abnormal requires Microsoft 365 or Google Workspace and does not support on-premises Exchange environments.
Best for
Not for
Rating
⭐⭐⭐⭐ 4.4 / 5
Abnormal Security was founded in 2018 by Evan Reiser and Sanjay Jeyakumar — building the platform on a hypothesis that email security had to move from signatures to behavior if it was going to catch the most sophisticated attacks. The company has raised substantial venture capital and grown to be trusted by over 25% of the Fortune 500 — a remarkable adoption rate that reflects the genuine detection gap its behavioral AI fills for organisations that have invested in traditional email security and still experience BEC and account takeover incidents.
In March 2026, Abnormal launched Attune 1.0 — its behavioral AI foundation model that simultaneously analyses identity, behaviour, and content to detect novel AI-generated threats and sophisticated social engineering. 85% of Abnormal’s detections are powered by Attune, which continuously learns from the communication patterns of every identity in the customer’s organisation.
| Pros | Cons |
|---|---|
| Detects BEC and social engineering attacks that contain no malicious payload — the exact attacks that signature-based gateways and Defender miss | Does not include URL rewriting, attachment sandboxing, or DLP — organisations need complementary tools for these capabilities |
| API deployment with no MX change — zero disruption to email flow and no DNS modification required | Enterprise-only custom pricing with no transparent published tiers — all quotes require a sales engagement |
| Attune 1.0 specifically designed to detect AI-generated phishing — relevant as sophisticated attackers use AI to craft more convincing attacks | Per-user pricing of $36 to $80/year means significant annual commitment for large organisations |
| 25% plus of the Fortune 500 trust the platform — the most validated enterprise email security tool by adoption scale | No on-premises Exchange support — organisations that cannot move to cloud email cannot use Abnormal |
| AI Security Mailbox automates phishing report triage — directly reduces SOC analyst workload on the most repetitive security task | Post-delivery processing model means there is a latency window between message arrival and Abnormal’s detection and remediation |
Abnormal Security does not publish pricing. All plans are custom-quoted based on mailbox count, modules selected, and contract length. Based on third-party buyer data:
Contact abnormalsecurity.com for a custom quote. Negotiate at quarter-end for best pricing.
Abnormal Security is an AI-native email security platform trusted by 25% plus of the Fortune 500 — using behavioral AI and the Attune 1.0 foundation model to detect BEC, phishing, account takeover, and vendor fraud through API integration with Microsoft 365 and Google Workspace.
Abnormal integrates with Microsoft 365 or Google Workspace via API in 4 clicks — no MX record change, no DNS modification, and no disruption to the existing email flow. A 14-day calibration period builds behavioral baselines before full protection is active.
Attune 1.0 is Abnormal’s behavioral AI foundation model launched in March 2026 — simultaneously analysing identity, behaviour, and content to detect novel AI-generated threats and sophisticated social engineering. 85% of Abnormal’s detections are powered by Attune.
Abnormal pricing is custom-quoted. Per-user pricing typically falls between $36 and $80 per user per year. Entry-level enterprise deployments typically start at $50,000 to $100,000 per year for 500 to 1,000 mailboxes.
No — Abnormal Security requires Microsoft 365 or Google Workspace and does not support on-premises Exchange environments. Organisations that cannot move to cloud email need to evaluate alternative email security platforms.
Microsoft Defender is included in M365 E5 and provides strong signature-based email security and some behavioral detection. Abnormal is specifically designed for the social engineering attacks that pass through Defender — BEC, vendor fraud, and account takeover with no malicious payload. 65% of Abnormal customers run Defender plus Abnormal as a layered defence rather than replacing Defender.
Abnormal Security is the most effective AI email security platform for the specific and high-stakes threat category that signature-based tools consistently miss — business email compromise, vendor fraud, and account takeover attacks with no malicious payload. The Attune 1.0 behavioral AI, API deployment with no MX change, and Fortune 500 adoption scale create a compelling security layer for any mid-market or enterprise organisation that has experienced BEC incidents despite existing email security investment. For any CISO whose organisation has lost money to a wire transfer fraud or compromised vendor account that passed through the existing email gateway, Abnormal Security addresses the detection gap directly.
Next steps