AI Email Threats:
When Attackers and Defenders Access the Same Models
A practitioner panel recorded live during InfoSecurity Europe 2026.
Watch the Session
A panel conversation on AI email threats, Claude Mythos, baseline controls, and what defenders should prioritize now.
“People are getting confused and just not focusing on the basics.”
– Sean Remnant, Co-Founder, Ignition Technology
Share:






Key Takeaways
Attacks haven’t changed, but the obvious tells are gone. The main threat is still BEC. Read more
Google and Microsoft enforcing DMARC for bulk senders proved the baseline still matters. When platforms started blocking unauthenticated emails, criminals moved to AI to get around it. Read more
Criminals are now configuring p=reject on their own sending infrastructure, while many large organizations still aren’t using DMARC properly. Read more
Companies still lack a clear picture of what they are exposing. In an era of rapid exploitation, your budget is best spent mastering the basics. Read more
AI agents aren’t supposed to modify evidentiary packs. Unfortunately, that’s exactly what’s happening. Read more
The shape of AI email threats hasn’t changed, but the preparation behind them has. What used to take hours of manual reconnaissance is now automated, turning simple phishing into highly tailored deception. Read more
Meet the Panel
A cross-partner panel of practitioners and specialists. No vendor pitches, no fluff.
Check Your Domain’s DMARC Status
Criminals are configuring DMARC. Most enterprises aren’t. Run your domain through the checker to see where you stand and what needs to change.
If you’re at risk of impersonation, one of our experts will be in touch to assist.
What the Panel Discussed

Recorded live during InfoSecurity Europe 2026, this session brought together six practitioners – a COO, a CIO, a CEO, a CISO, and two co-founders, to work through an important question: what does defense look like when attackers and defenders have access to the same models?
Kieran Frost, COO of Sendmarc, opened by framing the stakes. On April 7, Anthropic announced Claude Mythos preview, a model the UK AI Security Institute put through a 32-step corporate cyberattack simulation. Claude Mythos passed that test three times out of ten, a benchmark no previous model had cleared. One month later, OpenAI released ChatGPT-5.5-Cyber, passing the same test twice.
With Claude Mythos’ capabilities set to become commercially available, the question of how teams should respond to AI email threats has stopped being theoretical.
The Threat Landscape
Mark Overton, CISO at Softcat, opened with a grounding observation: what’s landing in security teams’ inboxes doesn’t look vastly different. The normal tells (spelling errors, for example) aren’t reliably there anymore, but the attack types themselves haven’t been reinvented. What is mainly being seen is BEC.
What has changed is the preparation phase. Kieran described how trivial it now is to scrape a LinkedIn profile, learn how a manager communicates, and send a convincing impersonation. Mark confirmed AI is being used in this reconnaissance phase, not necessarily in the email itself.
Mike Britton, CIO at Abnormal AI, added the scale dimension. Nation-states still operate at the nation-state level, but financially motivated criminals are now operating there too. Those who previously lacked the capability to run sophisticated AI email threats now do.
Phishing-as-a-service kits cost as little as $250. An attacker can now send 10,000 unique spear phishing emails to every employee in an organization – something that once demanded significant time and manual effort.
As Kieran summarized, AI hasn’t necessarily changed the attacks. It has just changed who can do them. That shift is what makes AI email threats a different problem to manage than the one companies planned for.
The Baseline Under Pressure
Andy Bates, Co-Founder of StonesThro, made the case that the baseline still matters, and that Google and Microsoft enforcing DMARC requirements for bulk senders proved it. When platforms started blocking unauthenticated email, criminals moved to AI to get around it.
Mike flagged something the room found striking: criminals are now configuring p=reject on their own sending infrastructure. Businesses sitting at p=none aren’t just unprotected. They are behind attackers who have already adopted the standard. Mike noted it still shocks him how many large organizations aren’t truly using DMARC, while criminals are.
On filtering: Mike described how phishing kits now generate unique URLs, links, and attachments per message. When every element of an attack changes with every send, there’s nothing to block.
Sean Remnant, Co-Founder of Ignition Technology, was asked where a CISO with one budget priority should put their money. His answer: Understand your attack surface and assets first. Reduce it. Do the basics.
Companies still don’t have a clear picture of what they’re exposing, and the speed at which vulnerabilities are now discovered and exploited makes that gap more dangerous than ever.
Behavioral Detection in Practice
Mike walked the panel through how behavioral detection works against AI email threats. It starts with establishing what normal looks like: normal communications, normal topics, normal login geography, normal payment patterns. When something deviates, it gets flagged.
He described a supply chain compromise he experienced firsthand: attackers sat in a supplier’s inbox, watched for an invoice, then sent a follow-up redirecting payment to a different account. The email was real. The only signal was behavioral.
He also made the operational case. Over 90% of emails reported to security teams by employees are legitimate. The result is an AP team that stops processing invoices and a security team that stops prioritizing real AI email threats, both paralyzed by noise. Behavioral detection reduces that noise, letting each team focus on what it’s actually there to do.
Doug Pecarski, CEO of Simply Discover, raised the evidentiary dimension. His team works with evidentiary packs. As long as agents aren’t providing or modifying the evidence, Doug noted, they’re in a comfortable place. That isn’t what they’re finding. By the time the event occurs, the build-up is fragmented across email, Slack, Teams, and document systems. Archive retrieval and immutability are going to become critical.
The Road Ahead
The panel’s honest answer on the 12-24 month outlook for AI email threats: forecasting is unreliable when model capability is moving this fast. Mike’s point was direct: Opus came out six months ago and already feels like a watershed moment. Annual planning feels too slow. Quarterly planning is the new minimum.
Sean noted that incumbents are moving fast and have the resources to invest. But he flagged the reverse risk: AI has lowered the barrier to entry for new vendors, too, and buyers need to be more diligent about what they’re actually purchasing. Mike pushed further: using AI is not a moat. If a vendor’s only differentiator is AI, that position is fragile.
The audience Q&A brought the session back to fundamentals. An audience member asked why so many government bodies and large businesses still haven’t started DMARC. The panel’s answers: lack of education, a prioritization problem, and the perception that DMARC is complex to enable.
A lawyer in the audience, Dr. Roshni, pushed further: given the legal drivers now emerging, why aren’t more organizations acting? Andy cited five cases where companies were sued after being impersonated. Mike returned to the compliance-versus-risk-management problem: businesses optimize to pass certifications, not to actually reduce risk.
Good risk management is hard work, and most organizations struggle to get it right.
Kieran wrapped the session with a single theme: the shape of the attacks hasn’t necessarily changed. Defending against AI email threats requires the same fundamentals, executed faster.
“I certainly found five legal cases where five companies have been sued successfully due to them being impersonated.”
– Andy Bates, Co-Founder, StonesThro
Share this Session
“AI hasn’t necessarily changed the attacks. It’s just changed who can do them.”
– Kieran Frost, COO, Sendmarc
Share:
Talk to a DMARC Specialist
Your domain checker result is a starting point. A Sendmarc specialist can walk you through what full enforcement looks like for your environment.
Keep Reading
More from Sendmarc on the topics raised at the panel on AI email threats and Claude Mythos.
AI Email Threats FAQs
The four questions the panel was convened to answer were addressed directly.
What happens when attackers and defenders have access to the same model?
The panel was clear on what happens when attackers and defenders have access to the same model. If defenders can use AI to stop the easy attacks, they take the high ground. What is non-negotiable is doing the things organizations already know they need to do, just faster and at scale.
What has actually changed, if anything at all?
What has actually changed isn’t the shape of AI email threats but the preparation behind them. AI email threats look the same in the inbox. BEC and phishing still follow familiar patterns.
Reconnaissance that once took hours is now automated. AI is being used to scrape LinkedIn profiles and mimic communication styles.
How are our traditional defenses performing in this new era?
Traditional defenses are under pressure in this new era. The authentication baseline – DMARC, SPF, and DKIM – remains necessary. Criminals are now configuring p=reject on their own sending infrastructure. A company sitting at p=none isn’t just unprotected – it’s behind attackers who have already adopted the standard.
Behavioral detection (modeling what normal communication looks like and flagging deviations) is built for this class of AI email threats.
How can defenders better leverage AI to hedge against these attacks?
Defenders can better leverage AI to hedge against AI email threats by using it to understand what normal looks like. Behavioral AI works by establishing a baseline of normal communication patterns – who talks to whom, what topics they discuss, where they log in from, and which bank accounts a supplier has always used. When something deviates from that baseline, it gets flagged.





