Death of the ‘obvious scam’: How AI is making cyberattacks look like normal emails

AI is making cyberattacks harder to detect as attackers use legitimate accounts, real conversations and familiar business workflows to evade traditional warning signs. At Proofpoint Protect 2026, executives discussed how agentic AI could automate ...

ET Online

AI-powered attacks are now blurring the line between legitimate business activity and cybercrime, challenging organisations to rethink how they detect and prevent threats.

SAN DIEGO: Imagine opening an email from someone you know at work. It looks completely normal.

The sender is trusted. The conversation is familiar. The details are real. Nothing immediately raises red flags. Except that the sender’s account has been compromised.

The email is designed to blend into an existing conversation without raising any suspicion.


And this is becoming a bigger problem for cybersecurity: attacks can now look like ordinary business activity.

Artificial intelligence (AI) is making these attacks harder to detect. AI is no longer just a tool that answers questions or generates text and images. It can now make decisions, pull information from different sources and carry out a series of tasks with limited human intervention.

That is where agentic AI comes in. Think of it as AI that not only answers but also acts.
ADVERTISEMENT

A conventional AI tool might write an email when you ask it to. An AI agent can be given a goal and figure out the steps needed to get there: finding information, using different tools, retrieving data and deciding what to do next.

These capabilities are already becoming part of everyday AI tools. Coding agents, for example, can look through code, write new code, run tests, spot errors and fix them without someone having to guide them through every step.

Now, think about what happens when an attacker has access to that kind of capability. AI could potentially help identify a target, understand their relationships, decide how to approach them and adapt its next move based on what happens. It is no longer just helping write the attack. It could help carry it out.

For security teams, that changes the problem. Cybersecurity has long relied on warning signs — a suspicious sender, an unusual login, a strange attachment or a message that simply does not look right.
ADVERTISEMENT

Identifying a cyberattack becomes more difficult when the sender is genuine, the conversation is real and the request fits an existing business relationship.

When the attack looks like business as usual
That was one of the themes at Proofpoint Protect 2026, a three-day flagship cybersecurity conference hosted by Proofpoint in San Diego, California.
ADVERTISEMENT

At the event, the company argued that some of the hardest attacks to detect are no longer the ones that look obviously malicious. They can begin inside an existing business relationship — using a genuine account, an ongoing email thread or information that both sides already know.

“Attackers increasingly operate inside the relationships and workflows organisations already trust,” Tom Corn, executive vice president and general manager, Threat Protection Group at Proofpoint, said at the conference.

That is what makes the problem harder: the attack may look like ordinary business activity until it is too late.

Proofpoint’s threat research offers a real-world example.

In a campaign tracked as UNK_CondorFiltration, attackers targeted more than 5,700 Microsoft 365 accounts across 28 tenants in Latin America. The targets were largely service and functional accounts — accounts set up for specific business functions rather than individual employees.

Proofpoint identified seven accounts that were compromised. Six were taken over within minutes.

Once inside the organisation’s systems, the attackers didn’t have to create any new accounts or pretend to be someone else. They could simply use an account that already belonged to the organisation.

In one case, within 90 seconds of gaining access, the attacker switched to a German VPN, probed the company’s corporate VPN, accessed Azure Portal and SharePoint, and requested a Microsoft Graph API token.

The cybersecurity company said the activity was consistent with attempts to access or exfiltrate corporate data, although its investigation could not establish whether any data had actually been taken.

And this is where Proofpoint has a point: the account was legitimate. The activity was not.

It is also the problem the company is trying to tackle as AI changes the way attacks are carried out.

At Protect 2026, Proofpoint introduced two new agentic security systems: Agentic Collaboration Security, which focuses on detecting attacks hidden in trusted communications and business relationships and Agentic Data and AI Security, which aims to help organisations monitor how AI agents access and use sensitive data.

The broader idea is that companies cannot prevent every breach. They need another layer of defence that can look at what a person or an AI agent is trying to do and flag actions that do not fit the context.

Proofpoint CEO Sumit Dhawan said this is where AI can help — by analysing multiple signals to understand intent rather than relying on a single suspicious event.

When legitimate access is no longer enough
Companies are increasingly giving AI systems access to internal information and software so they can carry out tasks on behalf of employees.

But as those systems begin to make decisions and take actions, simply knowing what they are allowed to access may not be enough.

Dhawan has framed the problem around intent. “The question is no longer simply: Can this agent access this resource?” he wrote in a September post. “It is: Why is it accessing it, what is it trying to accomplish, and should that action be happening in this context?”

The distinction is important. An AI agent may have legitimate permission to access a company's customer database, financial system or internal documents. But that does not mean every action it takes is authorised.

An employee may have the same access. The security question is therefore shifting from who can access something to what they — or the AI acting on their behalf — are actually trying to do.

“You cannot secure AI without securing the data it acts on, and you cannot secure data without understanding how AI is using it,” Mayank Choudhary, executive vice president and general manager, Data Security and Governance Group at Proofpoint, said.

That is the idea behind Proofpoint’s second major announcement at the conference, Agentic Data and AI Security, which brings AI security and data security together. The system is designed to give organisations visibility into how AI agents access, use and act on sensitive data, helping security teams identify actions that may pose a risk. The shift is already underway.

Proofpoint’s 2026 AI and Human Risk Landscape report found that 87% of organisations surveyed had moved AI assistants beyond the pilot stage, while 76% were testing or deploying autonomous agents. At the same time, 52% said they were not fully confident that their existing controls could detect a compromised AI system.

AI adoption question
Dhawan's view is that the debate about slowing AI development and the question of whether businesses will continue adopting AI are two different things.

In a discussion at Protect 2026, he said he did not see a slowdown in enterprise AI adoption. Instead, he argued that companies need security and governance to keep pace with that adoption.

That distinction matters because companies are moving AI from experimentation into actual business processes.

The more responsibility an AI system takes on, the more consequential its actions become. An agent that simply summarises documents creates one kind of risk. An agent that can access customer records, interact with enterprise software or initiate a business process creates another.

For cybersecurity teams, that means the old question — does this look suspicious? — is becoming less useful on its own.

The harder question is whether an action makes sense in that particular context.

Why India is becoming part of the conversation
Dhawan also pointed to India as a market where the security challenge is becoming more significant as digital adoption matures.

He told The Economic Times that Proofpoint had been “a bit too late” to India and some other markets because their digital transformation was taking place later than in more mature economies. His explanation for the change was not simply the rise of AI.

Before the pandemic, Dhawan said, India was still in the middle-to-late stages of digital transformation, and AI models were not as prevalent. As digital transformation accelerated and remote working became widespread after Covid, AI also lowered language barriers for attackers. Proofpoint saw an increase in threat activity and the volume of threats.

At the same time, he highlighted growing privacy, compliance and citizen-data protection requirements as key factors driving the market’s importance.

“We are seeing tremendous momentum in India,” Dhawan said.

He added that the company has invested in a sovereign security solution, a local team, co-located R&D and new model development in India, where it is seeing strong adoption among large banks, government agencies and other industries and plans to continue investing through 2027 and 2028.

(The writer was in San Diego, California, at the invitation of Proofpoint)
Download
The Economic Times Business News App
for the Latest News in Business, Sensex, Stock Market Updates & More.
READ MORE
ADVERTISEMENT

READ MORE:

LOGIN & CLAIM

50 TIMESPOINTS

More from our Partners

Loading next story
Business News › AI › AI Insights › Death of the ‘obvious scam’: How AI is making cyberattacks look like normal emails
Text Size:AAA
Success
This article has been saved

*

+