Abnormal AI is an American cybersecurity company specializing in protecting business communications. Its approach rests on one idea: identifying a fraudulent message sometimes requires more than examining its content; it also means understanding who communicates with whom, in what context, and according to which habits. Based in San Francisco, the software company develops a platform for organizations using cloud email services, including Microsoft 365 and Google Workspace. Its official website is abnormal.ai.
Roots in machine learning
Founded in 2018 by Evan Reiser and Sanjay Jeyakumar, the company first became known as Abnormal Security. Its founders come from the software and machine learning fields, with experience at Twitter among other companies. They apply these skills to a concrete problem: email attacks are becoming difficult to distinguish from ordinary business correspondence.
A fake wire transfer request signed by an executive or a fraudulent change to bank details may contain neither a dangerous attachment nor a suspicious link. Abnormal therefore builds its positioning around detecting behavioral anomalies. The change of name to Abnormal AI highlights the role of artificial intelligence in this strategy, while supporting a broader ambition to protect digital work environments.
Detecting fraud behind a seemingly ordinary message
The platform connects to cloud environments through their application programming interfaces, or APIs. It analyzes communications, identities, and various contextual signals to build a picture of typical behavior. An unusual sender, a new relationship, or a request inconsistent with observed practices can thus contribute to the risk assessment.
Abnormal AI tackles threats including phishing, impersonation, CEO fraud, and compromised business email accounts, often grouped under the term “business email compromise.” Its protection also covers attacks involving suppliers or hijacked legitimate accounts. The aim is to detect manipulation that evades analysis based solely on technical signatures or a domain’s reputation.
The software company also offers investigation and remediation features, including the removal of messages identified as malicious. For security teams, the intended benefit is twofold: reducing employees’ exposure to fraudulent requests and limiting the manual work involved in triaging alerts. This automation does, however, require control over false positives and the access permissions granted to the platform.
What comes next?
The spread of generative AI makes it easier to write credible, personalized fraudulent messages. It strengthens the case for detection that considers context rather than relying solely on awkward wording. For Abnormal AI, the challenge will be to keep its models relevant as these developments unfold, while extending its protection beyond email. Its ability to explain its decisions, preserve data privacy, and integrate with existing tools will influence companies’ choices.