Group Purchasing
Group Purchasing

When Trusted Senders Become Threats: Stopping BEC and Supply Chain Attacks with Self-Learning AI

When Trusted Senders Become Threats: Stopping BEC and Supply Chain Attacks with Self-Learning AI (PDF, 2.11MB)Published: 24 Apr, 2026
Created by:

Thank You To Our Sponsor

When Trusted Senders Become Threats: Stopping BEC and Supply Chain Attacks with Self-Learning AI, published by SANS Institute in April 2026, is a product review of Darktrace / EMAIL, an integrated cloud email security (ICES) solution that deploys in parallel to Microsoft 365 or Google Workspace. The review takes the perspective of an operational analyst, examining how the platform's self-learning AI detects business email compromise (BEC), supply chain attacks, and trusted sender compromise that signature-based tools typically miss.

Key findings:

  • During the review period, Darktrace / EMAIL analyzed 253,882 inbound emails in one month and identified 5,523 threats, affecting 13% of the monitored userbase
  • Phishing links accounted for the largest share of detections (2,705), followed by credential harvesting (1,638) and forged address attempts (849)
  • Document anomaly detections increased 80% and phishing attachment detections rose 46% over the reporting period, while extortion attempts decreased 51%
  • Of 1,308 outbound emails analyzed, 14 were flagged, with "Response to Solicitation" detections increasing 500% over 28 days — a signal that can indicate a compromised account or policy violation
  • The platform builds separate behavioral baselines for every internal user and external correspondent, rather than matching messages against known attack signatures
  • Traditional detection methods (signatures, reputation feeds, known-bad indicators) catch commodity threats but tend to miss trusted sender compromise, where phishing originates from a legitimate, previously trusted account
  • The core email license covers inbound, outbound, and lateral (internal-to-internal) email analysis — lateral coverage in particular addresses account takeover scenarios that bypass many email controls
  • Microsoft Teams messaging is analyzed with the same behavioral depth as email, extending self-learning detection into a second communication channel
  • Detection logic is fully visible to analysts through a two-tier Models and Recipes architecture, showing exactly which conditions triggered a detection and what response actions followed
  • The platform's tuning system uses AI-proposed exceptions that expire automatically as its baseline continues to learn, rather than requiring a permanently maintained rule library
  • Response actions follow a graduated escalation model — from locking a suspicious link or replacing a risky attachment with a notice, up to holding or quarantining a message — calibrated to the severity of the anomaly

The review finds that the core gap in most organizations' email security isn't a lack of tools, but a shared detection philosophy across native controls and secure email gateways, both of which rely on historical attack patterns. Darktrace / EMAIL's behavioral, self-learning approach is best suited to catching what those tools structurally can't: novel phishing with no prior signature, and attacks that originate from accounts with real, established communication history. The review notes that this positions the platform as a complement to existing native and gateway controls rather than a replacement. This review is based on a SANS-guided operational walkthrough of Darktrace / EMAIL rather than a practitioner survey, evaluating the platform's dashboard, detection architecture, and investigation workflow from the perspective of a working security analyst.

When Trusted Senders Become Threats: Stopping BEC and Supply Chain Attacks with Self‑Learning AI

Related Webcast

Your biggest email threats aren’t strangers, they’re trusted partners whose accounts have been compromised. Discover how self‑learning AI uncovers subtle behavioral shifts that signal BEC and supply chain attacks before damage is done.

Man presenting webcast to screen

FAQ

Traditional tools match incoming messages against signatures and known-bad indicators from historical attacks. Darktrace / EMAIL instead builds behavioral baselines for every internal user and external correspondent, flagging deviations from established "patterns of life" — which allows it to catch novel phishing and compromised trusted accounts with no prior signature.

Trusted sender compromise occurs when a vendor, partner, or other established contact's account is taken over, so the resulting phishing emails come from a legitimate sender with real communication history. Signature-based tools struggle here because the sender metadata, headers, and content all check out; Darktrace / EMAIL instead flags "out of character" deviations from that sender's known behavioral baseline. 

No. Its core license covers inbound, outbound, and lateral (internal-to-internal) email analysis, and it also extends behavioral monitoring to Microsoft Teams messages — during the review, outbound "Response to Solicitation" detections increased 500% over 28 days, illustrating the value of outbound coverage. 

Analysts can request an AI-proposed exception, which is tailored to the specific sender and detection type. Unlike a static rule library, these exceptions expire automatically as the platform's baseline learns the legitimate pattern, so the tuning is self-correcting rather than requiring ongoing manual maintenance. 

Over one month, the platform analyzed 253,882 inbound emails and flagged 5,523 threats affecting 13% of the userbase, with phishing links (2,705), credential harvesting (1,638), and forged addresses (849) as the top categories. 

Meet Your Author

Matt Bromiley
Matt Bromiley

Matt Bromiley

Certified Instructor

Matt Bromiley is a Lead Solutions Engineer at LimaCharlie and SANS Certified Instructor. He serves as a GIAC Advisory Board member, a SME for the SANS Security Awareness, and a technical writer for the SANS Analyst Program.

Read more about Matt Bromiley