From inbox to identity: How AI is reshaping the enterprise attack chain
For years, email has been one of the most dependable entry points for cybercriminals. It is where employees receive invoices, access documents, approve payments and communicate with colleagues and partners. That combination of trust, scale and daily routine makes email an enduring target. Securing this threat vector is not a new challenge. Phishing, business email compromise and malicious attachments have threatened enterprises for decades. What has changed is the speed and sophistication of these attacks. Artificial intelligence is enabling cybercriminals to turn what was once an isolated phishing message into a rapid attack chain that moves from an inbox to breach enterprise identity, cloud applications and critical systems. The inbox remains the front door, but identity has become the real destination. The inbox as the entry point Email remains central to business operations, connecting teams and partners across hybrid environments. It also allows attackers to reach targets at scale while blending into normal workflows. AI has made these messages far more convincing. Attackers can generate polished, context-aware lures in seconds, eliminating traditional warning signs like poor grammar and spelling errors. They can mimic the tone of a supplier, reference real business context, or impersonate leadership. Barracuda’s 2026 Email Threats Report revealed that 1 in 3 email messages are malicious or unwanted spam, with phishing accounting for 48% of malicious email activity . Furthermore, 90% of high-volume phishing campaigns used phishing-as-a-service kits, demonstrating how accessible industrialised attack tools have become. A fraudulent email is no longer just spam; it is the first step in compromising the broader enterprise. How an email turns into an identity breach The attack lifecycle progression is well defined: an employee receives a credible AI-crafted email directing them to review an invoice, reset credentials, or open a shared file. The link takes the victim to a fake login page designed to harvest credentials or capture session tokens, often bypassing multi-factor authentication. Once an attacker compromises that identity, the security perimeter dissolves. Armed with legitimate credentials, the attacker moves laterally across SaaS applications, Microsoft 365 environments and cloud workloads. They correspondence for sensitive financial data, establish persistence, create hidden forwarding rules, and launch lateral phishing attacks from a trusted internal account. Research found that 34% of organisations experience at least one account takeover (ATO) incident every month. Compromising an identity gives attackers legitimate access, making subsequent actions - whether data exfiltration, invoice fraud or ransomware deployment - far harder to detect. AI accelerates every stage AI is not just refining email copy; it is accelerating every stage of the cyber kill chain. Attackers leverage publicly available data, social media and corporate websites to automate reconnaissance, identifying high-value targets across finance, IT and leadership. AI enables attackers to launch automated campaigns, dynamically alter lures based on recipient replies, and deploy evasive techniques. Nearly 70% of malicious PDFs now contain QR codes (quishing) designed to move victims away from corporate email defences onto unmonitored mobile devices. As deepfake-enabled executive impersonation and automated credential attacks mature, attacks will execute faster, compounding pressure on security teams. Securing the full attack chain Traditional secure email gateways and signature-based defences are no longer sufficient on their own. They are blind to post-delivery weaponisation, lateral phishing between internal accounts, and attacks launched from compromised legitimate accounts. Managing email, identity, endpoint and cloud security in silos creates critical blind spots. To defend against AI-era threats, organisations must secure the entire attack lifecycle starting with the following:
AI-driven email protection: Deploy behavioural AI to analyse communication patterns and detect anomalous message characteristics.
Identity defence & ATO detection: Continuously monitor user sign-ins, anomalous access locations, and unauthorised mailbox rule changes.
Cross-domain correlation: Connect telemetry across email, identity, endpoints and cloud applications to detect lateral movement early.
Automated incident response: Implement automated remediation to find and purge malicious messages across inboxes in minutes.
Modern security awareness: Train employees to spot AI-driven tactics, while recognising that human vigilance cannot be the sole defence.
Published On Sep 30, 2026 at 08:00 AM IST
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
