Abnormal Security is a cybersecurity company specializing in AI-powered email security. Founded in 2018, the company provides a cloud-native platform that uses behavioral artificial intelligence and machine learning to detect and remediate advanced email threats, including phishing, business email compromise (BEC), account takeover, and malware. Unlike traditional email security solutions that rely on signature-based detection and reputation scoring, Abnormal Security models the identity and behavioral patterns of each user and organization to identify anomalies indicative of attacks. The company is headquartered in San Francisco, California, and has raised significant venture capital funding, reaching a valuation of over $5 billion as of 2024.
The platform integrates with major email providers such as Microsoft 365 and Google Workspace via APIs, allowing it to analyze email content, sender identity, and communication context without requiring on-premises hardware or mail gateway changes. This approach enables rapid deployment and continuous learning from an organization's unique communication graph.
History and Founding
Abnormal Security was founded in 2018 by Evan Reiser (CEO) and Sanjay Jeyakumar (CTO), both former executives at Amazon and Twitter. The founders aimed to address the limitations of legacy email security tools, which they observed were ineffective against sophisticated social engineering attacks that bypass traditional filters. The company emerged from stealth in 2019 with $28 million in Series A funding led by Greylock Partners and Insight Partners.
In 2020, Abnormal Security launched its core product, the Abnormal Email Security platform, which focused on detecting BEC and phishing using behavioral AI. The company quickly gained traction, reporting a 300% year-over-year growth in customers during 2021. By 2022, it had raised a Series C round of $210 million at a $2.4 billion valuation, followed by a Series D of $250 million in 2023, bringing its valuation to $5.1 billion. As of 2024, the company serves over 2,000 enterprise customers, including major firms in finance, healthcare, and technology.
Technology and Approach
Abnormal Security's core technology is built on Machine learning and Artificial intelligence models that analyze vast amounts of email metadata and content. The system constructs a baseline of normal behavior for each user, including typical senders, communication patterns, and language styles. It then flags deviations that match known attack vectors, such as unusual payment requests, credential phishing links, or impersonation of executives.
The platform employs a combination of Deep learning models, including Transformer (architecture)-based architectures, to process email text and detect subtle linguistic cues. It also uses graph-based analysis to map relationships between users and external domains, identifying suspicious connections. Unlike Large language model-based approaches that generate responses, Abnormal's models are trained for classification and anomaly detection, using supervised and unsupervised learning on labeled attack data and benign email corpora.
A key differentiator is the use of identity modeling. The system creates a digital identity for each employee, vendor, and partner, incorporating attributes such as job role, reporting structure, and typical communication partners. This allows it to detect when an attacker impersonates a trusted contact, even if the email domain is legitimate but compromised.
Products and Services
Abnormal Security offers a suite of products under the umbrella of its email security platform:
- Abnormal Email Security: The flagship product for inbound threat detection, covering phishing, BEC, malware, and spam. It provides real-time blocking and automated remediation via API integration.
- Abnormal Account Takeover Protection: Monitors user accounts for signs of compromise, such as unusual login locations, mailbox access patterns, and forwarding rules, and can automatically disable accounts or require re-authentication.
- Abnormal Abuse Mailbox: Automates the handling of user-reported phishing emails, using AI to triage and respond, reducing security team workload.
- Abnormal API Security: Extends protection to other cloud applications, such as collaboration tools and file-sharing services, by analyzing API activity for anomalies.
- Abnormal Data Loss Prevention: Detects and prevents sensitive data exfiltration via email, using content inspection and policy enforcement.
These products are delivered as a single platform with a unified console, and the company emphasizes a low false-positive rate, claiming that its AI reduces alert noise by over 90% compared to traditional tools.
Market Position and Competition
The email security market is highly competitive, with established players such as Proofpoint, Mimecast, and Barracuda Networks, as well as newer entrants like Darktrace and Tessian. Abnormal Security differentiates itself through its API-based, cloud-native architecture and its focus on behavioral AI rather than signature updates. The company reports that it can detect novel attacks within minutes of the first occurrence, without needing prior threat intelligence.
In 2023, Abnormal Security was named a Leader in the Forrester Wave for Email Security, and it has received numerous industry awards. Its customer base includes Fortune 500 companies across sectors such as banking, insurance, and healthcare, where BEC attacks are particularly costly.
Funding and Growth
Abnormal Security has raised a total of $544 million in venture funding. Key investors include Insight Partners, Greylock Partners, Menlo Ventures, and Scale Venture Partners. The company's rapid growth has been driven by the increasing prevalence of AI-generated phishing attacks, which have made traditional defenses less effective. In response, Abnormal has invested heavily in research and development, expanding its engineering team to over 400 employees as of 2024.
The company has also expanded internationally, with offices in London, Sydney, and Tokyo, to serve its global customer base. It reports annual recurring revenue (ARR) exceeding $200 million in 2024, a milestone that underscores its market traction.
Security and Privacy Considerations
As a security vendor, Abnormal Security handles sensitive email data, which raises privacy concerns. The company states that it processes email metadata and content in accordance with SOC 2 Type II and ISO 27001 standards, and it offers data residency options for customers in the European Union and other regions. It also provides granular controls for data retention and deletion.
In 2023, Abnormal Security published research on the rise of AI-generated phishing, highlighting how attackers use Generative AI tools to craft convincing messages. The company's own detection models are continuously updated to counter these evolving threats, and it collaborates with academic institutions and industry groups to share threat intelligence.
Future Directions
Abnormal Security is expanding beyond email to protect other communication channels, including voice and messaging platforms, as part of a broader 'human-centric security' vision. The company is also integrating Large language model capabilities into its products to improve the accuracy of threat detection and to automate incident response workflows. As of 2024, it is exploring the use of Neural network architectures that can process multimodal data, such as images and attachments, to catch malicious content that text analysis might miss.
The company faces challenges, including the need to maintain low false positives as it scales, and competition from tech giants that offer bundled security suites. However, its strong growth and investor confidence suggest a promising trajectory in the cybersecurity landscape.