-

Abnormal AI Reveals the Growing Risk of Human Error in Enterprise Email

98% of security leaders consider misdirected email a significant risk—surpassing even malware and credential theft

LAS VEGAS--(BUSINESS WIRE)--Abnormal AI, the leader in AI-native human behavior security, today released a new research report, 2025 State of Misdirected Email Prevention: Keeping Sensitive Data Out of the Wrong Inboxes, revealing that one of the most damaging and overlooked risks in enterprise cybersecurity comes not from malicious attackers, but from human mistakes.

Based on a survey of more than 300 security and IT professionals, the report highlights the growing prevalence and business impact of legitimate messages sent to the wrong recipient—also known as misdirected emails—which can result in data breaches, regulatory violations, remediation costs, and reputational damage.

The research makes clear that this concern is more than theoretical. Ninety-eight percent of security leaders consider misdirected email as a significant risk when compared to other risks like malware and insider threats. And those fears are being realized with 96% of organizations surveyed experiencing data loss or exposure from misdirected email in the past year, with 95% reporting measurable business impact such as remediation costs, compliance violations, or damage to customer trust.

“This report offers a sobering realization,” said Mike Britton, CIO at Abnormal AI. “The same inboxes attackers target are also the source of accidental data loss within organizations. Enterprises have invested heavily in stopping inbound threats like phishing, but outbound email remains a major vector for human error—one that has historically been overlooked.”

Additional findings include:

  • 47% of security and IT professionals learn of misdirected emails from recipients rather than from security tools.
  • 97% believe behavioral AI can help prevent accidental data loss before it occurs.
  • The average enterprise spends over 400 hours per year managing false positive alerts from data loss prevention (DLP) or email security tools.
  • Misdirected emails account for 27% of all data protection incidents under the GDPR last year, contributing to over $1.2 billion in fines worldwide.

The research underscores the pitfalls of traditional email security and DLP tools, built to detect external attacks—not the unintentional data loss caused by internal human error. Behavioral AI, by contrast, models typical communication patterns and can identify deviations that indicate misdirected emails, stopping dangerous activity in its tracks by intervening before sensitive data leaves the organization.

“This is a visibility problem as much as it is a technology one,” Britton added. “Traditional tools can’t differentiate a legitimate customer email from a sensitive message going to the wrong recipient. Protecting data today requires more than defending against external threats—it means understanding and supporting human behavior. Organizations that integrate AI-driven insights with user-centric safeguards are better positioned to prevent mistakes from turning into breaches.”

Additional Resources:

About Abnormal AI:

Abnormal AI is the leading AI-native human behavior security platform, leveraging machine learning to stop sophisticated inbound attacks and detect compromised accounts across email and connected applications. The anomaly detection engine leverages identity and context to understand human behavior and analyze the risk of every cloud email event—detecting and stopping sophisticated, socially-engineered attacks that target the human vulnerability.

You can deploy Abnormal in minutes with an API integration for Microsoft 365 or Google Workspace and experience the full value of the platform instantly. Additional protection is available for Slack, Workday, ServiceNow, Zoom, and multiple other cloud applications. Abnormal is currently trusted by more than 3,200 organizations, including over 20% of the Fortune 500, as it continues to redefine how cybersecurity works in the age of AI. Learn more at abnormal.ai.

Contacts

Media Contact:
Hanah Johnson
Senior Communications Manager
media@abnormal.ai

Abnormal AI


Release Versions

Contacts

Media Contact:
Hanah Johnson
Senior Communications Manager
media@abnormal.ai

More News From Abnormal AI

Abnormal AI Announces that SoftBank Corp. Begins Offering Its Enterprise Email Security Platform in Japan

TOKYO--(BUSINESS WIRE)--Abnormal AI, the AI-native behavior security company, today announced that SoftBank Corp. (“SoftBank”) began offering its email security platform to enterprise customers across Japan. Abnormal has operated in Japan since 2025, led locally by Country Manager Kei Mitsuyama. Through SoftBank’s offering of Abnormal's email security solution, Abnormal will be able to reach a broader base of enterprise customers across the country through SoftBank's enterprise sales network. P...

Abnormal AI Brings OpenAI Daybreak Models Into AI Cloud Security to Protect Against Rogue AI

SAN FRANCISCO--(BUSINESS WIRE)--The OpenAI-Hugging Face incident was a wake-up call for cyber defenders. During an internal cybersecurity evaluation, AI agents identified paths beyond their intended environment and accessed production infrastructure belonging to a third-party organization. The incident highlighted a challenge security teams increasingly need to prepare for: capable AI agents can identify weaknesses, connect multiple gaps and interact with cloud infrastructure faster than traditi...

Abnormal AI Joins Project Watershed 250 to Strengthen Cybersecurity for Texas Water Utilities

SAN ANTONIO--(BUSINESS WIRE)--Abnormal announces its participation in Project Watershed 250...
Back to Newsroom