Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • Darktrace AI fends off phishing attack on North American private equity firm

Security

Darktrace AI fends off phishing attack on North American private equity firm

Darktrace today announced that its AI-powered email security solution, Antigena Email, recently uncovered a targeted phishing attack at a North American private equity firm.


Image courtesy Darktrace

The company, which manages over 150 restaurants across the US, was trialling Darktrace’s Self-Learning AI when the attack took place. Intending to bolster email security, the company had deployed Darktrace’s email security solution, Antigena Email, which had learned the ‘normal’ email communications of every user within the organisation in order to detect the abnormalities associated with an email threat.

Advertisement
ODU RT

The attack, which slipped past the company’s existing security controls, started when an employee received an email appearing to originate from internal ‘HR’. The email had been carefully designed to look like a SharePoint Microsoft document and was titled ‘Q3 Commission 2021 and Agenda’, an attempt to induce the recipient into clicking on a malicious link.

Detecting that the IP address of the email was unusual, Darktrace AI identified this as spoofing activity and further investigation suggested it was part of a wider trend of targeted phishing campaigns at the time which used fake Microsoft branding. These attacks are often launched with the intention of causing operational disruption or conducting IP and financial theft.

The company’s security team were alerted and issued company-wide warnings about the attack, averting a crisis. Had Antigena Email been deployed in fully autonomous mode, it would have double-locked the malicious links to ensure they were not clickable.

“Email impersonation attacks have been on the rise for a number of years – these are hyperrealistic ‘digital fakes’ that expertly mimic the writing style of trusted contacts, colleagues and suppliers,” commented Mike Beck, Darktrace’s Global CISO. “We simply cannot put the onus on humans to spot these well-researched, targeted email attacks and that’s why it is crucial that organisations have AI in place as a first line of defense – capable of detecting the subtle signs of a fake and intervening before a user even has to engage with the email. This is the future of email security.”

Advertisement
PTC rectangle

 

 

Advertisement
FIA2026 animated banner
Anti-drone tech patents surge

Aerospace Defence Security

Anti-drone tech patents surge

19 March 2026

The number of patent applications for anti-drone (counter-UAV) technologies filed globally increased by 27% to 126 last year*, up from 99 the year before, according to new research from intellectual property (IP) law firm Mathys & Squire.

Marshall Aerospace secures five SAIL Mark projects

Aerospace Defence Security

Marshall Aerospace secures five SAIL Mark projects

18 March 2026

Marshall Aerospace is advancing its expertise in the UK’s fast-growing unmanned aircraft systems (UAS) sector after securing five separate SAIL Mark assessment projects funded by Innovate UK and the Department for Transport.

UK engineers advance innovative way to tackle drone threats

Defence Security

UK engineers advance innovative way to tackle drone threats

18 March 2026

A team of UK based engineers is developing a new way of eliminating hostile drones.

Met Office launches MAVIS

Aerospace Security Space

Met Office launches MAVIS

18 March 2026

The Met Office have officially launched the Met Office Aeronautical Visualisation Service (MAVIS) - a next-generation aviation weather platform designed to support a rapidly evolving aviation landscape, from traditional crewed aircraft to emerging spaceport operations.

Advertisement
PTC rectangle
JFD opens new Singapore facility

Defence Security

JFD opens new Singapore facility

18 March 2026

Provider of specialist marine and defence solutions, James Fisher and Sons plc (JFD Global), has expanded its Asia Pacific footprint with the official opening of a new facility in Singapore.

Glasgow to host CYBERUK 2026

Security Events

Glasgow to host CYBERUK 2026

17 March 2026

International cyber security chiefs will convene next month at the Scottish Event Campus (SEC), Clydeside, Glasgow, for the UK’s flagship cyber conference, CYBERUK (21st-23rd April), to discuss accelerating defences in the face of rising online threats.

Advertisement
ODU RT
Advertisement
FIA2026 animated banner