Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • Darktrace AI fends off phishing attack on North American private equity firm

Security

Darktrace AI fends off phishing attack on North American private equity firm

Darktrace today announced that its AI-powered email security solution, Antigena Email, recently uncovered a targeted phishing attack at a North American private equity firm.


Image courtesy Darktrace

The company, which manages over 150 restaurants across the US, was trialling Darktrace’s Self-Learning AI when the attack took place. Intending to bolster email security, the company had deployed Darktrace’s email security solution, Antigena Email, which had learned the ‘normal’ email communications of every user within the organisation in order to detect the abnormalities associated with an email threat.

Advertisement
Security & Policing Rectangle

The attack, which slipped past the company’s existing security controls, started when an employee received an email appearing to originate from internal ‘HR’. The email had been carefully designed to look like a SharePoint Microsoft document and was titled ‘Q3 Commission 2021 and Agenda’, an attempt to induce the recipient into clicking on a malicious link.

Detecting that the IP address of the email was unusual, Darktrace AI identified this as spoofing activity and further investigation suggested it was part of a wider trend of targeted phishing campaigns at the time which used fake Microsoft branding. These attacks are often launched with the intention of causing operational disruption or conducting IP and financial theft.

The company’s security team were alerted and issued company-wide warnings about the attack, averting a crisis. Had Antigena Email been deployed in fully autonomous mode, it would have double-locked the malicious links to ensure they were not clickable.

“Email impersonation attacks have been on the rise for a number of years – these are hyperrealistic ‘digital fakes’ that expertly mimic the writing style of trusted contacts, colleagues and suppliers,” commented Mike Beck, Darktrace’s Global CISO. “We simply cannot put the onus on humans to spot these well-researched, targeted email attacks and that’s why it is crucial that organisations have AI in place as a first line of defense – capable of detecting the subtle signs of a fake and intervening before a user even has to engage with the email. This is the future of email security.”

Advertisement
ODU RT

 

 

Advertisement
General Atomics LB
Farnborough International Airshow 2026 unveils new features

Aerospace Defence Security Space Events

Farnborough International Airshow 2026 unveils new features

22 January 2026

The Farnborough International Airshow 2026, returning from 20th to 24th July 2026, will be the largest and most ambitious event in its 78-year history, following record-breaking demand and the addition of a brand-new sixth exhibition hall

SatVu appoints Scott Herman as CTO

Defence Security Space

SatVu appoints Scott Herman as CTO

22 January 2026

UK based high resolution thermal intelligence company SatVu, that reveals operational activity and infrastructure performance from space, today announced the appointment of Scott Herman as Chief Technology Officer (CTO).

Smiths Detection delivers automated IRBS between South Korea and US

Aerospace Security

Smiths Detection delivers automated IRBS between South Korea and US

21 January 2026

Smiths Detection has enabled the launch of a fully automated International Remote Baggage Screening System (IRBS), setting a new global standard for cross-border aviation security and passenger processing between South Korea and the United States.

Amentum and Rolls-Royce SMR partner on small modular reactors

Security

Amentum and Rolls-Royce SMR partner on small modular reactors

20 January 2026

Amentum has been selected as the programme delivery partner for the first deployments of the Rolls-Royce Small Modular Reactor (SMR) in the UK and Czech Republic.

Advertisement
ODU RT
NCSC issues hacktivist warning

Security

NCSC issues hacktivist warning

20 January 2026

The National Cyber Security Centre (NCSC) – a part of GCHQ – has issued an alert highlighting the persistent targeting of UK organisations by Russian state-aligned hacktivist groups aiming to disrupt networks.

GeoCue partners with Coptrz to expand TrueView LiDAR in UK drone market

Aerospace Defence Security

GeoCue partners with Coptrz to expand TrueView LiDAR in UK drone market

20 January 2026

UK drone specialists Coptrz have joined forces with GeoCue to offer the complete TrueView LiDAR product range, from entry-level to engineering-grade solutions.

Advertisement
Security & Policing Rectangle
Advertisement
Babcock LB Babcock LB