Go back

Email Security Fought Its War to a Draw. The Battlefront Moved.

The war for email security has reached a stalemate, shifting the front lines of modern data breaches to your cloud workspace, OAuth tokens, and sensitive files.

Product
July 30, 2026
7m read
7m read
7m listen
7m watch
7m watch
Email Security Fought Its War to a Draw. The Battlefront Moved.Email Security Fought Its War to a Draw. The Battlefront Moved.
speakers
speakers
speakers
authors
Material Team
participants
No items found.
share

The war for email security has reached a stalemate, shifting the front lines of modern data breaches to your cloud workspace, OAuth tokens, and sensitive files.

TL;DR: Phishing's share of initial access has barely moved in years, according to Verizon's 2026 Data Breach Investigations Report. It's not a story about winning. The fight at the perimeter stopped being the one that decides outcomes. Credential theft, OAuth token abuse, and AI-written attacks that no longer look like attacks have moved the decisive part of the breach downstream of the inbox, into the accounts, files, and connected apps that make up the cloud workspace. Here's what the data actually shows, and what it means to defend the thing that's really under attack. Read more here.

For twenty years, email security had one job: catch the bad message before it reached the inbox. Filter the spam, flag the phish, quarantine the malware. It was a clean model, and for a while, it worked well enough that most companies stopped thinking about it.

That model is not obviously failing. Verizon’s 2026 DBIR reports that phishing’s share of initial access "has barely moved over the past few years." Read that sentence twice. It doesn’t say phishing is winning. It says the war at the perimeter has settled into a stalemate: attackers keep sending, filters keep catching, and the ratio barely changes year over year.

A stalemate at the front door would be fine, except the front door stopped being where the damage happens. Credential abuse shows up in 39% of breaches at some point in the attack chain, more than any other initial access vector, and a growing share of that abuse never touches a filter at all. The interesting question in email security right now isn’t how many attacks get caught. It’s what happens to the ones that don’t, and increasingly, to the ones that were never really about email in the first place.

The attacker's side of the ledger became free

Some of the stalemate is explained by simple economics. Generative AI didn’t make phishing smarter than filters. It made producing unlimited, well-written variations of the same attack functionally free, and that changes who wins a war of attrition.

SlashNext measured a 1,265% increase in malicious phishing emails in the year following ChatGPT’s public launch, a jump large enough that a rounded "13x" barely overstates it. A more recent academic study, presented at the 2025 ACM Internet Measurement Conference, found that by April 2025, at least 51% of spam and 14% of business email compromise attempts in a dataset of nearly half a million malicious emails were LLM-generated, with BEC’s share nearly doubling in a single year. The same researchers found something more specific than volume: LLM-written attacks were measurably more formal, grammatically cleaner, and more linguistically sophisticated than the ones a human wrote. Every heuristic a security awareness program spent a decade teaching, watch for typos, watch for broken English, watch for the too-urgent tone, is quietly going extinct. The DBIR’s own authors put it as a joke, but it isn’t really one: the advice is shifting from "does it contain typos" to "does it contain em dashes."

None of this means the filter got worse at its job. It means the job stopped being the whole job.

The breach happens after the click, or with no click at all

Follow a modern breach past the moment of delivery and a consistent shape emerges: these are stories about accounts and access, not about messages. Among ransomware victims with a prior credential or infostealer leak, half were compromised within 95 days of that leak. Small organizations, the ones least likely to be watching closely, saw a median of seven separate credential-leak events in a single year. None of that activity requires a phishing email to work. It requires a password or a token that already got out.

Then there’s the category that never involves email at all. Third-party involvement in breaches rose 60% year over year, reaching 48% of all breaches, per the same DBIR. The clearest recent example: attackers compromised OAuth tokens tied to a third-party integration and used them to pivot directly into the Salesforce environments of a list of companies that included Google, Zscaler, and Cisco. No phishing email. No malware. Just a trusted app token, authorized long ago by someone who has probably forgotten it exists, doing exactly what tokens are built to do.

This is the blind spot baked into inbox-centric security. A tool built to inspect inbound mail stops paying attention the moment a message is delivered or, worse, never had a message to inspect in the first place. The session that gets hijacked, the OAuth grant that gets abused, the years of sensitive mail sitting in a compromised mailbox: none of it happens in front of a filter.

The workspace sprawled past the inbox a while ago

Even without an active attacker, the cloud workspace has been quietly accumulating risk on its own. In Material’s own analysis of Google Drive environments, sensitive files grew by more than 1,100% over an eight-month window, nearly three times the growth rate of files overall, and well over a quarter of all files in Google Drive now contain sensitive data. No attacker required. It’s the ordinary, well-intentioned consequence of people sharing documents to get work done, at a pace nobody is tracking.

Connected apps tell a similar story. In an analysis of more than 22,000 OAuth-connected applications across 21 enterprise Google Workspace environments, nearly half showed no active usage in 90 days, yet every one of those authorizations remained fully live. More than a thousand apps had zero active users and a still-valid token, and a large share of those held sensitive or fully restricted permissions: read every email, send as the employee, reach every file in Drive. Lyft’s CISO, Chaim Sanders, has a name for these: zombie connections, "technically authorized, practically abandoned, and invisible to most of the controls we rely on."

AI adoption is accelerating all of it. Of the AI applications connected to corporate Google Workspace environments in that same dataset, 91% first appeared within the last 16 months, and most were never formally approved by anyone. Someone clicked authorize, and that was the entire review process. This is consistent with what Verizon is seeing from the user side: 45% of employees are now regular AI users at work, up from 15% a year earlier, and two-thirds of them are doing it from non-corporate accounts on corporate devices.

Unlike the SaaS sprawl of a decade ago, these aren’t passive integrations that read data and surface a suggestion. Agents act. What an AI agent does with the access it holds gets decided at the moment it runs, not at the moment someone granted the permission months earlier.

What actually has to change

None of this is an argument for turning off email filters. Inbound detection is still necessary, and a system that ignores obvious threats at the door is not a serious security program. It’s an argument that the filter was never going to be sufficient on its own, and that the data has been saying so for a while.

A few things follow from that. Grade the program on what an attacker can do after they get in, not on catch rate alone; a phish will land or a token will leak eventually, and the outcome depends on what happens next. Protect the data itself, in mailboxes and in Drive, so a compromised account yields a locked vault rather than an open archive. Treat OAuth connections as a governed asset with an owner and an expiration, not a one-time click that nobody revisits. And stop asking three separate tools to watch email, identity, and files in isolation, because the attacker was never going to respect those boundaries just because the org chart does.

Email security fought its war to a draw. The war moved into the accounts, the files, and the connected apps that make up the cloud workspace, and it’s been there for a while. The organizations that have already noticed are the ones asking a different question than "did we catch the phish." They’re asking what’s actually sitting in the workspace right now, and who, or what, can reach it.

Frequently Asked Questions

Find answers to common questions and get the details you need.

No items found.

Related posts

Our blog is your destination for expert insights, practical tips, and the latest news in technology. Stay informed with our regular updates and in-depth articles. Join the conversation and enhance your understanding of the tech landscape.

blog post

The Debug Agent That Does the Detective Work First

See how Material uses a hypothesis-driven Debug Agent to automate technical triage and reclaim engineering time.

Melissa Leigh Gore
7
m read
Read post
Podcast

The Debug Agent That Does the Detective Work First

See how Material uses a hypothesis-driven Debug Agent to automate technical triage and reclaim engineering time.

7
m listen
Listen to episode
Video

The Debug Agent That Does the Detective Work First

See how Material uses a hypothesis-driven Debug Agent to automate technical triage and reclaim engineering time.

7
m watch
Watch video
Downloads

The Debug Agent That Does the Detective Work First

See how Material uses a hypothesis-driven Debug Agent to automate technical triage and reclaim engineering time.

7
m listen
Watch video
Webinar

The Debug Agent That Does the Detective Work First

See how Material uses a hypothesis-driven Debug Agent to automate technical triage and reclaim engineering time.

7
m listen
Listen episode
blog post

Lessons from the Hugging Face Incident: Stop Trying to Never Get Breached

What the Hugging Face incident reveals about the only security strategy that still makes sense in the age of AI agents.

Material Research Team
5
m read
Read post
Podcast

Lessons from the Hugging Face Incident: Stop Trying to Never Get Breached

What the Hugging Face incident reveals about the only security strategy that still makes sense in the age of AI agents.

5
m listen
Listen to episode
Video

Lessons from the Hugging Face Incident: Stop Trying to Never Get Breached

What the Hugging Face incident reveals about the only security strategy that still makes sense in the age of AI agents.

5
m watch
Watch video
Downloads

Lessons from the Hugging Face Incident: Stop Trying to Never Get Breached

What the Hugging Face incident reveals about the only security strategy that still makes sense in the age of AI agents.

5
m listen
Watch video
Webinar

Lessons from the Hugging Face Incident: Stop Trying to Never Get Breached

What the Hugging Face incident reveals about the only security strategy that still makes sense in the age of AI agents.

5
m listen
Listen episode
blog post

Apple's Offboarding Mistake Opens a Bigger Conversation

Unrevoked OAuth tokens and stale permissions create a significant security risk, allowing access to internal systems to silently outlive an employee’s tenure long after they depart.

Material Research Team
12
m read
Read post
Podcast

Apple's Offboarding Mistake Opens a Bigger Conversation

Unrevoked OAuth tokens and stale permissions create a significant security risk, allowing access to internal systems to silently outlive an employee’s tenure long after they depart.

12
m listen
Listen to episode
Video

Apple's Offboarding Mistake Opens a Bigger Conversation

Unrevoked OAuth tokens and stale permissions create a significant security risk, allowing access to internal systems to silently outlive an employee’s tenure long after they depart.

12
m watch
Watch video
Downloads

Apple's Offboarding Mistake Opens a Bigger Conversation

Unrevoked OAuth tokens and stale permissions create a significant security risk, allowing access to internal systems to silently outlive an employee’s tenure long after they depart.

12
m listen
Watch video
Webinar

Apple's Offboarding Mistake Opens a Bigger Conversation

Unrevoked OAuth tokens and stale permissions create a significant security risk, allowing access to internal systems to silently outlive an employee’s tenure long after they depart.

12
m listen
Listen episode
blog post

The Inbox is a Master Key. Material Secures It Like One

Material Security protects the identity layer inside your email by applying conditional access to sensitive credentials like magic links and password resets, preventing attackers from using the mailbox as a master key to downstream applications.

Material Security Team
7
m read
Read post
Podcast

The Inbox is a Master Key. Material Secures It Like One

Material Security protects the identity layer inside your email by applying conditional access to sensitive credentials like magic links and password resets, preventing attackers from using the mailbox as a master key to downstream applications.

7
m listen
Listen to episode
Video

The Inbox is a Master Key. Material Secures It Like One

Material Security protects the identity layer inside your email by applying conditional access to sensitive credentials like magic links and password resets, preventing attackers from using the mailbox as a master key to downstream applications.

7
m watch
Watch video
Downloads

The Inbox is a Master Key. Material Secures It Like One

Material Security protects the identity layer inside your email by applying conditional access to sensitive credentials like magic links and password resets, preventing attackers from using the mailbox as a master key to downstream applications.

7
m listen
Watch video
Webinar

The Inbox is a Master Key. Material Secures It Like One

Material Security protects the identity layer inside your email by applying conditional access to sensitive credentials like magic links and password resets, preventing attackers from using the mailbox as a master key to downstream applications.

7
m listen
Listen episode
Privacy Preference Center

By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.

New