Skip to content
Rush Commerce
AI & Automation3 min read

AI-written email fraud slips your filters: verify out of band

StrongestLayer raised $4.1M as a third of email attacks now evade legacy filters. The fix for AI-era business email compromise isn't a smarter inbox — it's process.

On July 22, email-security startup StrongestLayer raised a $4.1M seed extension (to $9.3M total, led by Inovia Capital). The round is small; the reason it exists is not. Per the company's research, more than a third of attacks reaching inboxes now evade traditional detection — because the attacker used AI to write a clean, link-free message from an authenticated session, and your filter had nothing to pattern-match against.

What actually happened

Per StrongestLayer's announcement and SiliconANGLE:

  • The platform uses a reasoning-based approach — judging a message by intent and business context instead of matching known-bad signatures.
  • It targets business email compromise (BEC), executive impersonation, vendor fraud, advanced phishing, and adversary-in-the-middle attacks.
  • Production deployments grew more than eightfold in twelve months.
  • CEO Alan LeFort's framing: legacy tools "recognize attacks [they've] seen before" — and AI-written attacks are, by design, ones nobody has seen.

The shift is that modern attacks carry no malicious link or attachment. They ride trusted platforms and authenticated sessions and simply ask — reroute this invoice, update our banking details, wire it today. That's not a malware problem. It's a social-engineering problem wearing a legitimate sender's face.

Why this matters for your business

BEC is the fraud that empties small-business accounts, and it doesn't require a breach — just one convincing email to whoever cuts checks. A smarter filter helps, but you can't buy your way out of this with a product alone. The message that reroutes a $40K vendor payment will look perfect. The only reliable defense is a process the email can't talk its way around.

What we build for clients handling money or vendor data:

  1. Out-of-band verification, always. Any change to bank details, payment routing, or payout addresses gets confirmed on a second channel — a known phone number, not a reply. No exceptions for "urgent."
  2. An approval gate the sender can't reach. Payments over a threshold require a second human who never saw the original email — the same principle as keeping the approval gate out of an agent's reach.
  3. Assume the inbox is not the source of truth. Vendor records live in your system, verified once and changed only through your process — never because an email said so.

The attackers automated the con. The counter is to automate the check.

Key takeaways

  • StrongestLayer raised $4.1M (July 22) as it reports a third of inbox attacks now evade legacy filters
  • AI-written BEC carries no link or malware — it uses authenticated sessions and social engineering, so signature-based tools miss it
  • BEC targets whoever moves money; a perfect-looking email can reroute a real payment
  • The durable fix is process: out-of-band verification on any payment change, an approval gate the sender can't reach, and system-of-record truth over inbox truth

Is your payment approval a reply-all and a gut check? We build the verification and approval steps into your billing and vendor workflows so no single email can move money. See how we wire in the guardrails — or tell us where the money leaves the building.

Sources: StrongestLayer via PR Newswire, SiliconANGLE.

  • #email-security
  • #bec
  • #fraud-prevention
  • #automation
  • #small-business
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.