Abnormal AI
Abnormal AI (formerly Abnormal Security) is an AI-native security company headquartered in San Francisco, California, delivering behavioral AI-powered protection for email, cloud applications, and the modern digital workplace. Founded in …
What Abnormal AI Does
Abnormal AI (formerly Abnormal Security) is an AI-native security company headquartered in San Francisco, California, delivering behavioral AI-powered protection for email, cloud applications, and the modern digital workplace. Founded in 2018, the company raised a $250 million Series D funding round at a $5.1 billion valuation led by Wellington Management, with participation from Greylock Partners, Menlo Ventures, Insight Partners, and the CrowdStrike Falcon Fund, bringing total funding to approximately $580 million.
As of 2025, Abnormal AI has exceeded $200 million in annual recurring revenue with 100%+ year-over-year growth. The company serves over 3,200 organizations across 35 countries, including over 20% of the Fortune 500 and has stopped nearly $1 billion in fraud.
The Abnormal platform uses behavioral AI baselines built from thousands of signals per user to detect business email compromise (BEC), account takeover, supply chain compromise, and AI-generated attacks that bypass traditional secure email gateways and filters. Abnormal AI expanded beyond email in 2025 to cover collaboration tools (Slack, Teams), cloud identity providers, and financial platforms, rebranding from Abnormal Security to Abnormal AI in April 2025.
The company was named to the CNBC 2025 Disruptor 50 list. Abnormal AI integrates with Microsoft 365, Google Workspace, and major SIEM/SOAR platforms, and holds SOC 2 Type II certification.
The company employs approximately 500–700 people globally. Abnormal AI works at the email and human-behaviour layer rather than the endpoint or network layer, so it is deployed alongside CrowdStrike, SentinelOne or Microsoft Defender rather than as a replacement for them.
The comparison buyers actually run is against Microsoft Defender for Office 365 and legacy secure email gateways such as Proofpoint and Mimecast, and it turns on a different question: not whether malware is blocked, but whether a payment-redirect or vendor-invoice request that contains no attachment, no link and no malware is recognised as fraudulent. Because Abnormal integrates through cloud email APIs rather than sitting inline as a gateway, it can be evaluated on live mail flow without re-routing it.
Commercially it is the least transparent vendor in this group: its AWS Marketplace listing is private-offer only with no published tiers, so every deal is scoped and quoted. Best fit: Microsoft 365 or Google Workspace estates losing money to business email compromise, where the business case is measured in avoided fraud losses rather than blocked malware volume.
Sign in with your company email to claim and enrich this profile.