Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Detecting BEC Attacks with Sophos Fusion

Sophos
09/21/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


excited to be announcing and sharing that at this Black Hat we have launched Sophos Fusion. Sophos Fusion is a system. Sophos Fusion is an AI native cybersecurity defense system that reacts, that adapts to your environment. It doesn't matter where it's happening or what is happening, we can see it. We have a truly open platform. It's not a platform. We have a truly open stack. It's not a stack. It is a system. It is not even a stack of platforms. Like I said, it is a system and there is a difference. Everywhere you walk around here you're gonna hear about platforms. You're gonna hear about stacks, but we are talking about a system. Like I mentioned, a truly open system. You do not need to have Sophos products. You do not need to have Sophos as your endpoint or your control point. We can have this open system and you can bring what you have. And core of this system is our functionality and an ability to be able to have early detections and signs of business email compromise. And to talk more about that, I am going to hand over to my good friend, who I'd like to introduce you to, Jake Welter. Jake, over to you. Alright, so we are not talking about malware. We're not talking about any exploits. We're talking about simple email. Just a basic email. So you guys have heard this use case many times before, but here's what happens in a business email compromise attack. So this is all about exploiting trust. So I'm gonna come in and pose as the CEO and I'm gonna send an email late on a Friday afternoon and say, hey you know what? This is for the business. I need you to wire $47,000. I'm in a board meeting. Don't tell anyone because this is for the business. So what's the CFO gonna do in that situation? They're trying to get home. They're trying to start the weekend. CEO sends it. I'm gonna send that wire. Send that wire. Go home. You're good to go. Start the weekend. So this trend is not going away. This is over the last 10 years, almost $20 billion from 2015 to 2025. This 2.8 is just one year. That's 2024 and these are just what was reported to the FBI. So that number is probably way higher. And again, over a thousand percent. So this is not going away anytime soon and business email compromise really exploits that trust factor and it lives in those gaps. So we'll talk about how Salesforce defends against that. So again, I'm gonna exploit your organisation. So I'm gonna do my profile. I'm gonna get on LinkedIn. I'm gonna do my research. Find out about the organisation and build my attack. I'm gonna either find credentials. I'm gonna spoof an email and then I'm gonna always have urgency. This is always in the attack of, hey, you know what? You need to send this right now. And the attack doesn't end right there. That breach doesn't stop right there. It's only if somebody finds this or sees this. So I'm gonna keep doing this until they figure out what's going on. And again, no malware. You're not popping any alerts for anything suspicious like that. So let's talk about victims of all sizes. So I hear this often where, hey, maybe we're too big or we're too small. No one's gonna attack us with this and it really has nothing to do with size. So over here on the left, you can see this is a major manufacturer globally. Got hit for almost 40 million dollars. Local government, six million dollars. Who's on the hook for that? Taxpayers are. So now they gotta borrow to go and fill that gap. This one's rare. So I wanted to show that this does happen. The bank actually caught it and said no. So there's that. So this is the big thing again. It's all about exploiting trust and living in the gaps of your tools. So email, identity. Maybe you have someone watching this or you don't. It's not technically malicious. It's socially malicious. Again, exploiting that trust factor and that's what I'm gonna do to get my payday. So we're gonna take a look at Mr. Kelly here. So I've been in his inbox for the last 11 days. I now know the vendors. I now know the approval process. I know the CEO. I know that the CEO is gonna be traveling next week. Sweet. I'm ready to go. So we'll look at real telemetry that Sophos Fusion has seen and we can stitch those silos together to paint that picture in real time. Again, it depends on hey, who's looking at this? Maybe I'm gonna look at it next week. Maybe there was an alert in another silo and if you're not doing that real-time stitching, you're not seeing the complete picture. So in this attack we can see this untrusted sign-in from across the globe. Hey, I signed in from this Tor node. That's bad. That's super bad. I'm changing email forwarding rules in the inbox. Again, the victim doesn't know that this is happening but I can see what's going on in the organization and so this is where we can stitch this all together. This is all within minutes. The same minute where we can see that telemetry and actually build that case and defend against it. More evidence of these events so we can see these exchange rules being changed in real time. And then the big piece of this is where we actually stitch that together and provide this to you in plain English of hey, you know what? This came in from across the globe and this is bad. So as an analyst, we're giving it to you in plain English. These key findings, all of these highlighted highlights will directly link you to more information about the case. All in the same system and you're gonna get more information around that. So hey, you know what? What is this attack technique? I don't remember. We're gonna link you directly to it. So we're gonna do this in key findings. And again, it's all about visibility, about that trust factor. So your tools were not built for this but Sophos was. So we can see the telemetry. We can see the user intent within email and say this is odd. This is not correct for this user. Let's go take a look at that and stitch that together with identity. So identity will come in and say hey, you know what? Our SOC will see that untrusted sign-in. We'll be able to go and take actions. We can go revoke that session, remediate before it ever becomes an issue. And again, this is where MDR stops these attacks live. So that's all about Fusion. Your tools are not the problem. It's all about stitching that story together in real time and that's what we can do. So go home, go check your emails. We'll be watching it and that's all for me. Thank you.

TL;DR

  • Sophos launched Fusion at Black Hat 2026, positioning it as an AI-native, open cybersecurity defense system that works with any vendor's existing tools — not just Sophos products.
  • Business email compromise caused nearly $20 billion in losses from 2015 to 2025, with $2.8 billion reported to the FBI in 2024 alone, and the trend shows no signs of slowing.
  • BEC attacks succeed by exploiting trust and urgency rather than malware, making them invisible to traditional security tools that rely on signature-based or behavioral malware detection.
  • Sophos Fusion detects BEC by correlating email, identity, and telemetry signals in real time — surfacing Tor-node logins and inbox rule changes as a unified case in plain English for analysts.

Summary

Presented live at Black Hat 2026, this session marks the public launch of Sophos Fusion, an AI-native cybersecurity defense system designed to detect and stop business email compromise (BEC) attacks. Anthony Boisi opens by distinguishing Fusion from conventional platforms and stacks, positioning it as a truly open system that does not require Sophos endpoint products to function — customers can bring their existing tooling. Jake Welter then takes over to walk through the anatomy of a BEC attack: no malware, no exploits, just social engineering that exploits trusted relationships and urgency to trick employees into wiring funds. He cites FBI data showing nearly $20 billion in BEC losses from 2015 to 2025, with $2.8 billion reported in 2024 alone — and notes the real figure is likely far higher. Welter demonstrates how Sophos Fusion stitches together email, identity, and security telemetry in real time to surface suspicious signals — such as a Tor-node sign-in and inbox forwarding rule changes — that would otherwise sit in disconnected silos. The system presents findings in plain English with direct links to MITRE ATT&CK techniques, enabling analysts to act quickly. Sophos MDR is highlighted as the response layer that can revoke sessions and remediate threats before financial loss occurs.

Chapters

0:00 - Sophos Fusion Launch Announcement
1:37 - How BEC Attacks Work
2:41 - BEC Financial Impact & Scale
4:08 - Attack Anatomy: Victims of All Sizes
5:13 - Live Telemetry Demo with Sophos Fusion
7:24 - Detection, Response & MDR

Key Quotes

0:12 "Sophos Fusion is an AI native cybersecurity defense system that reacts, that adapts to your environment."
0:59 "Everywhere you walk around here you're gonna hear about platforms. You're gonna hear about stacks, but we are talking about a system."
2:41 "This is over the last 10 years, almost $20 billion from 2015 to 2025. This 2.8 is just one year. That's 2024 and these are just what was reported to the FBI. So that number is probably way higher."
5:02 "It's not technically malicious. It's socially malicious. Again, exploiting that trust factor and that's what I'm gonna do to get my payday."
7:30 "Your tools were not built for this but Sophos was."
8:08 "Your tools are not the problem. It's all about stitching that story together in real time and that's what we can do."

FAQ

Does Sophos Fusion require Sophos endpoint or email security products to work?

No. Sophos positions Fusion as a truly open system, explicitly stating that customers do not need Sophos as their endpoint or control point and can bring their existing tools.

How does Sophos Fusion detect BEC attacks that generate no malware alerts?

Fusion correlates signals across email, identity, and security telemetry in real time — flagging anomalies like Tor-node sign-ins and inbox forwarding rule changes within minutes and presenting them as a unified case in plain English, enabling analysts to revoke sessions and remediate before financial loss occurs.


Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Email Security
  • Threat Intelligence
  • Security Operations
  • AI & Machine Learning
  • Demo
  • Technical Deep Dive
  • Business Email Compromise
  • BEC
  • Sophos Fusion
  • AI-native security
  • Email security
  • Identity threat detection
  • Security signal correlation
  • Social engineering
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Detecting BEC Attacks with Sophos Fusion

              Industry Events (Sponsor Hosted)

              • Sep
                23

                Invisible Data: The Key to Effective Protection Strategies

                09/23/202601:00 PM ET
                • Sep
                  29

                  Embracing AI Adoption While Ensuring Robust Security Measures

                  09/29/202612:00 PM ET
                  • Oct
                    15

                    Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                    10/15/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 09/23/2026
                      01:00 PM
                      09/23/2026
                      Invisible Data: The Key to Effective Protection Strategies
                      https://www.truthinit.com/index.php/channel/2087/invisible-data-the-key-to-effective-protection-strategies/
                    • 09/29/2026
                      12:00 PM
                      09/29/2026
                      Embracing AI Adoption While Ensuring Robust Security Measures
                      https://www.truthinit.com/index.php/channel/2092/embracing-ai-adoption-while-ensuring-robust-security-measures/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Enhanced Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-enhanced-visibility-and-control-in-your-operations/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version