Intent-Driven Contextual Reasoning Using Sentence Transformers for Business Email Compromise Detection
According to the FBI Internet Crime Complaint Center (IC3), Business Email Compromise (BEC) attacks resulted in reported losses of $3.04 billion dollars, making it one of the most financially devastating cybercrime categories facing organizations today. BEC encompasses a broad class of targeted scams including payroll fraud, aging report theft, and W-2 harvesting — attacks that, when successful, result in direct and significant financial loss to organizations. The rise of generative AI models has fundamentally changed the threat landscape. AI models such as DeepSeek enable threat actors to construct unlimited conversational payload variations at scale, making traditional detection approaches increasingly ineffective. Conventional methods — including fine-tuned BERT-based binary and multi-class classifiers — are particularly vulnerable to AI-generated attacks, as they can be bypassed by payload variations not seen during training. Furthermore, any new class of BEC attack requires the model to be retrained with sufficient variations of that attack class, opening a window of opportunity for exploitation by threat actors.
This talk presents a novel, AI-resilient approach to BEC detection. Incoming emails are broken into chunks of text, from which dense vector embeddings are computed using a Sentence Transformer model. These embeddings are compared against a library of intent embeddings stored in a vector database using cosine similarity to extract semantic intent from the email body. Candidate matches are further validated by a cross-encoder re-ranker — only chunks scoring above a defined threshold are confirmed as intent signals. Contextual reasoning of intent, combined with structural features derived from email headers, body of emails, attachments, and call-to-action URLs, is used to derive the final verdict of malicious or benign. We will demonstrate how this approach successfully detects AI-generated BEC variants across payroll fraud, aging report scams, invoice fraud, HR impersonation, and vishing attacks — and discuss how contextual reasoning of intent derived from the email body, combined with structural features from email headers, results in detections that are resilient to AI-generated attacks across variations, languages, and obfuscation techniques.

Mr Nguyễn Đức Kiên – Viettel Cyber Security
Abhishek Singh is Senior Director and Distinguished Architect at Mimecast, an AI and cybersecurity executive, founder, and technologist with 15+ years of experience leading AI and cybersecurity research, engineering, and architecture functions to design and scale AI-native security platforms for enterprise threat detection at production scale. He has led cross-functional teams delivering AI security systems processing millions of security events at Cisco and FireEye, enabling multi-million-dollar enterprise impact.
A prolific inventor, Abhishek holds 46+ patents across AI and cybersecurity, spanning EDR, XDR, DAST, active defense, email/web security, IPS, VM-based threat analysis, and predictive and generative AI for advanced threat detection.
His research includes 21 peer-reviewed papers, 7 technical white papers, and contributions to 3 books. He is a frequent conference speaker, with appearances at Black Hat, RSA, Virus Bulletin, CanSecWest, AVAR, CAMLIS, CARO, RISE, and ACSAC.
Abhishek holds a Master of Science in Computer Science and a Master of Information Security, both from the College of Computing at Georgia Tech; a B.Tech in Electrical Engineering from the Indian Institute of Technology (IIT-BHU); and a Master of Engineering Leadership (ELPP+) from UC Berkeley.