Highlights
- 50% reduction in phishing triage workload
- ~70% net drop in a major invoicing phishing campaign
- 2-3 detections per 10,000 that need no action
- 12 hours from forwarding to fully operational
Background
McAfee publishes two customer-facing abuse mailboxes, [email protected] and [email protected], and the volume is substantial. Reports arrive from around the world covering phishing, malware, and scams of every kind, much of it unrelated to McAfee itself. That data already fed several internal pipelines, and the resulting intelligence flowed back to customers through McAfee’s products and services.
The Problem
The mailbox was being read for everything except McAfee. Analysis looked at submissions as a whole rather than hunting for brand infringement, so campaigns impersonating McAfee could pass through unexamined. The team had used brand protection vendors before, but McAfee runs on a culture of constant review and improvement, and the question of whether to keep buying or start building was open. Building meant owning the planning, requirements, maintenance, updates, and features, and then absorbing the ongoing admin: takedowns, ticket management, and every process attached to them.
The Solution
McAfee began evaluating replacements four to six months ahead of renewal of their previous vendor, running proofs of concept and in-depth comparisons before making a recommendation. Bolster AI won on AI identification. Reported phishing tends to repeat, so once a single detection lands, everything downstream of it surfaces with it. Setup was straightforward, since the abuse mailbox simply forwards to a mirror inbox, and Bolster AI can be fully operational within 12 hours. What sealed it was how the two teams work: McAfee’s analysts treat the Bolster AI SOC as an extension of their own, in constant communication rather than handing tasks into a black box.
The Results
In 2024, McAfee identified a large-scale invoicing phishing campaign that abused a third-party invoicing vendor and carried McAfee branding. The team handed the entire effort to Bolster AI, which worked the vendor directly and cut abuse through that channel by roughly 90%. Attackers shifted to lesser-known invoicing vendors, and the net reduction still landed around 70%. Day to day, Kelly Brown estimates a 50% reduction in triage workload, and she suspects the real figure is higher, because only two or three items per 10,000 detections need no action. Bolster AI has also returned more than 1,300 malicious phone numbers for blocking, since so many phishing lures now ask the victim to call rather than click.
“The Bolster AI SOC team is effectively an extension of our SOC team. We’re always working together, constantly communicating.” — Kelly Brown, Information Security Specialist, McAfee