TLDR: Malwarebytes has expanded its ThreatDown endpoint protection portfolio by integrating IRONSCALES’ AI-powered email security capabilities. The new ThreatDown Email Security module, now available to customers and soon to MSPs and MSSPs, leverages adaptive and agentic AI to combat sophisticated threats like phishing and business email compromise (BEC). This addition addresses a critical customer demand for streamlined, automated solutions against evolving email-based cyberattacks.
Cybersecurity firm Malwarebytes is significantly enhancing its ThreatDown endpoint protection portfolio by incorporating advanced email security capabilities through a partnership with IRONSCALES. This strategic integration introduces the new ThreatDown Email Security module, which is now available to all customers and is slated for release to Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs) in early August 2025.
According to Marcin Kleczynski, founder and CEO of Malwarebytes, the decision to add email security was straightforward, driven by overwhelming customer demand. Kleczynski stated, “Defending against phishing and other modern email threats is a huge pain point for IT resource-constrained organizations. It was the number-one request from our customers and a natural fit for our platforms.” He further emphasized the need for “streamlined solutions that expand attack surface protection while automating configuration, detection, and remediation, leveraging the tools they already own.”
This move comes as email security remains a paramount concern across the cybersecurity landscape. Recent industry activities underscore this focus, with Bitdefender acquiring Mesh Security in June to bolster its managed detection and response (MDR) and extended detection and response (XDR) offerings, and startup Trustifi securing $25 million in funding last month to scale its email security portfolio.
The new Malwarebytes module seamlessly integrates with its cloud-based security operations platform, Nebula, and OneView, its multi-tenant console for MSPs. This integration aims to simplify management complexity for businesses.
The urgency for robust email security is highlighted by alarming statistics. Hoxhunt, a cybersecurity training platform, reported that 64% of businesses faced Business Email Compromise (BEC) attacks last year, with each incident incurring an average financial loss of $150,000. Furthermore, approximately 80% of phishing campaigns are designed to steal credentials, frequently targeting cloud-based services like Microsoft 365 and Google Workspace through highly realistic, yet fraudulent, login pages. A significant 80% of phishing websites now incorporate HTTPS to appear legitimate and evade detection. The threat landscape is also expanding beyond traditional email, with about 40% of phishing campaigns now extending to channels such as voice technology, QR codes, Slack, Teams, and social media. IBM’s data further underscores the severity, noting that the average cost of a phishing breach reached an all-time high of $4.88 million last year.
A key component of Malwarebytes’ new offering is IRONSCALES’ AI-powered capabilities, which include adaptive AI (combining technology with human intelligence) and agentic AI for Security Operations Centers (SOCs). Audian Paxson, principal technical strategist at IRONSCALES, elaborated on the role of agentic AI, explaining that while traditional AI assists, agentic AI “assesses, prioritizes, and takes action without waiting for human intervention.” This allows it to effectively counter highly crafted or novel attacks that might bypass conventional systems.
The AI-based threat detection within the module leverages machine learning, natural language processing, computer vision, and behavioral analysis. Additional IRONSCALES-based features include the ability to instantly remove or quarantine malicious emails even after delivery, native API integration with Microsoft 365 and Google Workspace for agentless, four-click deployment, and streamlined operations through unified management within the ThreatDown console. The module also benefits from a crowdsourced element, enhancing detection accuracy by utilizing data from over 16,000 security teams globally and incorporating human-in-the-loop feedback.
Also Read:
- SentinelOne Bolsters AI Security Portfolio with Key Offerings on AWS Marketplace
- Microsoft Introduces Sentinel Data Lake for Enhanced AI-Powered Cybersecurity and Cost Efficiency
Kleczynski concluded by emphasizing the significant benefits for MSPs and MSSPs, who serve as “frontline defenders” for organizations with limited IT resources. He reiterated that email security was a “top priority” request from this crucial community.


