Assuming a security analyst is allowed to look at content that's been identified as malicious beyond some threshold like 99.9%...<p>And in order to address emerging threats, they should be able to apply their judgement based on threat indicators like known bad hashes, origin from known bad email addresses or IPs, etc. to call something malicious beyond that threshold...<p>Does that mean that if they know your account is under attack they can just read all of your emails?<p>I would give that a big "no" because unless your account has 999 malicious emails in it for every benign one, they have not met the criteria.