Join our Newsletter — 33% off our NHI Course

Why do malicious mail rules increase the impact of business email compromise?

Malicious mail rules matter because they let attackers automate stealth, exfiltration, and persistence after they get into a mailbox. A rule can hide warning messages, forward sensitive mail to an external account, or delete messages from specific senders. That gives the attacker time to impersonate executives, monitor investigations, and continue harvesting data even if the victim changes their password.

How malicious mail rules extend a BEC foothold

business email compromise is often most damaging after the initial login, because mailbox rules turn a one-time intrusion into an ongoing control point. Once an attacker can create or modify rules, they can shape what the victim sees, what investigations reveal, and which messages leave the environment. That extends access beyond the stolen password or session and makes the compromise harder to notice and remove.

A malicious rule can redirect high-value mail, suppress security notifications, or automatically move replies out of sight, which means the attacker does not need to stay online or repeatedly authenticate. In practice, that converts mailbox access into a persistent workflow for impersonation, surveillance, and data theft.

Rules are especially effective in BEC because email is both a communication channel and a record system. If an attacker can filter invoice threads, executive correspondence, or mailbox alerts, they can intercept business process decisions while also reducing the chance that the victim spots the interference quickly.

One useful way to think about the impact is that mail rules lower attacker effort after entry. Instead of returning to the inbox for every action, the intruder delegates routine abuse to automation inside the victim’s own mail system, which increases scale, consistency, and dwell time.

Why mailbox rule abuse is harder to detect than the login event

The login event is only the start. Mailbox rule abuse often blends into ordinary user activity because users legitimately create filters, forwarding rules, and inbox management logic. That makes the malicious version dangerous: it uses a normal feature to create abnormal control over message flow, often without generating the same urgency as a failed login or obvious phishing alert.

Attackers also rely on the fact that mail rules can alter both visibility and evidence. Deleting warnings, archiving MFA alerts, or forwarding selected messages to an external account can remove the signals defenders usually expect to see during a takeover. If the victim changes the password but the rule remains, the attacker may still receive valuable mail through the hidden path.

Business impact follows directly from that asymmetry. The attacker can monitor conversations, answer at the right time, and impersonate trusted parties while the real user sees less of the mailbox state than they should. That is why the rule itself, not just the compromised credential, becomes part of the blast radius.

For deeper examples of how compromised credentials and hidden access paths extend real-world compromises, see The 52 NHI breaches Report and the BEC case study TruffleNet BEC Attack , Stolen AWS Credentials.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 6 — Access Control Management Mail rule abuse extends unauthorized access and persistence after account compromise.
8 — Audit Log Management Detecting malicious rules depends on logging mailbox changes and alerting on suspicious edits.
Recommendation — Review and remove unauthorized mailbox rules and forwarding paths after any suspected compromise. Alert on mailbox rule creation, forwarding changes, and hidden delivery-path modifications.
MITRE ATT&CK T1114 — Email Collection Malicious rules are used to collect messages and maintain ongoing access to email content.
T1098 — Account Manipulation Attackers modify mailbox settings and rules to preserve access and evade detection.
Recommendation — Hunt for mailbox rules that redirect or filter targeted correspondence to attacker-controlled destinations. Investigate post-compromise changes to mailbox configuration as possible persistence activity.
NIST CSF 2.0 DE.CM — Continuous Monitoring Ongoing monitoring is needed to surface rule changes that indicate hidden persistence.
PR.AC — Access Control Management Mailbox rules turn compromised access into broader unauthorized message handling.
Recommendation — Monitor mailbox configuration changes and investigate any unexpected rule or forwarding activity. Restrict who can create forwarding and filtering rules for high-risk mailboxes.

Practitioner Guidance

What to verify: Treat any mailbox compromise as incomplete until you have checked inbox rules, forwarding settings, delegated access, and hidden delivery paths. Password reset alone is insufficient if the attacker already planted persistence in mail flow.

What to prioritise: Focus first on rules that forward externally, suppress warnings, delete messages from finance or executive correspondents, or move security-related messages out of sight. Those are the patterns most likely to preserve attacker visibility and business impact after account recovery.

What good looks like: A recovered mailbox should have a clean rule set, auditable ownership of every forwarding destination, and alerting for any post-compromise change to message handling. If you cannot explain why a rule exists, assume it deserves review.

Practitioner takeaway: The real risk is not just mailbox access, but attacker control over what the victim sees and what the business can prove. If the message path is still being shaped by the intruder, the compromise is still active even after the password changes.