Common signs include unexpected inbox or forwarding rules, deleted security alerts, missing responses to phishing warnings, and internal messages that suddenly contain unusual urgency or authentication links. A compromised account may also send credible-looking emails to colleagues, partners, or customers. Those behaviours indicate the attacker is using the mailbox to suppress detection and spread the campaign laterally.
Mailbox signals that show the attacker is using the account as a launchpad
The clearest indicator is a shift from ordinary account abuse to message control. Look for inbox rules, auto-forwarding, or deletion behaviour that hides warnings and channels replies away from the real user. A compromised mailbox used for phishing often also shows changes in tone and targeting, with messages that sound credible to insiders because they come from a trusted internal sender.
Unexpected mailbox rules are especially important because they let the attacker quietly suppress evidence after the first compromise. If security alerts disappear, warning notifications are no longer reaching the user, or sent items contain messages the owner does not recognise, the account is no longer just compromised, it is being operationalised to sustain the campaign.
Compromised email accounts frequently become a staging point for lateral spread because recipients trust the sender and are more likely to click links, approve requests, or reply with credentials. That makes the mailbox both an abuse channel and a persistence mechanism: the attacker can keep using it until rotation, reset, or containment breaks the trust path.
How phishing launchpad behaviour differs from ordinary account compromise
Ordinary account compromise may stop at login or inbox snooping. A phishing launchpad goes further by turning the mailbox into a delivery system. That is why unusual urgency, requests to bypass normal process, and messages that embed authentication links deserve attention even when they look polished or contextually correct.
A useful distinction is whether the account is being used to read information or to influence other people. When the attacker sends credible-looking email to colleagues, partners, or customers, they are exploiting the mailbox’s trust relationship, not just the user’s data. The behavioural pattern often includes selective targeting, reply-thread abuse, and follow-on messages that mimic normal business workflow.
This is also where detection gets harder. Because the messages originate from a legitimate account, spam filters and recipient suspicion may be weaker than for external phishing. If the attack is successful, the mailbox can become a repeatable delivery node that survives initial password resets unless rules, tokens, sessions, and forwarding paths are all reviewed.
Risk and Threat Considerations
A compromised mailbox used as a phishing launchpad creates two separate dangers: it suppresses the victim’s visibility into the breach and it weaponises a trusted identity against the organisation’s own people and partners. The attacker can use that trust to harvest credentials, extend access, and create downstream fraud or business email compromise.
Failure mechanism: Mailbox rules, forwarding, session persistence, and reply-thread abuse let the attacker hide alerts and send convincing messages from a trusted address. Because the account appears legitimate, the campaign can evade simple filtering and continue until the underlying access path is removed.
Impact: The compromised account can amplify a single intrusion into wider phishing, credential theft, and internal spread, with potential exposure to customer data, financial fraud, and reputational damage.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Secrets and Credential Management | Phishing launchpads often rely on stolen mailbox tokens or secrets. |
| NHI-04 — Access Governance and Least Privilege | Compromised mailboxes spread abuse when access and delegation are broader than needed. | |
| Recommendation — Rotate exposed mailbox secrets and revoke any lingering tokens or app access immediately. Remove unnecessary mailbox delegation and restrict high-risk forwarding paths. | ||
| CIS Controls v8 | 6.3 — Require MFA for Access to Administrative and Remote Access Services | Phishing launchpads often persist by abusing weak or stolen authentication paths. |
| 8.2 — Collect Audit Logs | Mailbox rule changes, forwarding, and message abuse need auditable traces. | |
| Recommendation — Enforce phishing-resistant authentication for email access and recovery actions. Retain mailbox and identity logs to reconstruct rule changes and outbound abuse. | ||
| MITRE ATT&CK | T1114.003 — Email Collection: Email Forwarding Rule | Unexpected forwarding rules are a classic mailbox persistence and abuse mechanism. |
| T1566 — Phishing | The compromised account is being used to deliver phishing messages to trusted targets. | |
| Recommendation — Hunt for unauthorized forwarding rules and remove them from compromised mailboxes. Treat outbound trusted-sender phishing as an active adversary technique and contain it fast. | ||
| NIST CSF 2.0 | DE.CM-1 — Monitoring for Anomalies and Events | Deleted alerts, unusual urgency, and abnormal outbound mail are detection signals. |
| Recommendation — Monitor identity and email telemetry for anomalous sending and suppression behaviour. | ||
Practitioner Guidance
What to verify: Check inbox rules, delegated access, forwarding destinations, sent items, and any recent changes to recovery settings before you assume the account is clean. Also verify whether security notifications, password-reset notices, or MFA prompts were diverted or deleted, because that often explains why the user did not report the compromise earlier.
What to prioritise: If the mailbox has already sent messages to other recipients, treat it as an active phishing source, not just an identity reset case. Containment should focus on stopping outbound abuse and revoking persistence paths first, then on reviewing who received the messages and whether any follow-up credential theft or fraud occurred.
Practitioner takeaway: The key question is not only whether the account was compromised, but whether it has been converted into a trusted delivery mechanism that can keep spreading the attack after the first sign-in is cut off.
Related resources from NHI Mgmt Group
- What happens when attackers use inbox rules after they compromise an email account?
- What are the signs that a phishing attack is moving beyond email into account takeover or post-compromise activity?
- What are the signs that an email account may have malicious inbox rules?
- What are the signs that an account takeover attack is using a phishing proxy instead of a simple stolen password?