Email is attractive because it is universal, trusted, and hard to fully police at scale. Attackers exploit spoofed domains, malicious attachments, weak passwords, and reused credentials to bypass human judgement. Because internal communication still depends heavily on email, one compromised mailbox can expose data, enable malware delivery, and support broader fraud or lateral abuse across the organisation.
Why email keeps working for attackers
Email stays effective because it is the default trust fabric of most organisations. It is used for login resets, vendor coordination, approvals, document exchange, and urgent business communication, so a message that looks routine can slip past both people and tools. Attackers do not need to defeat email everywhere, only at the point where one believable message gets attention.
The channel also scales the attacker’s economics. A single campaign can reach many recipients, but the defender has to validate sender identity, content intent, attachment safety, and account reputation continuously. That burden gets worse when staff, partners, and automated systems all rely on the same mailbox ecosystem for day-to-day work.
Email is also exposed to weak identity hygiene and protocol legacy. Spoofing, domain lookalikes, reply-chain abuse, and stolen credentials all make the inbox a practical entry path, especially when organisations still tolerate long-lived passwords, inconsistent MFA adoption, or broad mailbox permissions.
How a mailbox compromise turns into broader intrusion
Once an attacker gets mailbox access, the impact often goes far beyond reading messages. Mailboxes are rich in reset links, invoices, internal attachments, contact lists, and thread history, which lets an intruder impersonate a trusted user, redirect payments, harvest secrets, or seed malicious files into ongoing conversations.
That is why business email compromise is so persistent. The inbox is not just a communication tool, it is a workflow hub. If a mailbox also bridges to cloud apps, ticketing, HR, finance, or shared drives, then compromise can become a launch point for fraud, lateral abuse, and further credential collection. NHIMG’s 52 NHI breaches report and the related 52 NHI Breaches Analysis show how stolen credentials and lateral movement repeatedly turn one access foothold into a wider incident.
Compromise also benefits from the fact that email is conversational and stateful. Attackers can wait, reply, forward, and impersonate over time rather than trigger one obvious malicious event. That makes email particularly useful for phishing, invoice fraud, malware delivery, and recovery-account takeover after the first credential is stolen.
Risk and Threat Considerations
As a threat surface, email concentrates many of the organisation’s weakest assumptions in one place: users must recognise deception, systems must detect abuse, and identities must resist credential theft. That combination makes the mailbox a high-value target for initial access, follow-on fraud, and persistence.
Failure mechanism: Attackers exploit human trust, domain impersonation, stolen credentials, and inbox rules or forwarding abuse to hide activity and extend access after the first message lands.
Impact: A single compromised mailbox can expose sensitive data, enable internal impersonation, support malware delivery, and create a pivot into finance, cloud services, or other connected systems.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 6 — Access Control Management | Email abuse commonly starts with stolen or reused credentials and overbroad access. |
| 9 — Email and Web Browser Protections | The subject centers on email as an entry point for phishing and malicious content delivery. | |
| 8 — Audit Log Management | Mailbox compromise is often detected through suspicious sign-ins, forwarding rules, and abnormal access. | |
| Recommendation — Harden account access, remove excess mailbox permissions, and enforce strong authentication for email accounts. Deploy anti-phishing and email security controls that reduce malicious message delivery and user exposure. Log and review mailbox, authentication, and forwarding activity to spot account takeover early. | ||
| NIST CSF 2.0 | PR.AC — Access Control | Protecting email entry paths depends on authenticating users and constraining mailbox access. |
| DE.CM — Continuous Monitoring | Email abuse is often visible in anomalous login, forwarding, and message patterns. | |
| Recommendation — Enforce least privilege and strong authentication on email and related access paths. Monitor email activity for indicators of compromise and abnormal account behavior. | ||
| MITRE ATT&CK | T1566 — Phishing | Phishing is a primary email-delivered entry path for initial access and credential harvesting. |
| T1078 — Valid Accounts | Stolen email credentials let attackers use legitimate access rather than noisy exploits. | |
| Recommendation — Detect and disrupt phishing lures, impersonation, and message-based initial access attempts. Hunt for misuse of valid accounts and rapidly revoke suspicious email sessions. | ||
Practitioner Guidance
What to prioritise: Treat the mailbox as an identity boundary, not only a communication channel. The most useful controls are the ones that reduce the value of a stolen inbox: phishing-resistant MFA where feasible, conditional access, suspicious forwarding detection, and rapid session revocation.
What to verify: Confirm that mailbox recovery paths, delegation, shared mailbox permissions, and admin consent flows are actually controlled. If those paths are weak, attackers often bypass the inbox itself and use the surrounding trust relationships to persist.
What practitioners underestimate: Email security failures are often identity failures first and content-filter failures second. If compromised credentials, over-permissioned mailboxes, or weak recovery processes are not addressed, content inspection alone will not materially reduce exposure.
Practitioner takeaway: The right question is not whether email can be made perfectly safe, but whether a compromised mailbox can be prevented from becoming a trusted internal platform for impersonation and escalation.
Related resources from NHI Mgmt Group
- Why do unpatched systems remain such a common ransomware entry point?
- Why do exposed services remain such an effective entry point for attackers?
- Why do phishing emails remain such a high-risk entry point for ransomware?
- Why do endpoints remain such a high-risk entry point in hybrid work environments?