Join our Newsletter — 33% off our NHI Course

What are the signs that an email compromise has been active for months rather than days?

Long dwell time usually shows up as delayed discovery, activity in a narrow set of high value accounts, and evidence that the attacker had persistent read access rather than noisy destructive behaviour. Other indicators include retrospective mailbox scans, account disablement after discovery, and the need to review years of email activity. The pattern points to stealth, access maintenance, and weak monitoring rather than a short lived intrusion.

What long dwell time looks like in a mailbox compromise

An email compromise that has been active for months usually leaves a pattern of quiet persistence rather than obvious disruption. Look for a narrow footprint focused on one or a few high-value accounts, repeated access at odd times, mailbox searches that suggest reconnaissance, and signs that the attacker preferred observation and collection over immediate fraud or deletion.

That pattern matters because long dwell time often means the attacker was learning the environment, maintaining access, and waiting for the best opportunity. If discovery is delayed, you may need to review a much larger slice of mail history than you would for a short-lived intrusion, including sent items, forwarding rules, delegated access, and recovery actions taken after the compromise was found.

Teams investigating this pattern should treat the mailbox as a history of attacker behaviour, not just a point-in-time incident. The 52 NHI breaches Report is useful here because it shows how compromise often persists through quiet access and credential abuse rather than noisy disruption. For a broader operational view of long-lived secret and account misuse, Ultimate Guide to NHIs, What are Non-Human Identities provides the lifecycle and visibility context that helps explain why dwell time goes unnoticed.

  • Delayed discovery after the initial compromise.
  • Evidence of repeated read access, search activity, or selective message access.
  • Minimal destructive behaviour, with the attacker trying to stay hidden.
  • Post-discovery cleanup such as account disablement, rule removal, or token revocation.

Why months-long compromise is usually a stealth problem, not a noisy breach

When a mailbox compromise has lasted for months, the main clue is often what is missing: fewer obvious user complaints, fewer failed logins, and fewer obvious disruptions than you would expect from a short, opportunistic intrusion. The attacker’s goal is usually to preserve access, collect context, and avoid drawing attention while they identify the messages, contacts, and workflows that matter most.

That makes retrospective review especially important. A long-running compromise can include mailbox rule changes, hidden forwarding paths, OAuth consent abuse, sent-message tampering, and selective access to a small set of conversations that carry financial, legal, or operational value. Those actions are easier to miss when monitoring focuses only on obvious login failures or destructive events.

External guidance that tracks active exploitation and credential abuse helps frame why these cases can stay hidden. CISA Known Exploited Vulnerabilities Catalog is a useful prioritisation reference when the compromise chain began with a known weakness, while NIST Cybersecurity Framework 2.0 provides the broader detect and respond lens for monitoring gaps, incident scoping, and recovery.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 DE.AE — Anomalies and Events are Detected Mailbox compromise dwell time depends on detecting unusual access patterns and quiet persistence.
DE.CM — Security Continuous Monitoring Long-running email compromise is exposed by continuous review of access, rules, and mail activity.
RS.AN — Incident Analysis Months-long compromise requires retrospective scoping across a long activity window.
Recommendation — Tune monitoring to flag low-noise mailbox access anomalies and delayed compromise signals. Continuously monitor mailbox access, forwarding rules, and token-driven activity for persistence. Scope incidents across the full suspected dwell period before closing the case.
CIS Controls v8 8 — Audit Log Management Audit trails are needed to reconstruct quiet mailbox access and rule changes over time.
6 — Access Control Management Persistent compromise often survives through unmanaged mailbox permissions and forwarding paths.
5 — Account Management Long dwell time often involves compromised accounts that remain active long after initial access.
Recommendation — Centralize and retain mailbox and identity audit logs long enough to support dwell-time analysis. Review and remove stale mailbox access paths, delegated rights, and forwarding controls. Disable, recover, or reset compromised accounts immediately and verify no alternate access remains.
MITRE ATT&CK T1114 — Email Collection Selective mailbox reading and retrospective scans are core indicators of prolonged email compromise.
T1098 — Account Manipulation Mailbox compromise often persists through rule, delegate, or settings changes that preserve access.
Recommendation — Hunt for mailbox collection activity, selective reads, and suspicious search patterns. Inspect for account or mailbox manipulation that maintains attacker access after initial entry.

Practitioner Guidance

What to verify: Start with mailbox access patterns, forwarding and delegation changes, recent token or session revocation, and whether the account shows selective read activity rather than broad sending or deletion. If the pattern is months-long, expand the review window before assuming the attacker left early.

What to prioritise: Focus first on high-value accounts and shared mailboxes because long dwell time is often concentrated there. A small number of accounts can represent most of the exposure if the attacker had persistent read access to executive, finance, legal, or administrative inboxes.

Common mistake: Treating “no ransom, no wipe, no obvious spam” as low severity. Stealth compromises often matter more because they enable surveillance, impersonation, invoice fraud, or later-stage intrusion without obvious breakage.

Practitioner takeaway: The longer the compromise lasted, the less useful a symptom-based investigation becomes, so the right response is a timeline-led review that assumes the attacker was optimizing for visibility, not noise.