Mailbox rules that forward, redirect, mark as read, or delete messages let attackers conceal evidence while keeping access to sensitive mail flowing. That breaks visibility for defenders, delays user awareness, and can let payment fraud or credential theft continue longer. In practice, the most useful alerts focus on rule creation, external forwarding, and unusual mailbox delegation.
How mailbox rules hide business email compromise activity
Mailbox rules turn the mailbox itself into part of the attacker’s tradecraft. By automatically forwarding, moving, marking, or deleting messages, an intruder can keep receiving high-value mail while reducing the chance that the victim notices suspicious replies, alerts, or payment changes. The key issue is not only persistence, but concealment that changes how long the compromise remains useful.
That concealment matters because business email compromise is often discovered through message review, customer callbacks, or unusual inbox behavior. Once rules interfere with what the user sees, defenders lose a major source of informal detection. A mailbox can still function normally enough for ongoing fraud, even while key evidence is being filtered away from the human owner.
Mailbox rules are especially effective when they are narrow and selective. Attackers may target messages from finance, vendors, executives, or security tools, then hide only the items most likely to trigger suspicion. That makes the compromise harder to spot than a simple inbox takeover, because the mailbox keeps appearing active while the attacker quietly shapes what reaches the victim.
What business and security signals break first
The first thing to break is visibility. Security teams and users often rely on message arrival, reply chains, and out-of-band verification to notice fraud, but rule-based filtering removes those cues. If alerts are generated from inbox activity alone, the attacker may preserve access while making the mailbox look less abnormal than it really is.
Mailbox rules also break trust in the mailbox as a record of business intent. Finance approvals, vendor instructions, and payment changes may no longer be visible in the mailbox history that employees use to confirm legitimacy. That creates a mismatch between what the business thinks was communicated and what the compromised mailbox actually delivered, which is why these cases can lead to payment diversion or credential capture continuing longer than expected.
A useful way to think about the failure is that rules do not just hide evidence, they alter the control plane around email. If the defender depends on the user to notice odd messages, but the user no longer sees those messages, the compromise can survive until someone reviews rule configuration, sign-in activity, or external forwarding paths directly.
Which mailbox-rule patterns deserve the most scrutiny
Rules that forward mail outside the tenant are high priority because they extend the attacker’s reach beyond the compromised account. Rules that delete, archive, or move messages out of the inbox are also important because they reduce user awareness and shrink the evidence available during triage. Mark-as-read behavior is subtler, but it can still suppress the visual cues that normally prompt a user to investigate.
Unusual mailbox delegation is another signal worth treating as more than housekeeping noise, because it can indicate that the attacker is trying to preserve access under a second identity or route visibility through another account. The practical question is not whether a rule exists, but whether it changes who can see the message, where it goes, and whether the original owner can still notice the activity.
For readers mapping the behavior to broader attack patterns, the relevant control gap is the same one that appears in many access-abuse scenarios: ordinary functionality is being used as a covert channel. That is why alerting on rule creation, external forwarding, and delegated access usually gives defenders earlier warning than waiting for a reported fraud event.
Risk and Threat Considerations
Mailbox rules create a stealth layer that lets an attacker keep using the account while reducing the chance of human detection. The danger is not only exfiltration, but the extended time window for payment diversion, credential harvesting, and internal impersonation while the inbox still appears to operate normally.
Failure mechanism: The attacker changes mail handling so the victim or defender no longer sees the messages, replies, or alerts that would normally expose the compromise. That can suppress notice of suspicious forwarding, hide security notifications, and keep business conversations flowing to the attacker.
Impact: Detection is delayed, evidence is harder to reconstruct, and the compromise can continue long enough to increase fraud losses or widen the blast radius across vendors, finance workflows, and adjacent accounts.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1114 — Email Collection | Mailbox rules conceal and route mail for attacker access and persistence. |
| T1110 — Brute Force | BEC often follows account compromise, which enables rule abuse and concealment. | |
| Recommendation — Map mailbox-rule abuse to email collection activity and hunt for hidden forwarding or filtering. Correlate mailbox-rule changes with account compromise investigations and credential misuse. | ||
| CIS Controls v8 | CIS-5 — Account Management | Mailbox rules expose account-control abuse that account governance and review should catch. |
| CIS-8 — Audit Log Management | Detecting hidden mail activity depends on mailbox and rule-change audit visibility. | |
| Recommendation — Review privileged and user account changes that can alter mail handling or delegation. Retain and review mailbox audit logs for rule creation, forwarding, and delegation events. | ||
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Mailbox-rule abuse often succeeds because the compromised account can act with excessive mail access. |
| Recommendation — Reduce excessive mailbox permissions and constrain which identities can modify mail routing. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Mailbox-rule abuse is an account-governance problem tied to unauthorized mailbox behavior. |
| AU-6 — Audit Record Review, Analysis, and Reporting | Rule abuse is best detected through review of mailbox and audit events. | |
| Recommendation — Monitor and revoke unauthorized mailbox capabilities that enable hidden forwarding or deletion. Review mailbox audit records for rule creation, forwarding, and delegation anomalies. | ||
Practitioner Guidance
What to verify: Treat any new forwarding, deletion, or read-state rule as a security event until proven otherwise. Confirm who created it, whether it points outside the tenant, and whether it aligns with a documented business process rather than an ad hoc mailbox change.
Decision rule: If the mailbox can send or receive sensitive business mail, prioritize rule review and forwarding-path inspection before you rely on user-reported symptoms. In these cases, the absence of obvious mailbox disruption is not reassurance; it can be the attacker’s desired outcome.
Practitioner takeaway: The operational mistake is assuming a healthy-looking inbox is a safe inbox, because mailbox rules can preserve access while stripping away the visibility needed to catch BEC early.
Related resources from NHI Mgmt Group
- How should organisations reduce business email compromise risk when attackers use generative AI?
- How should organisations defend against business email compromise when attackers use real conversations?
- How should organisations protect Microsoft 365 users against business email compromise across the full attack chain?
- What happens when attackers use inbox rules after they compromise an email account?