Join our Newsletter — 33% off our NHI Course

Why do inbox rules and external forwarding make Microsoft 365 BEC attacks harder to detect?

They create a layer of legitimate-looking activity inside the victim’s own mailbox, so the attacker does not need to break email delivery outright. Messages can be hidden, auto-deleted, or sent outside the organisation without obvious disruption. That preserves the fraud path while reducing the chance that users notice suspicious replies, invoices, or payment requests.

How inbox rules change the attacker’s visibility footprint

Inbox rules make a BEC campaign look like normal mailbox behaviour instead of a crude delivery failure. Once an attacker can create, edit, or abuse rules, they can divert messages, suppress alerts, or auto-process threads in a way that blends into ordinary user activity. That is why mailbox review often has to look at rule creation, rule timing, and sender patterns together rather than only message content.

For defenders, the key issue is that the mailbox itself becomes the concealment layer. The attacker does not need to block email at the perimeter if they can change what the victim sees after delivery, which means the operational signal shifts from obvious spam-like abuse to subtle account behaviour.

Why external forwarding is especially useful to BEC operators

External forwarding extends the same hiding logic beyond the mailbox. By sending selected mail outside the tenant, an attacker can observe conversations, harvest invoices or approval threads, and move replies away from internal monitoring points. That helps preserve the fraud path even when the inbox continues to function normally for the victim.

This matters because BEC often depends on timing, context, and trusted conversation history. Forwarding lets the attacker stay inside that workflow without necessarily triggering the kind of service interruption that would make the compromise obvious to users or help desk staff.

Forwarding also raises the stakes of account compromise because it can expose sensitive correspondence, payment instructions, and recovery messages. Once the attacker can mirror or reroute mail, the mailbox is no longer just a communication channel, it becomes a surveillance and control point.

What makes detection harder in practice

Detection is harder because these techniques preserve legitimacy at the protocol and user-interface level. The victim still receives mail, the tenant may still send mail, and the organisation may only see a rule object or forwarding configuration change rather than a blatant malicious attachment or blocked login.

That is why BEC investigations usually need to correlate mailbox rules, forwarding changes, sign-in anomalies, and unusual message handling. A single rule can be the difference between visible fraud and a quiet compromise that continues long enough for payment diversion or impersonation to succeed.

Mail flow controls and audit logs matter here because the attacker’s goal is often persistence, not noise. If the mailbox keeps working, many traditional indicators stay muted until someone compares expected correspondence with what the user actually sees, or until a recipient notices an instruction change that no one internally approved.

Risk and Threat Considerations

Inbox rules and forwarding create a low-friction persistence path after initial compromise. The attacker can keep reading, hiding, or rerouting mail while the account still appears functional, which delays discovery and extends the window for invoice fraud, credential harvesting, and impersonation.

Failure mechanism: The compromise succeeds when mailbox-level controls are trusted as ordinary user activity, so rule creation or forwarding changes are not treated as high-signal security events.

Impact: The attacker gains a durable interception channel that can support covert monitoring, message suppression, and payment redirection with less user-visible disruption.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1114 — Email Collection Inbox rules and forwarding enable covert mailbox monitoring and mail collection.
T1098 — Account Manipulation Rule creation and forwarding changes modify account settings to persist and evade detection.
Recommendation — Hunt for suspicious mailbox collection and forwarding activity after account compromise. Alert on mailbox rule changes and forwarding configuration tampering.
CIS Controls v8 CIS-6 — Access Control Management Mailbox forwarding and rule abuse are access-path changes that need review and removal.
Recommendation — Review and revoke unauthorized mailbox access paths and forwarding settings.
NIST SP 800-53 Rev 5 AU-6 — Audit Review, Analysis, and Reporting Mailbox rules and forwarding are detectable only when logs are reviewed and correlated.
AC-6 — Least Privilege Limiting who can create rules or external forwarding reduces BEC concealment paths.
Recommendation — Review mailbox audit events for forwarding and rule-creation anomalies. Restrict rule and forwarding privileges to the minimum required.

Practitioner Guidance

What to verify: Treat new forwarding destinations, hidden inbox rules, and sudden changes to rule ownership as security-relevant events, especially when they occur shortly after a sign-in from a new device, location, or IP range. If the mailbox can still send and receive normally, do not assume the account is clean.

Decision rule: If a rule or forwarding change can expose internal mail externally or suppress finance-related correspondence, prioritise containment and mailbox review before relying on user-reported symptoms. The absence of delivery failure is not reassuring in a BEC case.

Practitioner takeaway: The important judgement is to treat mailbox behaviour as part of the attack surface, because BEC often wins by preserving normal email flow while quietly changing who sees, forwards, or loses the message.