Common signs include a password that suddenly stops working, unfamiliar sent messages, odd replies that contacts say they received, and suspicious IP addresses in the account log. These signals matter because email access often becomes the pivot point for broader fraud. If any appear, reset the password immediately and then change passwords on other linked accounts.
How to tell the account is still being used, not just that access was lost
The clearest pattern is active, ongoing behaviour that the real owner did not cause. That includes new sent mail, unexpected replies, password resets the user did not initiate, and login activity from unfamiliar places or devices. When the attacker keeps using the mailbox, the account stops behaving like a passive compromise and starts looking like a live control point for fraud, impersonation, and account recovery abuse.
A useful distinction is between a one-time lockout and a persistent takeover. If the mailbox still sends messages, forwards mail, or changes settings after the password change, assume the attacker has another path in, such as a stolen session, a forwarding rule, a synced device, or access to a recovery channel.
One practical check is whether the mailbox is acting on its own. Audit sent items, deleted items, forwarding rules, inbox rules, recovery addresses, and any security alerts from the provider. If the attacker is still present, the signs usually cluster rather than appear in isolation.
Mail activity that usually reveals active attacker use
Unexpected outbound mail is one of the strongest signals. This can include messages the user does not remember sending, replies to old conversations with strange wording, or short bursts of mail designed to scam contacts. Contacts may also report odd requests for money, credentials, gift cards, or urgent invoice changes because the attacker is trying to exploit trust already built around the account.
Mailbox rule changes are another common clue. Attackers often create forwarding rules, automatic deletion rules, or filtering rules that hide warnings and replies. If security alerts are arriving but disappearing from the inbox, or if messages are landing in archives or trash without explanation, the account may still be under active control.
Changed settings matter as much as changed messages. A compromised mailbox can be quietly repurposed to forward all mail elsewhere, reset passwords on other services, or capture verification codes. That is why an attacker who remains inside often leaves a mix of visible and hidden signs, not just obvious spam.
What evidence suggests the attacker still has a foothold
Login history is useful when it is consistent with the compromise story. Suspicious IP addresses, unfamiliar geographies, new devices, or repeated reauthentication prompts can show that the account is being accessed from outside the legitimate user’s normal pattern. If the provider shows successful logins after the password was changed, the attacker likely still has a valid session, token, or another credentialed route in.
Other warning signs include password reset emails that the user did not request, MFA prompts the user cannot explain, and login notifications that appear shortly after the legitimate owner signs out. Those signals point to a living compromise rather than a stale password leak.
When the attacker is still active, the account may also be used as a bridge to other services. That is why a mailbox compromise often becomes a broader compromise, especially if the email address is the recovery method for banking, cloud, or work accounts.
Risk and Threat Considerations
An email account that remains under attacker control is not just a privacy problem. It can be used to reset other passwords, intercept sensitive messages, impersonate the owner, and maintain persistence through forwarding rules, stolen sessions, or compromised recovery channels. Once the attacker can read and send mail, the account becomes a trusted launch point for fraud and lateral compromise.
Failure mechanism: The attacker keeps access through a retained session, a recovery path, a hidden forwarding rule, or another credentialed route even after the owner notices the breach.
Impact: The mailbox can be used to impersonate the victim, hijack password resets, exfiltrate messages, and extend the compromise to connected accounts and contacts.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8, NIST SP 800-53 Rev 5 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Account compromise signs depend on account control and unauthorized access paths. |
| Recommendation — Review account access and revoke any unauthorized or stale mailbox access immediately. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Review, Analysis, and Reporting | Mailbox logs and sign-in history are the key evidence for active attacker use. |
| IA-5 — Authenticator Management | Recovery and password rotation are central once an email account is suspected compromised. | |
| Recommendation — Analyze sign-in and mail activity logs for anomalous access and persistence indicators. Rotate compromised authenticators and invalidate lingering sessions or tokens. | ||
| OWASP ASVS | V16 — Security Logging and Error Handling | The answer relies on account logs and alerting to spot ongoing abuse. |
| Recommendation — Verify logging and alerting capture suspicious mailbox activity and login events. | ||
| MITRE ATT&CK | T1114 — Email Collection | Attackers commonly monitor or manipulate mailboxes for persistence and fraud. |
| Recommendation — Map observed mailbox abuse to email collection and investigate for follow-on access. | ||
Practitioner Guidance
What to verify: Confirm whether the attacker can still send mail, forward mail, or log in after a password change. If any of those remain true, treat the account as still live-compromised rather than partially recovered.
What to prioritise: Revoke active sessions, remove suspicious forwarding and recovery settings, rotate the password, and secure the recovery email and phone number before trusting the mailbox again. If the provider supports it, review sign-in history and device list for residual access.
Practitioner takeaway: The key judgement is whether the mailbox is still behaving like an active control point. If it is, password reset alone is not enough until you have closed the attacker’s alternate access path.