Join our Newsletter — 33% off our NHI Course

What happens after an attacker gains access to a Microsoft 365 account through phishing?

After initial access, attackers often try to make the compromise durable by adding their own authentication method, then using the account for lateral movement, data theft, fraud, or resale. In Microsoft 365 environments, that can mean manipulating sign-in settings, establishing persistence, and expanding into other services. Rapid containment matters because the post-compromise phase is where damage compounds quickly.

How post-compromise activity typically unfolds in Microsoft 365

Once an attacker is inside a Microsoft 365 mailbox or identity, the next goal is usually durability. They often search for ways to keep access even if the original phished password is changed, then use the account as a trusted foothold for email abuse, internal discovery, and movement into other services. The important shift is from simple login theft to sustained account control.

That durability is commonly created by changing account settings, adding another sign-in path, or exploiting the victim’s existing trust relationships. In Microsoft 365, those trust relationships can extend into email, collaboration, file sharing, and linked SaaS applications, so the compromise can expand beyond the inbox quickly.

Attackers do this because a living account is more valuable than a one-time login. A compromised Microsoft 365 identity can make malicious mail look legitimate, help harvest more credentials, expose shared content, and support fraud or resale with far less friction than starting from scratch.

Why persistence matters more than the initial phish

The initial phishing event is usually only the entry point. What happens after that is determined by whether the attacker can preserve access long enough to operate, evade detection, and widen the blast radius. In practice, that means looking for changes that outlast password resets, not just the original suspicious message.

Common post-access behaviors include mailbox rule abuse, forwarding configuration, consent or token abuse where available, and changes to recovery or sign-in settings. These are operationally important because they can keep the account useful to an attacker even when the user stops interacting with the phishing lure.

In Microsoft 365, the account can also become a staging point for business email compromise, internal phishing, document theft, and reconnaissance against other users or connected tenants. The longer the attacker remains inside, the more likely they are to blend into normal collaboration patterns and turn one account into a broader trust problem.

How compromise spreads from one account to the rest of the environment

After access is established, attackers usually try to move from the first account to something with more reach, like shared mailboxes, delegated access, synced data, admin workflows, or downstream SaaS integrations. Even without direct privilege escalation, a single mailbox can expose enough conversation history and shared links to identify the next target.

Data theft is often the fastest outcome. Mail, attachments, OneDrive content, and Teams messages can reveal contracts, invoices, credentials, or internal approvals. If the attacker can impersonate the user convincingly, they may also be able to trigger payments, change bank details, or request sensitive action from colleagues.

For that reason, Microsoft 365 compromise should be treated as an access problem, not just an email problem. Once the attacker can read, send, or alter trusted communications, the impact can extend into fraud, extortion, impersonation, and compromise of adjacent systems that rely on the same identity.

Risk and Threat Considerations

Post-phishing compromise is risky because the attacker is now operating with a trusted identity that can create new access, hide in ordinary business activity, and survive a simple password reset. The main danger is not only theft of one mailbox, but the attacker using that mailbox to reach people, data, and workflows that still trust the compromised identity.

Failure mechanism: Attackers preserve access by modifying account recovery, adding a new sign-in path, abusing session material, or setting up email forwarding and rules that keep data flowing to them after the user changes credentials.

Impact: The compromised account can be used for lateral movement, internal phishing, data exfiltration, payment fraud, and resale, while detection becomes harder because the activity originates from a legitimate tenant identity.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK define the specific risk controls and attack patterns relevant to this topic.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-01 — Improper Offboarding Persistence after compromise resembles retained access that should be removed.
NHI-02 — Secret Leakage Phishing post-compromise often leads to exposed credentials, tokens, or mailbox-derived secrets.
NHI-05 — Overprivileged NHI A compromised account can be abused more broadly when permissions exceed business need.
Recommendation — Revoke every attacker-added access path and confirm no residual sign-in method remains. Rotate exposed secrets and invalidate any tokens tied to the compromised account. Review permissions and remove any access that would widen post-compromise blast radius.
MITRE ATT&CK T1098 — Account Manipulation Attackers commonly change account settings to persist after phishing access.
T1114 — Email Collection Compromised Microsoft 365 accounts are often used to collect mail and attachments.
T1021 — Remote Services Initial mailbox compromise is often leveraged to reach other connected services.
Recommendation — Hunt for account-setting changes that add or preserve unauthorized access. Monitor mailbox access and collection activity for unusual exfiltration patterns. Trace downstream service access from the compromised identity and block unexpected paths.

Practitioner Guidance

What to prioritise: Treat the first 24 hours as a containment window. Preserve evidence, then look for persistence changes before you focus on message cleanup, because removing the visible phishing email does not remove the attacker’s access path.

What to verify: Check whether the attacker added or altered any sign-in method, consented to any app, created forwarding or inbox rules, or established active sessions that survive password reset. Those are the signals that determine whether the compromise is still live.

Decision rule: If the account can still authenticate after a password reset, assume persistence and escalate to full account containment, token/session revocation, and downstream access review rather than treating it as a simple user reset case.

Practitioner takeaway: The key question is not “was the password stolen?”, but “what durable access did the attacker leave behind and what trusted paths can they now abuse?”