Attackers prefer email because it is the fastest path to trusted access. If a user can be tricked into revealing credentials, approving MFA prompts, or sending money, the attacker may not need to breach the network at all. Microsoft 365 also concentrates risk, so compromising one ecosystem can provide access to many organisations at once.
Why email beats the perimeter
Microsoft 365 email is attractive because it gives attackers a direct route to the place where trust already exists. A mailbox is not just a message store, it is a workflow hub for invoices, password resets, internal approvals, and one-time links. If the attacker can act through that trusted channel, they can often avoid noisy network intrusion entirely.
Email also compresses the attack surface. Instead of breaking a perimeter, an attacker can exploit human judgment, session trust, or weak authentication to inherit access that already fits the business process. That makes email the preferred starting point for phishing, business email compromise, and token or credential theft.
How Microsoft 365 changes the economics of compromise
Microsoft 365 concentrates identity, messaging, collaboration, and file access in one ecosystem. That concentration means a single successful compromise can expose mail, documents, shared links, Teams conversations, and downstream application access that relies on the same account or session. The attacker gains leverage from one foothold rather than having to move laterally through multiple network tiers.
The same centralisation also makes abuse scalable. A convincing inbox compromise can be used to pivot into suppliers, customers, and internal teams through normal business communication, which is why email compromise often looks more like trust exploitation than a classic perimeter breach. The 52 NHI Breaches Report is useful background on how stolen credentials and trusted access paths are repeatedly abused once the first trust boundary is crossed.
What attackers actually do after they get in
Once attackers have mailbox access, the objective is usually persistence or monetisation. They may create forwarding rules, search for invoices and payment requests, harvest MFA codes, reset passwords on linked services, or impersonate the user in ongoing conversations. In many cases the mailbox itself is only the entry point to a broader fraud or extortion campaign.
That is why direct network intrusion is often unnecessary. If the attacker can steal credentials, capture a session, or trick a user into approving access, they can work inside legitimate channels and blend into normal business activity. The result is lower detection pressure, higher success rates, and a wider range of downstream abuse options.
Risk and Threat Considerations
Email-first attacks are risky because they exploit the least defended part of the enterprise, the human trust layer. Once a mailbox or session is compromised, the attacker can impersonate internal communications, redirect payments, and use the account as a launch point for further access.
Failure mechanism: Weak phishing resistance, reused passwords, MFA fatigue, overbroad mailbox permissions, and trusted links between Microsoft 365 and other services allow one successful social-engineering event to become an account compromise.
Impact: The attacker can bypass network controls entirely, sustain access through legitimate sign-in paths, and expand from one account into financial fraud, data theft, and wider business compromise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Mailbox compromise often starts with stolen or tricked user credentials. |
| IA-5 — Authenticator Management | The attack path commonly depends on password theft, token abuse, or MFA weaknesses. | |
| Recommendation — Enforce strong organizational-user authentication for Microsoft 365 accounts. Rotate and protect authenticators, tokens, and recovery paths tightly. | ||
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | Email compromise frequently exposes tokens, reset links, and other secret material. |
| NHI-05 — Overprivileged NHI | Compromised accounts often have broader access than their business role needs. | |
| Recommendation — Scan and remove exposed secrets from mail, documents, and shared links. Reduce account privileges so a single mailbox compromise has limited blast radius. | ||
| MITRE ATT&CK | T1566 — Phishing | The answer centers on attackers using email to trick users into granting access. |
| T1078 — Valid Accounts | The attacker’s advantage comes from using legitimate Microsoft 365 access after compromise. | |
| Recommendation — Detect and block phishing lures that target mailbox trust and sign-in approval. Hunt for abnormal use of valid accounts instead of relying only on perimeter alerts. | ||
| CIS Controls v8 | CIS-5 — Account Management | Mailbox compromise and trusted access rely on account and permission sprawl. |
| CIS-6 — Access Control Management | The attack succeeds when users can approve or reach more than they should. | |
| Recommendation — Review and remove unnecessary accounts, delegates, and recovery paths. Apply least privilege to reduce what one compromised mailbox can reach. | ||
Practitioner Guidance
What to prioritise: Treat mailbox compromise as a business-critical access event, not just an email issue. The first questions are whether the account can send trusted mail, approve access, reset passwords, or reach sensitive collaboration data.
What to verify: Confirm phishing-resistant MFA for high-value users, review mailbox forwarding and delegate permissions, and check whether identity sessions, not just passwords, are the real control point. If an account can still act through stale sessions, the control is weaker than it looks.
Decision rule: If a Microsoft 365 account can influence money movement, privileged access, or sensitive internal approvals, investigate it as a fraud and identity incident first, and only then as an email hygiene problem.
Practitioner takeaway: The right defensive model is to reduce the trust value of any single mailbox, because attackers are choosing the path where one user mistake can deliver the access they want.
Related resources from NHI Mgmt Group
- Why do attackers often check model availability before trying to generate content?
- Who is accountable for reducing BEC risk when attackers target Microsoft 365 users?
- What happens when attackers gain access through valid credentials instead of stealing passwords directly?
- How should financial services teams strengthen email security when native Microsoft 365 controls still let targeted phishing through?