Join our Newsletter — 33% off our NHI Course

What happens when tax-themed phishing reaches internal accounts or trusted business processes?

Once attackers compromise an account, the campaign can shift from inbound phishing to internal fraud. They may send believable follow-up messages, request payroll changes, redirect payments, or spread malicious links from a trusted mailbox. That is why defenders need controls for both external and internal email, plus monitoring for anomalous account behavior and unusual payment requests.

How a tax-phishing compromise turns into internal fraud

Once an attacker gets into an internal mailbox or business workflow, the campaign stops looking like simple phishing and starts behaving like business email compromise. The account can be used to continue the conversation from a trusted position, insert itself into approval chains, or push changes that appear routine because they arrive from a familiar sender and context.

That shift matters because the compromise no longer depends on whether a message looks suspicious at first glance. It depends on whether the attacker can exploit trust already built into payroll, payments, finance, or employee support processes.

What trusted account access lets the attacker do next

A compromised internal account can be used to send believable follow-up requests, such as payroll updates, invoice redirection, gift-card or payment changes, or requests to review a document through a malicious link. If the mailbox already participates in a thread, the attacker may only need to alter a small detail to make the request feel consistent with normal operations.

The same access can also be used to broaden the compromise. A trusted mailbox can deliver malware or credential prompts to coworkers, vendors, or partners because recipients are more likely to open content that appears to come from a known business contact. In practice, the mailbox becomes both the fraud channel and the delivery mechanism.

Why internal abuse is harder to spot than the original phishing email

Inbound phishing often stands out because it comes from outside the organisation and uses obvious lure patterns. Internal abuse is more difficult because the message source, thread history, and tone may all look legitimate. Even when the content is malicious, it may fit normal business language closely enough to bypass cursory review.

Defenders therefore need to watch for behavior rather than only message origin. Unusual login times, forwarding changes, new inbox rules, abnormal payment requests, and sudden pressure to bypass standard approval steps are all stronger indicators than the subject line alone. Controls that only filter external mail miss the more damaging phase of the attack.

Risk and Threat Considerations

Once a tax-themed phish lands inside a trusted account, the main risk is business process abuse, not just account compromise. The attacker can exploit existing authority, timing, and familiarity to redirect funds or manipulate internal approvals before anyone questions the request.

Failure mechanism: The attacker inherits trust from a real mailbox or workflow, then uses that trust to issue requests that look consistent with ordinary finance or payroll activity.

Impact: Organisations can suffer payment diversion, payroll fraud, secondary phishing, and broader compromise of internal communication channels, especially when approvals are informal or exceptions are easy to obtain.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-6 — Least Privilege Limits how much damage a compromised mailbox or workflow can cause.
AU-6 — Audit Review, Analysis, and Reporting Supports detection of suspicious account behavior and payment anomalies.
IA-5 — Authenticator Management Covers the credentials that let attackers turn a phish into internal account abuse.
Recommendation — Restrict mailbox-linked permissions to the minimum needed for the role. Review logs for unusual mailbox actions, forwarding, and approval changes. Rotate and protect credentials that authenticate access to internal business processes.
OWASP Non-Human Identity Top 10 NHI-02 — Secret Leakage Compromised internal accounts often expose tokens or credentials used for follow-on abuse.
NHI-05 — Overprivileged NHI Overbroad non-human or service access can amplify payment and mailbox compromise.
Recommendation — Detect and remove exposed secrets that enable trusted-account abuse. Remove excess privileges that let compromised accounts reach finance workflows.
MITRE ATT&CK T1566 — Phishing The question starts with phishing that becomes internal compromise and fraud.
T1078 — Valid Accounts Attackers exploit compromised accounts to act as legitimate users inside business processes.
Recommendation — Map phishing incidents to follow-on abuse of trusted internal access. Hunt for misuse of valid accounts after suspicious mailbox activity.

Practitioner Guidance

What to verify: Treat any change to payment destination, payroll details, or vendor banking instructions as a high-risk event until it is confirmed through a separate channel. If the request arrives from an account that normally handles money, that is not sufficient proof of legitimacy.

What to prioritise: Monitor for mailbox rule changes, unexpected forwarding, impossible travel, unusual device sign-ins, and messages that steer employees away from standard approval paths. Those signals often appear before the financial loss becomes visible.

Decision rule: If the compromised account can influence payments, payroll, or procurement, respond as a fraud and access incident together, not as a simple email cleanup. The practical question is how much authority the mailbox had, and what it could still trigger before containment.

Practitioner takeaway: The critical failure is not the phishing email itself, but the moment a trusted account is used to make an ordinary business process lie on behalf of the attacker.