A sudden spike in messages from one account can indicate that an attacker has taken over a mailbox and is using it to spread phishing, fraud, or malware inside the organisation and beyond it. Internal burst detection matters because compromised accounts can move laterally with trusted sender reputations, making abuse look ordinary unless frequency and destination patterns are monitored closely.
Why a burst of internal mail is a strong compromise signal
A sudden rise in messages from one mailbox is rarely just “more activity.” It often reflects an attacker using a trusted account to send phishing, fraud, or malicious links from inside the organisation, where the messages are more likely to pass filters and be opened by colleagues.
That pattern matters because the sender already has valid access, so the abuse blends into normal business traffic. Monitoring message volume alone is not enough; the important question is whether the spike is paired with unusual recipients, timing, or message themes.
What makes the activity look ordinary at first
Compromised mailboxes are effective because they inherit the account’s reputation, contact graph, and history. Recipients see a familiar name, and security controls may see a routine internal sender unless the mailbox starts contacting many new people, sending at unusual hours, or forwarding to external domains.
Internal burst detection is therefore a behavioural control, not a content filter. It looks for changes in sending cadence and destination patterns, especially when the account suddenly becomes active in ways that do not match the user’s normal working rhythm. That is often the earliest clue that the mailbox is being abused rather than merely used more often.
What defenders should inspect when a burst is detected
Once a spike appears, the next step is to determine whether it is a business event, automation, or abuse. Review the account’s recent login source, mailbox rules, forwarding settings, sent-item timing, and whether the messages were targeted broadly or sent to a small set of high-value recipients.
Useful triage also checks for signs of credential theft or session hijack, because a mailbox can be abused without obvious password changes. If the account is authenticating from a new location, sending from unfamiliar devices, or creating rules that hide replies and alerts, treat the event as likely compromise and move quickly to containment.
Risk and Threat Considerations
A burst of internal email activity is risky because it can turn one compromised account into a highly trusted delivery channel for phishing, invoice fraud, malware, or follow-on access. The threat is not just volume, but the way valid internal trust lowers suspicion and increases the chance that the campaign spreads.
Failure mechanism: An attacker uses the compromised mailbox to imitate normal collaboration while sending at scale, creating misleading trust signals and bypassing user caution.
Impact: The account can be used to reach many internal and external targets quickly, increasing the chance of lateral spread, data exposure, financial fraud, and wider organisational compromise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1114 — Email Collection | Mailbox abuse and message burst activity support email-based compromise and follow-on abuse. |
| T1078 — Valid Accounts | A compromised mailbox is an abused valid account used through legitimate access. | |
| Recommendation — Correlate abnormal mail bursts with credential access and lateral movement techniques in your detections. Hunt for anomalous use of valid accounts when sender reputation suddenly changes. | ||
| CIS Controls v8 | CIS-8 — Audit Log Management | Burst detection depends on visibility into sent mail, logins, and mailbox-rule changes. |
| CIS-6 — Access Control Management | Compromised mail activity is enabled by excessive or uncontrolled account access. | |
| Recommendation — Centralise mail and authentication logs so abnormal sending patterns can be investigated quickly. Remove unnecessary mailbox access paths and disable stale accounts that could be abused. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Review, Analysis, and Reporting | Investigating bursts requires reviewing message and authentication activity for anomalies. |
| IA-5 — Authenticator Management | Compromised mailboxes often follow credential or session abuse that auth controls must limit. | |
| AC-6 — Least Privilege | Reducing mailbox and forwarding privilege lowers the blast radius of takeover. | |
| Recommendation — Review mail and login audit records for unusual volume, destinations, and timing. Rotate or revoke exposed authenticators quickly when mailbox compromise is suspected. Limit mailbox forwarding and delegation rights to the minimum required for the role. | ||
| NIST Zero Trust (SP 800-207) | SA-15 — System Access and Privilege | A compromised account demonstrates why trust in account state must be continuously revalidated. |
| Recommendation — Continuously verify account context before allowing high-risk message or forwarding actions. | ||
Practitioner Guidance
What to prioritise: Treat the burst as a triage trigger, then check whether the account is also showing new recipients, inbox-rule changes, external forwarding, or unusual login context. A spike with one of those indicators is much more concerning than a spike caused by a known campaign or bulk notification job.
What to verify: Confirm whether the sender behaviour matches the user’s normal pattern. If the mailbox is sending outside its usual hours, to new distribution clusters, or with short, generic content that drives replies or clicks, escalate the case and consider immediate session revocation and credential reset.
Practitioner takeaway: The most useful signal is not that an account is busy, but that it is busy in a way the legitimate user does not normally behave, because that is what turns a trusted mailbox into an attacker-controlled delivery path.
Related resources from NHI Mgmt Group
- What are the signs that an email security stack is failing to detect internal phishing and account takeover activity?
- What actions should I take if my OAuth tokens are compromised?
- Why do attackers often check model availability before trying to generate content?
- How should teams respond when a service account token is exposed?