Join our Newsletter — 33% off our NHI Course

What are the signs that an email compromise campaign is being missed by legacy monitoring?

Warning signs include messages that reuse real names, familiar thread history, or legitimate sender addresses while pushing urgent payment or banking changes. Another signal is low and steady volume rather than a noisy blast, which means the campaign may not trigger threshold-based alerts. If employees report suspicious context but the gateway sees nothing malicious, detection is likely too narrow.

How legacy monitoring misses a low-and-slow email compromise campaign

Legacy email monitoring often assumes compromise will look noisy: a burst of malicious messages, a known bad attachment, or a clear sender anomaly. Campaigns that reuse legitimate thread context, familiar names, and real mailbox history can stay inside normal-looking traffic patterns, especially when the attacker sends only a few messages at a time and avoids obvious malware indicators.

The practical problem is that the detection logic is usually tuned to the gateway’s view of the world, not the conversation’s business context. If the message looks like a plausible continuation of a real discussion, but the intent is to redirect payment, banking details, or approval flow, the campaign can sit just below alert thresholds while still creating material exposure.

That makes the 52 NHI Breaches Report relevant as a broader reminder that compromise frequently rides on abused trust, stolen access, and credentialed activity rather than obvious malware-only patterns. In email compromise work, the same lesson applies: the attacker often succeeds by behaving like a trusted participant, not by looking overtly hostile.

What the warning signs look like in practice

One common sign is a message that feels socially “right” but operationally wrong. Real names, correct internal tone, and authentic thread history can all be copied while the request itself shifts to an unusual destination account, a new payment instruction, or a change in banking details. That mismatch matters more than a simple sender check.

Another signal is tempo. A campaign that sends a few carefully timed messages, or only targets a narrow set of employees, may never trip legacy volume thresholds. The absence of a noisy blast is not reassurance if the messages are narrowly targeted and tied to a payment, invoice, or executive-request workflow.

A third warning sign is human reporting that outperforms the gateway. When employees flag suspicious context, unusual urgency, or a request that does not fit prior practice, but the mailbox or secure email gateway shows nothing malicious, the detection stack is probably over-weighted toward static indicators and under-weighted toward behavioural and contextual cues.

For comparison, real-world business email compromise often succeeds because the attacker controls the conversation at the point where a financial decision is made. TruffleNet BEC Attack, Stolen AWS Credentials shows how abused credentials can support broader compromise and later fraud, which is why “looks legitimate” is not the same as “safe”.

What legacy controls tend to miss

Legacy monitoring is strongest when it can match known-bad content or known-bad infrastructure. It is weaker when the attack is relationship-driven, because the message itself may be clean while the intent is malicious. That creates a blind spot around sender reputation, thread hijacking, mailbox takeover, and trusted-looking language used to create urgency.

Detection also becomes brittle when the control assumes a sharp difference between “normal” and “malicious”. Email compromise campaigns often live in the gray zone: they reuse legitimate workflows, ask for one small exception, and depend on a rushed approval. A single request to change payment details can be more dangerous than a dozen obviously suspicious emails.

The right operational assumption is that compromise may already be in motion before your tools agree on it. Arup deepfake fraud 2024 is a useful reminder that trusted communication channels can be manipulated to drive high-impact fraud, so monitoring has to account for social trust abuse, not just technical indicators.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1114 — Email Collection Email compromise campaigns rely on mailbox access and message abuse.
T1566 — Phishing Low-and-slow BEC campaigns commonly begin with deceptive email delivery and trust abuse.
T1078 — Valid Accounts Campaigns often look legitimate because they use trusted accounts or compromised access.
Recommendation — Map suspicious mailbox activity to email collection patterns and hunt for abusive mailbox use. Correlate suspicious email patterns with phishing techniques and validate sender and content anomalies. Investigate use of valid accounts for suspicious mail flow and financial-request activity.
CIS Controls v8 CIS-8 — Audit Log Management Detection depends on mailbox, identity, and workflow visibility beyond gateway filtering.
Recommendation — Centralize and review email, identity, and finance workflow logs for anomalous request patterns.
NIST CSF 2.0 DE.AE-02 — Detect Anomalies The issue is missed anomalies that appear normal to legacy monitoring.
PR.AA-05 — Protective Authentication Management Compromised accounts make malicious messages appear trusted and bypass simple sender checks.
Recommendation — Tune detection to flag contextual anomalies in mail flow and business-request behavior. Strengthen authentication and account protections so mailbox trust cannot be abused silently.

Practitioner Guidance

What to prioritise: Treat business-context anomalies as first-class signals. A request that changes payment rails, bank details, approvers, or timing deserves review even when the message passes gateway checks and the sender looks familiar.

What to verify: Confirm whether the alerting logic can see thread context, sender change patterns, and payment-related language, not only malware and reputation indicators. If it cannot, the monitoring layer is too narrow for modern email compromise.

Common mistake: Teams often wait for a quarantine event, a malicious attachment, or a high-volume burst before declaring compromise. In low-and-slow BEC style activity, the more reliable trigger is a mismatch between conversational familiarity and business-request abnormality.

Practitioner takeaway: If employees notice suspicious context before the tooling does, assume the attack is exploiting trust and workflow familiarity, then widen detection beyond sender reputation and threshold-based alerting.