Common warning signs include unusual login activity, a sudden burst of outbound messages from a legitimate mailbox, and emails that push urgent action through a link or attachment. A brand mismatch in the message flow, such as one brand in the email and another on the landing page, is another strong indicator that the campaign is fraudulent.
What the mailbox and traffic pattern reveal
An internal phishing campaign often shows up first in behavior, not content. The key signal is that a trusted account begins acting unlike itself: messages go out in bursts, logins appear from unexpected places or at odd times, and recipients are pushed toward a fast click on a link or attachment. That combination matters because it suggests the campaign has moved from a single lure to active account abuse.
Brand mismatch is another practical clue. When the email, the landing page, and the message theme do not line up cleanly, the attacker is often stitching together reused infrastructure or a compromised sender path. The faster you see that inconsistency, the sooner you can treat the activity as an in-progress campaign rather than an isolated suspicious email.
When these patterns appear together, the question is no longer whether an email was malformed, but whether a legitimate mailbox has already been used to distribute malicious traffic at scale. That is the operational shift practitioners should watch for.
What changes when the campaign is already active
An active campaign usually leaves a trail across identity, messaging, and user interaction. You may see a legitimate account sending to internal and external recipients, new forwarding or reply behavior, repeated authentication prompts, or a sudden jump in failed and successful sign-ins. Those are strong signs that the attacker is trying to extend access, not just deliver one phishing message.
The phishing content itself also tends to become more urgent once the attacker has momentum. Common indicators include deadline pressure, payment or password themes, unexpected document requests, and attachment-based lures that try to bypass user hesitation. If the message flow includes replies, follow-up messages, or multiple waves from the same mailbox, assume the campaign is being iterated in real time.
At this stage, the important distinction is between suspicious mail and a compromised sending path. A single spoofed email is a warning. A trusted mailbox sending convincing lures is evidence that the campaign is already under way and may be operating from inside your environment.
Why confirmation has to happen quickly
Once a campaign is active, delay increases the blast radius. Every minute the attacker retains access can produce more sent mail, more recipient interaction, and more credential capture opportunities. The most useful confirmation steps are those that establish whether the sending account is genuinely compromised, whether any forwarding or OAuth-style persistence has been added, and whether recipients have already interacted with the lure.
That triage matters because the next decision is containment, not just awareness. If the evidence points to mailbox abuse, the response should focus on stopping outbound delivery, removing persistence, and identifying which users clicked or submitted credentials. If the pattern is only a spoofed brand mismatch with no account abuse, the response can stay narrower and focus on blocking the lure path.
For deeper context on identity compromise and credential abuse patterns, the MailChimp Breach and Poland Military Breach examples show how trusted email access can be turned into broad message abuse and sensitive exposure. If the phishing path is tied to token theft or delegated access, the CoPhish OAuth Token Theft via Copilot Studio case is a useful reminder that the sender may be legitimate while the intent is not.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1566 — Phishing | Explains the lure-and-delivery behavior behind active phishing campaigns. |
| Recommendation — Map suspicious mail patterns to phishing tradecraft and hunt for delivery, credential capture, and follow-on abuse. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Mail and login anomalies require review of logs and sign-in records to confirm compromise. |
| IA-5 — Authenticator Management | Campaigns that steal credentials or tokens are controlled by credential lifecycle and revocation. | |
| Recommendation — Correlate mailbox, sign-in, and forwarding-rule logs to confirm active abuse and scope the incident. Revoke and rotate exposed authenticators, tokens, and related secrets immediately after compromise. | ||
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | Phishing campaigns often succeed by stealing secrets or tokens from trusted identities. |
| NHI-10 — Human Use of NHI | Abuse of a legitimate mailbox or delegated identity is central when phishing is sent from trusted access. | |
| Recommendation — Treat any stolen token or credential as compromised and rotate it before restoring access. Remove human-operated misuse paths and restrict who can act through trusted non-human or delegated access. | ||
Practitioner Guidance
What to verify: Treat any burst of outbound mail from a trusted account as a containment trigger and verify whether the account has unusual sign-ins, new forwarding rules, or newly granted application access. That combination is more actionable than the message content alone.
Decision rule: If the campaign is coming from a legitimate mailbox or any identity with sending authority, prioritize account isolation and credential or token revocation before you spend time on message cleanup. If the email is only spoofed, focus first on filtering, takedown, and recipient warning.
What practitioners underestimate: The landing page is not the only indicator. In many real campaigns, the fastest clue is the sender behavior, especially a trusted mailbox that suddenly starts operating like a distribution node.
Practitioner takeaway: The best sign that phishing is already underway is not just that suspicious mail exists, but that trusted identity is being used to push it, because that is what turns a lure into an active campaign.
Related resources from NHI Mgmt Group
- What are the signs that exploitation of a hardcoded credential vulnerability may already be under way?
- What are the signs that a container supply chain abuse campaign is under way?
- What signs indicate a WSUS exploitation attempt is under way?
- Why do lockfiles matter more once a supply chain incident is already under way?