Join our Newsletter — 33% off our NHI Course

What are the signs that email account compromise is being used to drive fraud inside an organisation?

Common signs include unexpected payment instructions, changes to supplier bank details, urgent requests for gift cards or payroll updates, and emails that appear to come from trusted executives or vendors. Organisations should also watch for unusual logins, mailbox forwarding rules, and account activity that does not match normal business patterns. These are often the early indicators of account abuse.

How email compromise turns into fraud inside an organisation

email account compromise matters because the attacker is not just reading messages, they are using a trusted inbox to shape business decisions. That can let them redirect payments, alter supplier details, approve payroll changes, or impersonate executives with enough context to sound legitimate. In practice, the fraud often succeeds because the message arrives inside an existing business relationship and looks routine.

The first pattern to watch is transaction manipulation. If a compromised mailbox is used to insert new banking instructions, pressure staff into urgent action, or push gift card and payroll requests, the attacker is trying to convert mailbox trust into financial loss. Email Identity and BEC Guide covers the email authentication and payment verification controls that reduce that risk.

A second pattern is impersonation with context. Once the attacker can read prior threads, they can reply in the middle of an existing conversation, mimic tone, and exploit routine approval paths. That is why compromise indicators often include emails that look like they came from a trusted executive or vendor, especially when the request bypasses normal review steps. The 52 NHI Breaches Report is useful background on how stolen credentials and lateral use of trust relationships can amplify the blast radius of a compromise.

Mailbox abuse also shows up in quieter ways. Forwarding rules, delegated access, and login activity outside normal business patterns can give the attacker persistence even after the first message is sent. If those changes are present, the account may already be being used as an internal fraud platform rather than only as an information source.

Why the signs are often operational, not just technical

The most reliable signals are usually combinations of business anomalies and mailbox anomalies. A single unusual login may be benign, but an unusual login followed by new inbox rules, a supplier bank change, and a payment request is a much stronger fraud chain. That is why the warning signs should be read as a sequence, not as isolated events.

Payment-side clues matter as much as email-side clues. Urgent requests, changes to invoice destinations, shifts in beneficiary details, and unexpected pressure to bypass normal approval thresholds are all evidence that the mailbox is being used to drive a financial outcome. If the request is time-sensitive and discourages verification, the attacker is often trying to beat reconciliation or callback controls.

Some of the clearest cases involve executive impersonation or vendor impersonation that rides on a real compromise. Arup deepfake fraud 2024 shows how trusted identity cues can be chained into a payment scam, and the same trust abuse pattern often appears when an email account is the entry point.

What makes these fraud attempts hard to spot

Fraud driven from email compromise is effective because it blends into normal work. The attacker uses existing names, prior conversations, and ordinary business language, so the message does not always look malicious on its face. The real signal is often behavioural drift: a supplier suddenly changes bank details, an executive starts requesting exceptions, or a mailbox begins sending messages outside normal hours or to unfamiliar recipients.

Compromised accounts can also create secondary indicators that are easy to miss. Forwarding rules, deleted sent items, unusual OAuth permissions, and account activity that does not match the user’s normal pattern all suggest the mailbox is being controlled or staged for ongoing abuse. That is especially important where the fraud is not immediate but is being prepared over several days or weeks.

For teams that want a broader benchmark on email impersonation and inbox abuse patterns, Identity Fraud Prevention Guide provides useful context on fraud signals, account takeover behaviour, and the kinds of account activity that should trigger escalation.

Risk and Threat Considerations

Email compromise becomes a fraud problem when the attacker can use trust, timing, and workflow knowledge to influence money movement or sensitive changes. The main risk is not only the stolen mailbox, it is the attacker’s ability to operate inside established approval paths and make false instructions appear routine.

Failure mechanism: The attacker hijacks a real account, observes normal correspondence, and then introduces a request that fits the existing business context closely enough to bypass informal trust checks or speed-focused approvals.

Impact: Organisations can suffer direct payment loss, payroll diversion, supplier fraud, and follow-on exposure if the compromised mailbox is also used to harvest invoices, personal data, or internal process details for the next stage of fraud.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1114 — Email Collection Email abuse and inbox review enable fraud staging and trust exploitation.
T1078 — Valid Accounts Compromised email accounts are valid accounts used to impersonate trusted senders.
Recommendation — Monitor for mailbox access, message harvesting, and suspicious rule creation around suspected compromise. Detect unusual use of valid accounts and quickly revoke access when abuse is suspected.
CIS Controls v8 CIS-6 — Access Control Management Compromised mailboxes and forwarding rules require rapid access and delegation control.
CIS-8 — Audit Log Management Login anomalies and mailbox rule changes depend on reliable audit evidence.
Recommendation — Review and remove unauthorized mailbox access, forwarding, and delegated permissions. Collect and review mailbox, identity, and transaction logs for fraud indicators.
NIST SP 800-53 Rev 5 AU-6 — Audit Record Review, Analysis, and Reporting Fraud-driven compromise is often exposed through unusual logins and rule changes.
IA-5 — Authenticator Management Email compromise is enabled by stolen or abused credentials and session material.
Recommendation — Review mailbox and identity logs for deviations from normal user behavior. Rotate or revoke compromised authenticators and reset affected sessions promptly.
OWASP Non-Human Identity Top 10 NHI-04 — Insecure Authentication Mailbox compromise often starts with weak or abused authentication to the email account.
NHI-02 — Secret Leakage Stolen credentials or tokens can let attackers control an email account used for fraud.
Recommendation — Strengthen mailbox authentication and remove weak or bypassable sign-in paths. Find and revoke exposed secrets that can access mail services or related workflows.

Practitioner Guidance

What to prioritise: Treat payment instructions, supplier banking changes, and payroll updates as fraud-sensitive events, not ordinary mailbox content. The highest-value signal is the combination of a trusted sender, urgency, and a request that changes where money goes.

What to verify: Confirm whether the account has new forwarding rules, unusual login geography or device patterns, and whether the request matches the sender’s normal role and approval path. If the message changes financial details, verify through an out-of-band channel before any payment is released.

Decision rule: If the mailbox can influence payments, employee pay, or vendor settlement, assume the compromise has fraud potential even if the email content appears modest. Contain the account first, then review recent correspondence and transaction requests for abuse.

Practitioner takeaway: The most dangerous sign is not a strange email by itself, but a familiar email that is trying to alter a financial decision while exploiting trust the organisation already extends to that account.