Join our Newsletter — 33% off our NHI Course

What should organisations do when phishing campaigns target employees through both external email and compromised internal accounts?

Organisations should treat internal email as part of the attack surface, not a trusted channel by default. That means filtering inbound and lateral email, training users to verify unexpected requests, and using controls that detect fraud and BEC beyond malware. If attackers can reuse compromised accounts, internal trust assumptions must be reduced quickly.

Why mixed-channel phishing changes the trust model

When phishing arrives through both external email and compromised internal accounts, the organisation is no longer dealing with a single inbound filter problem. The attacker is using two trust paths at once: one to get initial access, and one to make malicious requests look legitimate once inside the mailbox ecosystem. That means the defensive model has to treat internal mail as a potentially hostile delivery path, not a guaranteed trusted channel.

In practice, the highest-value targets are often the requests that blend into normal business flow, such as payment changes, credential resets, file-share invitations, or “urgent” approval requests. The risk is not just malware delivery. It is fraud, business email compromise, and account abuse that can continue even when perimeter filters catch obvious spam.

Controls that matter across both external and internal email

Defence needs to cover the full message path, from arrival to lateral movement. That includes inbound filtering, impersonation detection, mailbox anomaly detection, restrictions on auto-forwarding and suspicious delegation, and controls that reduce the value of a stolen account if it is reused to send trusted-looking messages. Strong authentication for users helps, but it does not solve the problem on its own because a compromised account can still send convincing mail from inside the tenant.

Organisations should also harden the processes that phishing tries to subvert. If an email asks for a payment, password reset, banking detail change, or document approval, the verification step should happen out of band through a known contact path or approved workflow. This is where controls such as phishing-resistant authentication, sender verification, and mailbox abuse monitoring reinforce each other rather than acting as separate silos. For identity assurance, NIST SP 800-63 Digital Identity Guidelines is useful when you are deciding how much trust to place in the login event itself.

Internal account compromise also changes the detection problem. A message from a legitimate internal mailbox may still be malicious, so security teams need rules that look for unusual senders, new forwarding rules, impossible travel, abnormal reply chains, and mass-mail behaviour. For a control framework view of those basics, NIST Cybersecurity Framework 2.0 provides the governance, protect, detect, respond, and recover lens that maps well to mailbox abuse.

How compromised internal accounts widen the attack path

Once an attacker has a working internal account, they gain more than delivery capability. They can observe internal language, mimic real workflows, harvest trust relationships, and reuse the account to attack colleagues, suppliers, and finance processes. That is why compromised-account phishing is often more dangerous than ordinary spam: the attack is no longer filtered by sender reputation alone, and the attacker can exploit the recipient’s expectation that internal mail is safe.

The practical consequence is that mailbox compromise must be treated as both an access issue and a fraud issue. If the attacker can use the account to reset other credentials, approve transactions, or request sensitive files, the blast radius can extend far beyond the email system. Organisations should assume that one compromised account can become a launching point for broader credential theft, impersonation, and lateral social engineering. The more tightly these accounts are governed, the less useful they are to an attacker.

Risk and Threat Considerations

Mixed-channel phishing raises the chance that users will trust a message for the wrong reason. External mail can be blocked, but a message sent from a compromised internal account can bypass normal suspicion and trigger quick action before verification happens.

Failure mechanism: The attacker combines inbound phishing with trusted internal delivery, then uses the compromised mailbox to maintain legitimacy, redirect conversations, or trigger approvals and credential resets.

Impact: Organisations can see credential theft, fraudulent payments, data exposure, and broader account takeover that spreads through trusted internal communication paths.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-63 IA-5 — Authenticator Management Phishing success often depends on stolen or replayed authenticators and session material.
Recommendation — Use phishing-resistant authenticators and tightly manage credential lifecycle to limit account reuse.
NIST CSF 2.0 PR.AA-05 — Identity Management, Authentication, and Access Control Mixed-channel phishing exploits weak trust in authenticated internal senders and account reuse.
DE.CM-01 — Security Continuous Monitoring Detecting internal-mail abuse depends on monitoring anomalous sending and mailbox behavior.
RS.CO-01 — Personnel know their roles and order of operations in a response incident Phishing campaigns using internal accounts require coordinated reporting and containment actions.
Recommendation — Apply stronger authentication and access controls to reduce trust in compromised mail accounts. Monitor email and identity signals for anomalous internal sending, forwarding, and delegation. Define who contains mailbox abuse, who validates requests, and who escalates suspected compromise.
NIST SP 800-53 Rev 5 AC-2 — Account Management Compromised internal accounts become attacker delivery channels when account governance is weak.
Recommendation — Review, disable, and tightly govern accounts that can be abused for internal phishing.

Practitioner Guidance

What to prioritise: Treat mail flow, mailbox compromise, and business-process abuse as one problem. If the message can influence finance, HR, executive, or admin workflows, it needs stronger verification than ordinary user mail.

What to verify: Check whether internal senders are being monitored for unusual forwarding rules, delegated access, abnormal sending patterns, and sudden changes in conversation behaviour. If those signals are missing, the attacker may be operating inside a trusted mailbox without being seen.

Decision rule: If an email request creates a real-world consequence, such as a payment, account change, or data release, require an independent confirmation path before action. If the request originated from a compromised internal account, treat the trust downgrade as immediate, not conditional on full forensic confirmation.

Practitioner takeaway: The key shift is to stop treating “internal” as synonymous with “safe”; once account compromise is plausible, the organisation must verify requests by process, not by sender location.