By NHI Mgmt Group Editorial TeamDomain: Breaches & IncidentsSource: ExpelPublished September 29, 2025

TL;DR: A compromised employee account was used to send internal phishing emails that standard alerts missed, while Expel’s MDR email coverage correlated unusual login location, recipient behavior, and mailbox changes to raise a critical incident. The case shows why internal-origin email abuse demands identity-aware detection, not just perimeter filtering.


At a glance

What this is: This is an analysis of how a compromised internal email account was used to distribute phishing emails and how correlated email telemetry exposed what standard alerts missed.

Why it matters: It matters because identity compromise turns trusted internal communication into an attack channel, forcing IAM, SOC, and email security teams to detect abuse after authentication rather than only at the perimeter.

👉 Read Expel's analysis of internal phishing from a compromised employee account


Context

Internal phishing is harder to stop than external phishing because the message inherits trust from a real user account, mailbox, and normal business context. Once an account is compromised, traditional email filters may see only a legitimate sender, even though the communication is part of an attack chain. That makes identity security, mailbox telemetry, and behavioural detection part of the same control problem.

For IAM and SOC teams, the key issue is not just whether malicious mail enters the environment, but whether a trusted identity can be abused to deliver it from inside. This incident sits squarely at the intersection of human identity compromise, mailbox abuse, and downstream endpoint risk. The pattern is increasingly common whenever conditional access, mailbox monitoring, and response playbooks are not tightly linked.


Key questions

Q: What breaks when a phishing victim account is used to send internal email at scale?

A: The trust boundary breaks first. A compromised account can bypass user suspicion, security filters, and normal sender expectations because the message appears to come from inside the organisation. That can create a second wave of phishing, credential capture, and mailbox abuse. Defenders need to treat the first compromise as a propagation risk, not a single-user event.

Q: Why do compromised user accounts increase phishing risk inside the organisation?

A: A compromised account can impersonate a normal colleague, which raises click likelihood and reduces detection. Internal senders inherit trust, and attackers can use that trust to deliver links, collect credentials, or install tools. The risk rises further if mailbox telemetry and conditional access are not tied to response.

Q: How can teams tell whether phishing controls are actually working?

A: Look for fewer successful credential submissions on lookalike domains, lower password reuse, and faster reporting of suspicious messages. If users still reach fake login pages and can submit credentials without friction, the control environment is only reducing risk on paper. The goal is to stop secrets from leaving the user’s device.

Q: Who is accountable when phishing leads to account compromise?

A: Accountability is shared, but security leadership owns the control environment that made impersonation succeed. Email authentication, browser trust configuration, access scoping, and incident reporting are governance responsibilities, not just end-user habits. If phishing can repeatedly turn into compromise, the control model is failing at the organisational level.


Technical breakdown

Why internal-origin phishing bypasses normal email controls

Traditional email security is optimised to inspect incoming messages from external sources, where sender reputation, URL reputation, and attachment scanning can be applied before delivery. When an attacker sends from a compromised internal mailbox, those controls are weaker because the message appears to come from a legitimate identity inside the trust boundary. The real detection problem becomes behavioural: unusual login geography, new recipients, mailbox rule changes, and abnormal forwarding or deletion activity. In practice, internal-origin phishing is a trust-abuse problem, not just a filtering problem.

Practical implication: SOC and IAM teams need detections that combine mailbox behaviour with identity telemetry, not inbox filtering alone.

How attacker-controlled RMM tools turn phishing into remote access

A remote monitoring and management tool is not malicious by default. Attackers abuse it because once a user installs it, the tool can provide administrator-like control while blending into legitimate operational noise. In this incident, the malicious email led users to download an executable masquerading as a document, which then installed the attacker-controlled RMM. That pattern matters because it converts a simple click into durable remote control and creates a path for lateral movement without needing a bespoke malware family. Legitimate admin tools can therefore become effective post-compromise infrastructure.

Practical implication: application control and software allowlisting must cover remote admin tools, not just obvious malware binaries.

Why mailbox changes are often the earliest signal of compromise

Mailbox filter creation, deletion of sent or received messages, and unusual recipient patterns often show up before broader endpoint compromise is obvious. Those actions indicate the attacker is trying to reduce visibility, preserve access, or shape delivery conditions for follow-on phishing. In this case, Expel’s detection worked because it correlated the unusual login location, non-routine recipients, and mailbox manipulation into a single high-confidence incident. That is a stronger model than waiting for a malicious payload to detonate on an endpoint. It is also a reminder that account abuse leaves traces inside the collaboration stack itself.

Practical implication: response teams should monitor mailbox rule creation and message deletion as first-class compromise indicators.


Threat narrative

Attacker objective: The attackers were trying to turn a trusted internal account into a delivery mechanism for remote access and lateral movement.

  1. Entry occurred when attackers compromised a user account and used the authenticated mailbox to send phishing messages from inside the organisation.
  2. Escalation happened when recipients clicked the link and installed an attacker-controlled RMM tool that could provide remote access on multiple endpoints.
  3. Impact was a potential lateral movement path toward broader compromise, with the activity appearing consistent with pre-ransomware staging.
  • MITRE ATT&CK Enterprise Matrix — MITRE ATT&CK Enterprise — adversary tactics and techniques, threat detection, attack chain mapping, credential access, lateral movement, privilege escalation.
  • Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Internal-origin phishing is an identity compromise problem before it is an email problem. The message delivery channel matters, but the real failure is that a trusted human identity was converted into an attack platform. That shifts governance from inbox inspection to account behaviour, mailbox telemetry, and response orchestration across IAM and SOC. Practitioners should treat compromised user accounts as active delivery infrastructure, not merely as stolen logins.

Mailbox abuse creates a detection gap because the sender is authenticated, not external. External filtering alone cannot reliably distinguish a real employee message from a message sent under attacker control. The control gap is the absence of identity-aware correlation between authentication anomalies, recipient drift, and mailbox rule changes. Teams should assume that legitimacy at the protocol layer does not equal legitimacy at the behavioural layer.

Application control must include legitimate admin tools that attackers routinely repurpose. Remote monitoring and management software can function like a remote access trojan when delivered through social engineering. That makes software policy, endpoint controls, and phishing response part of the same containment stack. The broader lesson is that trusted tooling becomes attack infrastructure the moment a user is persuaded to install it.

Detection latency, not only prevention, determines how far internal phishing can spread. The incident shows why organisations need controls that spot abnormal account use before multiple endpoints are touched. Conditional access, mailbox rules monitoring, and cross-domain alert correlation are not optional extras. Practitioners should measure how quickly they can recognise authenticated abuse after the first malicious email is sent.

Identity security and email security now overlap at the mailbox boundary. Once a user account can be leveraged to deliver phishing, the governance model must cover sign-in risk, mailbox rules, privileged recovery, and endpoint execution in one response path. That boundary is where many programmes still operate in silos. Practitioners should align identity, messaging, and endpoint teams around a shared abuse-detection workflow.

From our research:

  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
  • Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks.
  • Forward pivot: Read 52 NHI Breaches Analysis for patterns that show how compromised identities turn into repeatable attack paths.

What this signals

Internal phishing should now be treated as an identity lifecycle failure, not a pure messaging problem. Once attackers hold a valid account, the control question becomes how quickly the organisation can detect abnormal behaviour, revoke access, and contain secondary execution. That is where IAM, email security, and endpoint response need a shared operating model, supported by guidance such as Ultimate Guide to NHIs , Key Challenges and Risks.

Mailbox telemetry is becoming a first-class identity control signal. A compromised account often leaves traces in recipient drift, rule changes, and deletion activity before endpoint compromise becomes obvious. For teams building detection logic, that means the trust boundary is no longer the inbox alone but the authenticated session behind it.

Conditional access only helps if it is paired with response discipline. Unusual logins and atypical sending patterns should trigger containment, not just investigation tickets. Teams that can revoke sessions, block domains, and isolate endpoints in one workflow will shrink the attacker’s window far more effectively than teams that rely on static email filtering.


For practitioners

  • Harden compromised-account response playbooks Automatically disable the account, force password reset, revoke sessions, and invalidate mailbox tokens when an authenticated account starts sending abnormal internal mail or creating unexpected rules.
  • Correlate mailbox behaviour with identity signals Alert on unusual login geography, new recipient clusters, forwarding rules, message deletion, and suspicious send patterns from accounts that normally do not broadcast broadly.
  • Restrict execution of remote admin tools Use application control to block or tightly govern RMM installers on user workstations, especially when the tool is not required for the user role.
  • Contain endpoint execution from internal phishing clicks Quarantine and reimage systems that downloaded the payload, then block the related domains and IP addresses before the payload can establish persistence.

Key takeaways

  • Internal phishing works because attackers inherit the trust of a real authenticated user, not because email filters suddenly fail.
  • The incident shows how mailbox behaviour, recipient drift, and login anomalies can expose compromise before broader endpoint impact occurs.
  • Practitioners should align IAM, email security, and endpoint containment so a hijacked account cannot become a delivery system.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03The incident centers on compromised identity and abused internal access.
MITRE ATT&CKTA0001 , Initial Access; TA0006 , Credential Access; TA0008 , Lateral MovementThe attack chain spans account compromise, credential abuse, and lateral movement intent.
NIST CSF 2.0PR.AC-4Least-privilege and access governance are directly implicated by account abuse.
NIST SP 800-53 Rev 5IA-5Authenticator management is central because the attacker used a compromised user account.
CIS Controls v8CIS-5 , Account ManagementAccount lifecycle and monitoring controls are the core defensive gap in this case.

Map the case to ATT&CK and prioritise detections for compromised-account phishing and follow-on movement.


Key terms

  • Internal-origin Phishing: A phishing campaign sent from an account already trusted inside the organisation. It is dangerous because standard inbound controls often see legitimate authentication, while the real issue is the abuse of a valid identity and its surrounding mailbox behaviour.
  • Mailbox Behavioural Telemetry: Signals derived from how a mailbox is used, such as recipient patterns, rule changes, deletions, and forwarding activity. These indicators help reveal when a legitimate account is being operated by an attacker rather than its owner.
  • Remote Monitoring and Management: Remote Monitoring and Management, or RMM, is software used to administer devices and systems from afar. In this context it becomes a high-risk control plane because it can reach many assets at once and often carries enough privilege to change configuration, suppress alerts, or trigger operational actions.

What's in the full article

Expel's full analysis covers the operational detail this post intentionally leaves for the source:

  • The exact email signals that triggered the critical incident, including unusual login location and mailbox manipulation.
  • The response sequence used to contain the five affected endpoints and remove remaining malicious emails.
  • The recommended conditional access and application control changes that reduce repeat abuse.
  • The incident scoping logic that distinguished this case from ordinary phishing quarantine activity.

👉 Expel's full post covers the attack chain, mailbox indicators, and recommended containment actions.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management in a way that helps security teams strengthen access control and response discipline. It is designed for practitioners who need to connect identity governance to operational containment across modern environments.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 20, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org