By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: Artemis SecurityPublished July 28, 2026

TL;DR: A departing finance manager created a first-ever inbox forwarding rule to a personal Gmail and the case was flagged before offboarding disabled the account, even though login, device, and phishing-resistant MFA all looked clean, according to Artemis Security. The finding shows that strong authentication can coexist with mailbox-state abuse that survives account disablement.


At a glance

What this is: This is a breach-detection analysis showing that a first-ever mailbox forwarding rule can create offboarding risk even when authentication signals are clean.

Why it matters: It matters because IAM and PAM teams often trust account disablement and MFA too much, while mailbox-level state can still move sensitive mail outside the organisation after offboarding begins.

By the numbers:

👉 Read Artemis Security's analysis of the offboarding forwarding-rule detection case


Context

Mailbox forwarding rules are a classic offboarding blind spot because they operate inside the account rather than at the authentication layer. In this case, the primary identity signal was clean, but the mailbox itself was being repurposed to send mail to a personal address during the user’s exit.

For identity teams, the lesson is not about password strength or device trust. It is about lifecycle control across human IAM and adjacent mailbox state, where a disabled account can still leave behind forwarding rules, delegate access, and mailbox-level persistence if those objects are not explicitly enumerated.

The article’s core finding is that detection has to reason about intersections. A first-ever forwarding rule becomes materially different when the same identity profile already shows a termination date and offboarding activity.


Key questions

Q: How should security teams handle mailbox forwarding during offboarding?

A: Security teams should treat mailbox forwarding as part of identity lifecycle control, not as an email-only issue. The key is to check for external forwarding, inbox rules, and delegate access when a user enters offboarding, then remove or block those settings before the account is disabled. Strong authentication does not make a risky mailbox action acceptable.

Q: Why do strong MFA and managed devices not stop internal email exfiltration?

A: Because they prove who authenticated, not what the user did after login. A trusted session can still create forwarding rules, redirect mail, or alter mailbox behaviour. The control gap appears when identity teams assume authentication quality is the same as action legitimacy, especially during leaver processing.

Q: What breaks when offboarding only disables the primary account?

A: The lifecycle control remains incomplete. Users may still have active sessions, linked app permissions, or residual access through connected systems, which means the organisation records termination without actually ending access. That is a governance failure because it creates a false sense of closure and leaves exposure behind.

Q: Who is accountable when a departing employee leaves a forwarding rule in place?

A: Accountability usually spans IAM, email administration, and HR lifecycle owners because the risk sits at the boundary between identity status and mailbox configuration. If the programme treats offboarding as only credential revocation, no one owns the message-routing layer that keeps the risk alive.


Technical breakdown

First-ever inbox forwarding rules as a lifecycle control gap

An inbox rule that forwards or redirects mail is not a login event. It is mailbox-state change, which means it can survive authentication hardening and still move data after access is removed. The article shows why novelty matters: a first-ever forwarding rule is a stronger signal than a routine mailbox action because it changes how future mail is handled. In practice, the security issue is not the rule itself but the absence of monitoring that joins mailbox history, directory attributes, and lifecycle state.

Practical implication: enumerate mailbox rules and forwarding attributes during offboarding, not only at account disable.

Why phishing-resistant MFA does not stop mailbox abuse

Phishing-resistant MFA proves who is at the keyboard, but it does not validate whether the action is appropriate. A user can authenticate with a strong device-bound factor and still create a forwarding rule that redirects mail outside the organisation. That distinction matters because many identity programmes treat successful authentication as a proxy for legitimate intent. In mailbox governance, intent must be evaluated against lifecycle state, historical behaviour, and destination risk.

Practical implication: do not let strong MFA suppress alerts when a user creates external forwarding during offboarding.

Offboarding workflows kill sessions, not mailbox state

Offboarding commonly focuses on disabling the account, revoking tokens, and ending active sessions. That is necessary but incomplete because mailbox rules, forwarding settings, and delegate grants can remain in place after the identity is disabled. The technical failure is a control boundary mismatch: the identity is removed, but the message-routing logic persists. This is why email exfiltration through internal features is so persistent in enterprise environments.

Practical implication: extend offboarding runbooks to include mailbox-state checks, rule enumeration, and forwarding removal.


Threat narrative

Attacker objective: The objective was to preserve access to incoming business mail after departure by routing it to a personal address outside organisational control.

  1. Entry occurred through a legitimate user session on a managed device with phishing-resistant MFA, so the action blended into normal human activity.
  2. Escalation happened when the mailbox was reconfigured with a first-ever forwarding rule that redirected incoming mail to a personal Gmail account and then extended to forward as well.
  3. Impact would have been continued delivery of business email to an external personal inbox after routine account disablement, creating an offboarding leakage channel.
  • Coupang Signing Key Breach — Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
  • Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Mailbox forwarding during offboarding is a governance failure, not an authentication failure. The article shows a clean login path that still produced a risky mailbox change because the control problem sat above the session layer. Lifecycle state, mailbox history, and destination risk mattered more than MFA strength. That means offboarding governance must treat mailbox state as part of identity, not as a separate email-admin concern.

First-ever forwarding rules create identity blast radius when they intersect termination data. A new forwarding rule is ordinary until the identity profile also shows an imminent exit. That combination turns a harmless feature into a channel for post-employment data movement. The named concept here is lifecycle-routing exposure: mailbox routing changes that become security events only when viewed against leaver status. Practitioners should treat that intersection as a primary detection lens.

Strong MFA can confirm the actor while leaving the abuse path untouched. The article is a reminder that authentication and authorisation are not the same control plane. A verified user can still make a harmful change inside the mailbox if policy does not evaluate action context. Human IAM programmes need to stop using successful sign-in as evidence that downstream behaviour is safe.

Account disablement does not equal data-path shutdown. This is the assumption gap the case exposes. Identity offboarding was designed for access revocation, but mailbox forwarding is a routing control that can outlive the account. The implication is not just tighter policy. It is a redefinition of what “offboarded” means when message flow can continue after the identity is gone.

Identity teams need intersection-based detection, not threshold-based alerting. The strongest signal in the story was not any single event, but the convergence of a first-ever rule, a personal destination, and a termination date. That pattern is exactly where human judgement adds value to automation. Practitioners should structure detections around correlated lifecycle and mailbox events, then escalate only when those facts align.

From our research:

  • 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months, according to The State of Non-Human Identity Security.
  • From our research: Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared with nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
  • Mailbox forwarding and delegate access are lifecycle problems that belong in the same operational view as identity governance, which is why the NHI Lifecycle Management Guide is the right next resource for offboarding-bound controls.

What this signals

Lifecycle-routing exposure: mailbox forwarding becomes a security event only when it intersects leaver status, and that means human IAM programmes need to watch for routing changes, not just account closure. As offboarding gets more automated, correlation between identity profile changes and mailbox state will matter more than isolated alerts. Teams that do not join those signals will miss the exact window this case exploited.

With 85% of organisations lacking full visibility into third-party vendors connected via OAuth apps, per the State of Non-Human Identity Security, the same visibility problem shows up inside human offboarding when mailbox controls sit outside the IAM workflow. The practical response is to extend identity review into email-state review before disablement completes.


For practitioners

  • Join mailbox-rule monitoring to leaver workflows Alert when a user creates or edits an external forwarding rule within the offboarding window, especially after a termination date appears in the identity profile.
  • Enumerate mailbox state during every offboarding Check inbox rules, mailbox forwarding attributes, and delegate grants before account disablement so message routing cannot outlive the identity.
  • Rank first-ever forwarding rules as high-risk Score a new rule against the mailbox’s full history, not a fixed lookback window, because novelty is the key signal in this pattern.
  • Separate MFA assurance from action approval Treat phishing-resistant MFA as proof of session authenticity only, then evaluate whether the mailbox action matches lifecycle state and policy.

Key takeaways

  • This case shows that a verified user can still create a harmful mailbox routing change during offboarding.
  • The evidence was not a login anomaly but the intersection of a first-ever forwarding rule, a personal destination, and termination data.
  • Disabling the account is insufficient unless offboarding also removes mailbox rules, forwarding settings, and delegate access.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Mailbox forwarding during offboarding is an access and authorisation governance issue.
NIST SP 800-53 Rev 5AC-2Account lifecycle control is central because the risk starts before the account is disabled.
NIST SP 800-63SP 800-63BThe case relies on phishing-resistant authentication, but assurance does not cover downstream mailbox actions.
OWASP Non-Human Identity Top 10NHI-08Mailbox forwarding is a lifecycle and delegation problem that maps to unmanaged credential and access persistence patterns.

Use SP 800-63B to validate session assurance, then separate that from authorisation of mailbox changes.


Key terms

  • Mailbox Routing Exposure: The risk that mailbox rules, forwarding settings, or delegate permissions can keep moving messages after identity access should have ended. It is a lifecycle problem, not just an email configuration issue, because the control failure is persistence of data flow after account disablement.
  • Lifecycle-routing exposure: A security condition where a mailbox or similar routing control becomes risky only when paired with leaver status, termination dates, or offboarding activity. The same change can be harmless in steady state and dangerous during exit processing, which is why correlation is essential.
  • Phishing-Resistant MFA: Phishing-resistant MFA uses authentication factors that cannot be easily replayed, intercepted, or socially engineered. In regulated environments, this usually means device-bound or cryptographic methods rather than push prompts or SMS codes, because the control must hold up under realistic attack conditions.
  • Offboarding: Offboarding is the controlled retirement of a workload, service account, token, certificate, or other non-human identity when it is no longer needed. It includes revoking credentials, removing permissions, and verifying that no residual trust path remains available to attackers.

What's in the full article

Artemis Security's full breach analysis covers the operational detail this post intentionally leaves for the source:

  • The exact detection logic used to correlate first-ever rule creation with leaver status and personal destination matching.
  • The raw event sequence from identity profile change to mailbox rule creation to offboarding disablement.
  • The triage workflow for confirming mailbox state, session legitimacy, and message exposure before account closure.
  • The practical hunting pattern for rule novelty across Exchange and similar mailbox platforms.

👉 The full Artemis Security post includes the event timeline, detection logic, and investigation steps that surrounded the mailbox rule change.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 11, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org