TL;DR: A single phishing-driven account compromise at a university escalated into 4,800 malicious emails, 40+ clicks, and inbox-rule-based concealment, according to Expel’s SOC analysis of the campaign. The case shows why identity correlation, not isolated alerts, determines whether defenders catch a contained phish or a broader account-abuse chain.
At a glance
What this is: Expel describes a university phishing campaign where one compromised account was used to seed larger-scale email abuse across thousands of users.
Why it matters: It matters because identity compromise, email abuse, and privilege to message large groups can turn a single click into a campus-wide incident that identity and SOC teams must detect as one chain.
By the numbers:
- According to Expel, the attacker sent phishing email to 4,800 other users at the university after compromising a student account.
- 40 recipients clicked the phishing link in the, icked the phishing link in the campaign.
- Q2 2025
👉 Read Expel's analysis of the university phishing campaign and account abuse chain
Context
Phishing remains effective because it exploits identity trust, not just technical weakness. When an attacker gains one account, the resulting abuse can spread through trusted messaging channels, mailbox rules, and social expectations faster than isolated alerts reveal.
This case sits squarely at the intersection of human identity governance and SOC investigation. A compromised student account became an internal distribution mechanism, while inbox rules were used to hide activity and preserve access long enough for the campaign to expand. That pattern is common in real-world identity abuse, not an edge case.
The primary lesson for IAM and SOC teams is that mailbox compromise, message volume, and suspicious sign-in location need to be analysed together. A single phish is often the entry point to a broader identity incident, and this one followed that familiar pattern.
Key questions
Q: What breaks when a phishing victim account is used to send internal email at scale?
A: The trust boundary breaks first. A compromised account can bypass user suspicion, security filters, and normal sender expectations because the message appears to come from inside the organisation. That can create a second wave of phishing, credential capture, and mailbox abuse. Defenders need to treat the first compromise as a propagation risk, not a single-user event.
Q: Why do mailbox rules make phishing incidents harder to contain?
A: Mailbox rules can hide replies, security warnings, and evidence of attacker activity while leaving the account technically usable. That gives the attacker persistence without needing malware. In practice, rule inspection should be part of every identity-led phishing investigation, because deletion and forwarding controls often explain why activity went unnoticed.
Q: How do security teams know if internal phishing is spreading beyond the first account?
A: Look for shared subjects, repeated sender patterns, rapid sign-in changes, and multiple recipients clicking the same lure across a short period. Those signals indicate the account is being used as an internal delivery mechanism rather than a one-off compromise. Joining mailbox telemetry with authentication logs is the fastest way to see scope.
Q: Who is accountable when phishing leads to account compromise?
A: Accountability is shared, but security leadership owns the control environment that made impersonation succeed. Email authentication, browser trust configuration, access scoping, and incident reporting are governance responsibilities, not just end-user habits. If phishing can repeatedly turn into compromise, the control model is failing at the organisational level.
Technical breakdown
How compromised accounts become internal phishing infrastructure
Once an attacker controls a legitimate account, outbound mail from that account inherits trust from the organisation’s own systems and users. That trust can be abused to distribute malicious links, request credentials, or seed further compromise. In this case, the compromised account became an internal phishing node that reached thousands of recipients. The technical risk is not just initial access but the attacker’s ability to use the victim’s identity as a delivery channel. Mail flow controls, sender reputation, and user awareness all matter, but they do not prevent abuse once the account is already active.
Practical implication: treat every compromised mailbox as a potential internal propagation path, not only an endpoint to restore.
Why inbox rules matter in identity abuse investigations
Inbox rules are often used by attackers to suppress security alerts, hide replies, or bury evidence of malicious activity. Because mailbox rules are a normal user feature, they can blend into routine administration unless teams specifically inspect them after suspicious sign-ins. In this attack, an inbox rule that deleted relevant mail was a concealment mechanism that helped extend attacker dwell time. For identity defenders, mailbox telemetry is part of the access story, because the attacker’s control plane may include rule creation, forwarding, and deletion actions rather than only password abuse.
Practical implication: review mailbox rules and forwarding settings whenever a suspicious login or phishing reply chain appears.
Why correlation across sign-ins and email activity exposes the full attack chain
A single alert rarely reveals the campaign. The SOC traced one suspicious login, expanded the IP range, and found additional account activity that linked multiple compromised users to the same operator. That is a classic identity investigation pattern: one account compromise becomes evidence for others when sign-in metadata, sender patterns, and mailbox changes are correlated. This approach turns fragmented detections into a coherent attack graph. Without that correlation, defenders may remediate one user while the broader abuse campaign continues.
Practical implication: correlate authentication events, mailbox changes, and bulk-message patterns in one investigation workflow.
Threat narrative
Attacker objective: The attacker wanted to turn one compromised identity into a trusted internal distribution point for phishing, credential collection, and wider account compromise.
- Entry occurred when the attacker used phishing to capture a student’s credentials and gain access to the mailbox.
- Escalation followed when the attacker used that legitimate account to send phishing messages to thousands of internal users and to create inbox rules that hid activity.
- Impact was broader credential and personal-data exposure risk, with dozens of users clicking the lure and the campaign reaching across the campus environment.
Breaches seen in the wild
- MITRE ATT&CK Enterprise Matrix — MITRE ATT&CK Enterprise — adversary tactics and techniques, threat detection, attack chain mapping, credential access, lateral movement, privilege escalation.
- Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Compromised identity becomes a distribution layer when mailbox controls are weak. This case shows that phishing is not just about stolen credentials, it is about what the attacker can do after the first login. When mailbox access, inbox rules, and bulk-send capability are not governed as part of identity risk, one account becomes an amplification point. Practitioners should treat message-sending rights and mailbox automation as identity controls, not merely email hygiene.
Inbox-rule abuse is a governance gap, not a side effect. Attackers use rules to hide replies, security notices, and evidence of their own activity. That means mailbox-rule creation, forwarding, and deletion behaviour should be monitored as part of access governance, especially in environments where users can self-manage rules. The failure mode is persistence through normal features, which makes detection dependent on behaviour correlation rather than signature-based alerts. Teams should make mailbox rules visible in identity investigations.
Campus-scale phishing illustrates why identity and SOC telemetry must be joined. The article’s central lesson is that the important signal was not the first click, but the relationship between sign-ins, sender activity, and mass-mail patterns. That is a named detection gap we can call identity correlation latency: the delay between a single suspicious identity event and a full understanding of campaign scope. Security teams should shorten that gap with joined telemetry and cross-domain triage.
Service accounts, students, and staff are governed by the same trust problem once credentials are live. The account type changes the business context, but not the core security issue: a legitimate identity can be repurposed instantly after compromise. That makes lifecycle controls, MFA, anomaly detection, and offboarding logic relevant across human identity programmes. The practitioner conclusion is straightforward: if compromised identities can message trusted audiences, governance has failed at the point of use.
From our research:
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to the Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which helps explain how identity abuse can persist unnoticed in large environments.
- Forward pivot: The NHI Lifecycle Management Guide shows how provisioning, rotation, and offboarding reduce the same persistence window that mailbox abuse exploits, according to the NHI Lifecycle Management Guide.
What this signals
Identity correlation latency: this case shows that the operational gap is often not detection of a single suspicious event, but the time it takes to connect that event to a broader abuse chain. Programs that still separate email, IAM, and SOC telemetry will continue to miss the campaign until scale makes it obvious. Joining identity signals to message activity is now a governance requirement, not an efficiency improvement.
For identity teams, the lesson is that mailbox privilege, self-service rule creation, and authentication anomaly handling need to be governed together. The NHI Lifecycle Management Guide is useful here as a reminder that access should be time-bound, monitored, and revoked when behaviour changes. Human identity programmes need the same lifecycle discipline when email becomes a delivery channel for compromise.
This pattern also reinforces the Zero Trust assumption that legitimate access cannot be treated as low risk after authentication. A trusted account can become hostile immediately, so continuous verification must extend into post-login behaviour, message patterns, and account configuration changes. That is where identity governance and SOC response converge.
For practitioners
- Correlate sign-ins with outbound mail volume Build detections that link a new login, unusual IP geography, and sudden high-volume internal messaging from the same account. This helps identify the account-abuse pattern before it spreads across mailing lists.
- Review mailbox rules after suspicious access Automatically inspect inbox rules, forwarding settings, and delete actions for any account that has a risky sign-in or phishing interaction. Attackers often use these settings to hide evidence and prolong access.
- Restrict broad-send privileges to trusted identities Limit the ability to email large recipient sets to approved mailing lists and trusted service accounts, and monitor for bulk sends outside those channels. Internal reach is what turns one compromised account into mass exposure.
- Reset credentials and isolate interacted accounts quickly Temporarily disable accounts that clicked the lure or showed linked activity, then force credential reset and session review. That containment step blocks reuse of captured credentials and stops the next internal send.
Key takeaways
- A single compromised mailbox can become a campus-wide phishing platform when identity controls do not constrain outbound trust.
- The strongest evidence of broader abuse came from correlated sign-ins, message patterns, and inbox-rule concealment, not from the first alert alone.
- Teams should govern mailbox rules, bulk-send rights, and post-login behaviour as identity controls that limit propagation after compromise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0001 , Initial Access; TA0006 , Credential Access; TA0008 , Lateral Movement | The attack chain begins with phishing and expands through credentialed account abuse. |
| NIST CSF 2.0 | PR.AA-1 | Identity proofing and access control are central when compromised accounts drive internal phishing. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is relevant where accounts can send broadly or change mailbox rules. |
| CIS Controls v8 | CIS-5 , Account Management | Account lifecycle and access monitoring are directly implicated by the compromise and reuse of student identities. |
| NIST Zero Trust (SP 800-207) | Zero Trust assumptions are stressed when authenticated users can become attack vectors immediately after login. |
Map phishing-to-mailbox abuse to these tactics and tune detections for rapid credential theft and account misuse.
Key terms
- Inbox Rule Abuse: The misuse of email filtering rules to hide, redirect, or suppress messages after an account has been accessed. In Exchange, these rules can become persistence and exfiltration mechanisms when they are created inside a legitimate mailbox context and are not monitored for malicious action patterns.
- Identity correlation: Identity correlation is the process of linking multiple account records to one governed subject. It lets IAM and IGA teams understand that separate usernames, principals, or emails may belong to the same employee or workload, which is essential for access review, offboarding, and entitlement analysis.
- Internal Phishing: Internal phishing is a campaign sent from a compromised or trusted internal account to other users inside the organisation. It is especially dangerous because the message inherits organisational trust, which raises click rates and delays suspicion.
What's in the full article
Expel's full analysis covers the operational detail this post intentionally leaves for the source:
- Timeline detail on how the first compromised account was identified and traced through campus logins
- Investigation specifics on the suspicious inbox rule and the IP pivot used to map related accounts
- Containment actions taken against interacted accounts, malicious domains, and the phishing messages themselves
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, identity lifecycle, and secrets management. It helps security practitioners apply lifecycle discipline to identity abuse patterns that cross human and non-human systems.
Published by the NHIMG editorial team on August 20, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org