Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Internal phishing from compromised email accounts: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18936
Topic starter  

TL;DR: A compromised employee account was used to send internal phishing emails that standard alerts missed, while Expel’s MDR email coverage correlated unusual login location, recipient behavior, and mailbox changes to raise a critical incident. The case shows why internal-origin email abuse demands identity-aware detection, not just perimeter filtering.

NHIMG editorial — based on content published by Expel: internal phishing from a compromised employee account

Questions worth separating out

Q: What breaks when a phishing victim account is used to send internal email at scale?

A: The trust boundary breaks first.

Q: Why do compromised user accounts increase phishing risk inside the organisation?

A: A compromised account can impersonate a normal colleague, which raises click likelihood and reduces detection.

Q: How can teams tell whether phishing controls are actually working?

A: Look for fewer successful credential submissions on lookalike domains, lower password reuse, and faster reporting of suspicious messages.

Practitioner guidance

  • Harden compromised-account response playbooks Automatically disable the account, force password reset, revoke sessions, and invalidate mailbox tokens when an authenticated account starts sending abnormal internal mail or creating unexpected rules.
  • Correlate mailbox behaviour with identity signals Alert on unusual login geography, new recipient clusters, forwarding rules, message deletion, and suspicious send patterns from accounts that normally do not broadcast broadly.
  • Restrict execution of remote admin tools Use application control to block or tightly govern RMM installers on user workstations, especially when the tool is not required for the user role.

What's in the full article

Expel's full analysis covers the operational detail this post intentionally leaves for the source:

  • The exact email signals that triggered the critical incident, including unusual login location and mailbox manipulation.
  • The response sequence used to contain the five affected endpoints and remove remaining malicious emails.
  • The recommended conditional access and application control changes that reduce repeat abuse.
  • The incident scoping logic that distinguished this case from ordinary phishing quarantine activity.

👉 Read Expel's analysis of internal phishing from a compromised employee account →

Internal phishing from compromised email accounts: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18527
 

Internal-origin phishing is an identity compromise problem before it is an email problem. The message delivery channel matters, but the real failure is that a trusted human identity was converted into an attack platform. That shifts governance from inbox inspection to account behaviour, mailbox telemetry, and response orchestration across IAM and SOC. Practitioners should treat compromised user accounts as active delivery infrastructure, not merely as stolen logins.

A few things that frame the scale:

  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
  • Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks.

A question worth separating out:

Q: Who is accountable when phishing leads to account compromise?

A: Accountability is shared, but security leadership owns the control environment that made impersonation succeed. Email authentication, browser trust configuration, access scoping, and incident reporting are governance responsibilities, not just end-user habits. If phishing can repeatedly turn into compromise, the control model is failing at the organisational level.

👉 Read our full editorial: Internal phishing from a compromised account exposes a detection gap



   
ReplyQuote
Share: