TL;DR: A single phishing-driven account compromise at a university escalated into 4,800 malicious emails, 40+ clicks, and inbox-rule-based concealment, according to Expel’s SOC analysis of the campaign. The case shows why identity correlation, not isolated alerts, determines whether defenders catch a contained phish or a broader account-abuse chain.
NHIMG editorial — based on content published by Expel: LLMjacking? How Attackers Hijack AI Using Compromised NHIs
By the numbers:
- According to Expel, the attacker sent phishing email to 4,800 other users at the university after compromising a student account.
- 40 recipients clicked the phishing link in the, icked the phishing link in the campaign.
- Q2 2025, ng to Expel’s Quarterly Threat Report for Q2 2025, identity-based attacks make up about two thirds of the incidents its SOC sees.
Questions worth separating out
Q: What breaks when a phishing victim account is used to send internal email at scale?
A: The trust boundary breaks first.
Q: Why do mailbox rules make phishing incidents harder to contain?
A: Mailbox rules can hide replies, security warnings, and evidence of attacker activity while leaving the account technically usable.
Q: How do security teams know if internal phishing is spreading beyond the first account?
A: Look for shared subjects, repeated sender patterns, rapid sign-in changes, and multiple recipients clicking the same lure across a short period.
Practitioner guidance
- Correlate sign-ins with outbound mail volume Build detections that link a new login, unusual IP geography, and sudden high-volume internal messaging from the same account.
- Review mailbox rules after suspicious access Automatically inspect inbox rules, forwarding settings, and delete actions for any account that has a risky sign-in or phishing interaction.
- Restrict broad-send privileges to trusted identities Limit the ability to email large recipient sets to approved mailing lists and trusted service accounts, and monitor for bulk sends outside those channels.
What's in the full article
Expel's full analysis covers the operational detail this post intentionally leaves for the source:
- Timeline detail on how the first compromised account was identified and traced through campus logins
- Investigation specifics on the suspicious inbox rule and the IP pivot used to map related accounts
- Containment actions taken against interacted accounts, malicious domains, and the phishing messages themselves
👉 Read Expel's analysis of the university phishing campaign and account abuse chain →
Phishing account takeovers: why one login can expose the whole campus?
Explore further
Compromised identity becomes a distribution layer when mailbox controls are weak. This case shows that phishing is not just about stolen credentials, it is about what the attacker can do after the first login. When mailbox access, inbox rules, and bulk-send capability are not governed as part of identity risk, one account becomes an amplification point. Practitioners should treat message-sending rights and mailbox automation as identity controls, not merely email hygiene.
A few things that frame the scale:
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to the Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which helps explain how identity abuse can persist unnoticed in large environments.
A question worth separating out:
Q: Who is accountable when phishing leads to account compromise?
A: Accountability is shared, but security leadership owns the control environment that made impersonation succeed. Email authentication, browser trust configuration, access scoping, and incident reporting are governance responsibilities, not just end-user habits. If phishing can repeatedly turn into compromise, the control model is failing at the organisational level.
👉 Read our full editorial: Phishing account takeovers can cascade into campus-wide email abuse