Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› How should security teams detect cyber espionage campaigns…
Threats, Abuse & Incident Response

How should security teams detect cyber espionage campaigns that are hunting for merger and acquisition information in corporate email systems?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Threats, Abuse & Incident Response

Security teams should treat M and A targeting as an email and identity monitoring problem, not just a malware problem. Prioritise unusual access to Microsoft Exchange and Microsoft 365 mailboxes, especially executive and IT accounts, and watch for broad searches across mail systems for transaction terms. Network logging matters because long dwell times often show up first as abnormal traffic, mailbox access, or persistence rather than obvious exfiltration.

How to spot espionage that is searching for deal data in email

Look for behaviour that resembles structured collection, not a single noisy intrusion. In merger and acquisition campaigns, attackers often enumerate high-value mailboxes, then search across mailstores for transaction terms, code names, adviser names, board material, diligence phrases, and draft announcements. The signal is often a combination of mailbox access, search volume, unusual timing, and persistence.

For defenders, that means treating email telemetry as an investigation source in its own right. Review access patterns for executive, legal, finance, M&A, and IT accounts, then compare them with the user’s normal mailbox behaviour. A quiet account that suddenly performs broad searches, opens many historical threads, or accesses multiple mailboxes in a short window deserves attention even if no attachment detonation or malware alert appears.

Anthropic GTG-1002 AI espionage campaign is a useful reminder that espionage tradecraft is increasingly fast, automated, and credential-driven, which makes mailbox access patterns and search activity more important than any single malicious email.

Why identity and email telemetry need to be analysed together

Deal-hunting campaigns usually depend on valid access, stolen sessions, or abused delegated access because that lets the attacker blend into normal collaboration traffic. Security teams should therefore correlate email events with identity signals such as impossible travel, anomalous sign-ins, new forwarding rules, token reuse, suspicious OAuth consent, mailbox delegation changes, and access from unfamiliar networks or devices.

Microsoft Exchange and Microsoft 365 deserve particular attention because they concentrate the conversations, calendars, attachments, and internal threads that reveal transaction status. An investigation should look for account use that spans both web and API access, since adversaries often move through whatever path gives them the quietest read-only visibility. The best detections join identity context, mailbox query behaviour, and downstream network or cloud logs so a campaign can be seen as a chain, not a one-off event.

CISA cyber threat advisories provide current threat context for state-linked and espionage activity, while MITRE ATT&CK Enterprise Matrix helps teams map mailbox-focused activity to credential access, persistence, and lateral movement techniques.

The 52 NHI Breaches Report is also relevant because many real campaigns use stolen secrets, service access, or other machine-mediated paths to reach the mailbox layer quietly.

What to prioritise in detections and investigation

Start with the assets most likely to contain deal material: executive mailboxes, assistants, legal counsel, finance, corporate development, investor relations, and administrators with broad mail visibility. Then prioritise three detection buckets: unusual mailbox search and enumeration, abnormal access to many historical messages or folders, and signs that the attacker is maintaining access through persistence rather than dropping obvious malware.

Good hunting logic also separates curiosity from collection. One or two searches are not enough on their own, but repeated searches for transaction terms, unusual mailbox traversal, mass download or sync activity, and post-access actions such as forwarding-rule creation or delegate grants create a much stronger espionage picture. Network logs matter because long dwell time often shows up first as odd traffic patterns, repeated cloud mail access, or access from an environment that does not match the user’s normal work location or device.

If the same account is used to reach both email and adjacent collaboration tools, treat that as a possible expansion path. The campaign may be using email as the discovery layer and then pivoting into shared drives, calendars, chat, or document systems to assemble the broader deal picture.

Risk and Threat Considerations

Espionage campaigns that hunt M&A information are dangerous because they target data with direct business value, and they often do it through legitimate access paths that look normal at first glance. The main risk is not just exfiltration, but silent collection over time, where an attacker can map relationships, timing, and negotiation intent before the organisation notices.

Failure mechanism: access is obtained through a trusted mailbox or session, then the attacker uses search, folder traversal, forwarding, or delegated access to harvest material that blends into ordinary user activity. Because the activity is low and slow, defenders may miss it if they rely on attachment scanning or a single alert source.

Impact: compromise can expose deal strategy, valuation assumptions, bid timing, counterparty names, and internal decision making, which can create legal, financial, and reputational damage long before the organisation confirms data theft.

Anthropic’s first AI-orchestrated cyber espionage campaign report is a strong external reference for how modern espionage can combine reconnaissance, credential abuse, and exfiltration at speed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKTA0006 — Credential AccessMailbox espionage commonly depends on stolen or abused access.
TA0008 — Lateral MovementAttackers often pivot from one trusted mailbox or account into others.
Recommendation — Map mailbox abuse to credential-access techniques and hunt for stolen-session indicators. Correlate mailbox anomalies with pivots into adjacent accounts and services.
NIST CSF 2.0DE.CM-03 — Continuous MonitoringThe question is about detecting abnormal email and identity activity.
DE.AE-01 — Anomalies and Events are Detected and AnalyzedDefenders must distinguish normal mail use from suspicious collection behavior.
Recommendation — Monitor mail, identity, and network telemetry for anomalous access and search patterns. Tune detections for abnormal mailbox search, traversal, and persistence patterns.
NIST SP 800-53 Rev 5AU-6 — Audit Record Review, Analysis, and ReportingDetection depends on analyzing mailbox and sign-in audit records.
AC-6 — Least PrivilegeExcessive mailbox visibility increases espionage blast radius.
Recommendation — Review audit trails for search bursts, unusual access, and delegation changes. Restrict mailbox and delegation access to the minimum needed for the role.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIMailbox and service access paths can be abused when privileges are too broad.
Recommendation — Reduce mailbox and service privileges that let one account enumerate too much data.

Practitioner Guidance

What to verify: confirm whether the mailbox activity matches the account’s historical baseline for search volume, access times, folder depth, and cross-mailbox reach. If a privileged or executive mailbox suddenly behaves like a discovery tool, treat that as a higher-priority investigation than a noisy but contained phishing event.

Decision rule: if you can tie the mailbox activity to transaction terms, unusual sign-in context, or persistence actions such as forwarding rules and delegation changes, escalate as suspected espionage rather than generic account misuse. If you cannot yet prove theft, still preserve logs and isolate the identity path, because the collection phase is often the earliest stable detection point.

What good looks like: detections are correlated across identity, mailbox, and network layers, and analysts can explain why the access was unusual, what was searched, and which accounts or mailboxes were exposed. That combination is what turns a vague suspicion into a defensible incident judgment.

Practitioner takeaway: For M&A hunting, the highest-value clue is usually not a malicious payload, but the pattern of access, search, and persistence around the most sensitive mailboxes.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org