Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› What are the most common mailbox persistence techniques…
Threats, Abuse & Incident Response

What are the most common mailbox persistence techniques used in business email compromise attacks?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 30, 2026 Domain: Threats, Abuse & Incident Response

The most common techniques are malicious mail rules, external auto-forwarding, and subtle mailbox setting changes that preserve attacker access after phishing. These controls let attackers hide messages, redirect alerts, and intercept ongoing conversations without repeatedly logging in. Effective defence depends on detecting configuration drift in the mailbox, not only blocking initial credential theft.

Why mailbox persistence is the real BEC problem

business email compromise is not just about getting into a mailbox once. The attacker’s advantage comes from staying there long enough to read thread context, watch payment timing, and quietly shape replies. Mailbox persistence techniques are attractive because they survive password resets, let the attacker remain invisible to the victim, and turn a one-time phish into ongoing access.

The most common persistence methods are configuration changes that do not look like obvious malware: rules that delete or redirect messages, forwarding settings that send mail outside the organisation, and subtle mailbox changes that preserve access while reducing user visibility. The practical challenge is that these are ordinary administrator features being abused as attacker infrastructure.

That is why detection has to focus on the mailbox state itself, not only on login events. A clean sign-in history does not prove a mailbox is clean if rules, forwarding, delegated access, or recovery settings have already been altered.

How malicious rules and forwarding keep the attacker in the loop

Inbox rules are the most familiar persistence technique because they are easy to automate and easy to hide. Attackers commonly create rules that move security alerts, replies from finance, or conversation updates into archive, RSS, deleted items, or a low-visibility folder. Others filter specific sender names or subjects so the victim never sees the messages that would expose the compromise.

External auto-forwarding is equally useful to an attacker because it copies the conversation stream off-platform. Even when the attacker loses the original login, forwarded mail can still disclose invoice threads, internal approvals, and password resets. In practice, forwarding is often the control that converts mailbox compromise into broader business fraud.

More subtle changes can be just as valuable. Attackers may alter reply-to behaviour, set delegate access, change recovery details, or add a mail client connection that keeps the account reachable without triggering the same user suspicion as an interactive login. The persistence value is in reducing friction, not in sophistication.

What defenders should look for in mailbox drift

The useful security question is not “did someone log in?” but “what changed in the mailbox after access was obtained?” That means looking for new rules, hidden forwarding destinations, unexpected delegation, mailbox permission changes, and modifications to notification or recovery settings. A mailbox can be compromised while still appearing technically functional to the user.

For practitioners, the key control idea is configuration drift monitoring. Baseline the mailbox state, compare it to current settings, and alert on changes that have no business justification. This is especially important where finance, executive assistants, shared inboxes, or external-facing roles are involved, because those mailboxes are disproportionately useful for fraud and conversation hijacking.

One Email Identity and BEC Guide covers the mailbox takeover patterns that matter here, including inbox rules, OAuth mail permissions, and payment-verification controls. For incident context, The 52 NHI Breaches Report is useful because it shows how credential and access abuse often becomes persistence, not just initial compromise. If the compromise path involved stolen credentials or reused access, TruffleNet stolen AWS keys campaign 2025 is a relevant example of how stolen access can be operationalised into ongoing fraud.

Risk and Threat Considerations

Mailbox persistence is high-risk because it turns a single credential theft into sustained visibility over business workflows. The attacker can suppress alerts, observe payment conversations, and choose the right moment to impersonate a trusted party, which makes the compromise harder to notice than a simple account lockout or login anomaly.

Failure mechanism: The attacker changes mailbox settings that control message routing or visibility, so detection tools and users continue to see a normal account while critical messages are silently diverted, deleted, or forwarded.

Impact: The organisation may lose integrity of email-based approvals, invoice handling, and password-reset flows, creating repeat fraud opportunities even after the initial phishing event is remediated.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and OWASP ASVS set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AU-2 — Event LoggingMailbox persistence depends on visible setting changes and account activity.
AU-6 — Audit Record Review, Analysis, and ReportingDetect suspicious mailbox drift by reviewing changes and alerts.
AC-6 — Least PrivilegeReduces the blast radius of mailbox delegation and permission abuse.
Recommendation — Log mailbox rule, forwarding, and permission changes for review. Review mailbox audit events for unauthorized rule and forwarding changes. Restrict mailbox permissions to the minimum required access.
OWASP ASVSV7 — Session ManagementPersisted mailbox access often outlives the original authenticated session.
Recommendation — Invalidate sessions after compromise and verify session revocation.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingMailbox persistence often relies on access that was never fully removed.
Recommendation — Remove stale mailbox access paths and revoke unused connections.

Practitioner Guidance

What to prioritise: Treat mailbox settings as part of the incident scope. If you only reset the password and revoke sessions, the attacker may still retain effective access through rules, forwarding, or delegated permissions.

What to verify: Check the mailbox for newly created rules, hidden forwarding addresses, permission grants, transport changes, and recovery-setting edits. Compare current configuration to a known-good baseline rather than relying on user assurance.

Common mistake: Teams often assume that “no active login” means “no ongoing compromise”. For mailbox persistence, the more important question is whether the account can still move or conceal mail without fresh authentication.

Practitioner takeaway: The right defence is mailbox-state monitoring plus rapid rollback of unauthorized changes, because BEC persistence is usually a configuration abuse problem before it is a login problem.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org