Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› What are the signs that a compromised account…
Threats, Abuse & Incident Response

What are the signs that a compromised account is still active?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Threats, Abuse & Incident Response

Look for unusual login geography, atypical device use, repeated mailbox forwarding changes, abnormal reset requests, and activity outside the account’s usual business pattern. The most important signal is not a single alert but a cluster of identity and behavioural anomalies that shows the account is being used in ways the real user would not sustain. That is where containment decisions should start.

How to read the warning pattern

A compromised account is often still active when the attacker is using it just enough to avoid obvious disruption. The clearest clue is not one event but a pattern: logins from unfamiliar places or devices, repeated changes to forwarding or recovery settings, and account activity that does not match the user’s normal business rhythm. That combination suggests live use, not just stale compromise.

The practical distinction is between a one-time intrusion and an account that remains under someone else’s control. If you keep seeing authentication events, mailbox rule edits, password-reset attempts, or other behaviour after the first alert, treat the account as an active access path and assume the attacker is testing how much time they still have.

What activity patterns usually expose ongoing compromise?

Ongoing compromise tends to show up as behaviour that is technically valid but operationally odd. A user may still be able to sign in, yet the access comes from a new country, an unusual IP range, a different browser profile, or a device that was never enrolled by the real user. In email and collaboration platforms, mailbox forwarding, inbox rule creation, deleted security notifications, and suspicious consent or delegation changes are especially important because they let an attacker persist without repeated logins.

Reset requests and account recovery changes are another strong signal because they often indicate the adversary is trying to lock in control. Watch for repeated MFA prompts, unfamiliar authenticator enrollment, password changes shortly after login, and access outside the usual time window. These signs matter most when they appear together, because a single anomaly can be noise, but several aligned anomalies usually indicate an actor who is still operating inside the account.

When does the behaviour become a containment decision?

The threshold is crossed when the anomalies explain each other. If the login geography, device fingerprint, forwarding behaviour, and business-pattern drift all point in the same direction, the account should be treated as active compromise rather than a benign anomaly. At that point, the question is no longer whether something happened, but whether the attacker still has a path to persistence, data access, or lateral movement through the account.

That matters because compromised accounts are often used quietly first. An attacker may read mail, wait for a payment or reset opportunity, search for privileged contacts, or use the account as a trusted relay. If the account still has functioning sessions, tokens, delegated access, or rule-based forwarding, containment has to focus on cutting those paths quickly, not just resetting the password and hoping the issue ends.

Risk and Threat Considerations

A compromised account that remains active is a live trust problem, not a historical incident. The main risk is that the attacker can continue using legitimate access to avoid detection, retain persistence, and expand to adjacent systems through inboxes, sessions, or approval workflows.

Failure mechanism: The defender sees isolated alerts, but the attacker keeps valid access through a session, token, forwarding rule, or repeated recovery attempt, allowing continued use without obvious lockout.

Impact: Persistent access can lead to mailbox abuse, data theft, fraudulent requests, privilege escalation, and secondary compromise of people or systems that trust the account.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Covers suspicious sign-in behaviour and account takeover for user accounts.
AU-6 — Audit Review, Analysis, and ReportingSupports detecting clustered anomalies across logins, rules, and reset attempts.
AC-2 — Account ManagementAddresses ongoing account control, revocation, and disabling after compromise signals.
Recommendation — Enforce stronger user authentication and review anomalous sign-in activity immediately. Correlate authentication, mailbox, and recovery events to confirm active compromise. Disable or restrict accounts and remove persistence paths when compromise is suspected.
NIST CSF 2.0DE.CM-09 — Monitoring for unauthorized personnel, connections, devices, and softwareApplies to detecting unusual device and connection patterns tied to active compromise.
Recommendation — Monitor for anomalous devices, locations, and sessions associated with compromised accounts.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingRelevant when attacker persistence survives because access is not fully removed.
NHI-07 — Long-Lived SecretsApplies when stolen credentials or tokens let an account remain active after compromise.
Recommendation — Remove all active sessions, tokens, and recovery paths when an account is no longer trusted. Rotate or revoke secrets and tokens that could keep the account usable to an attacker.

Practitioner Guidance

What to verify: Confirm whether the suspicious activity is clustered around a live sign-in path, active session, or persistent mail rule. If the account still generates successful logins, rule changes, or reset activity after the first alert, assume the compromise is ongoing until proven otherwise.

Decision rule: If you can explain the activity as a one-off anomaly, investigate; if you cannot explain the pattern as user-normal behaviour, isolate the account, revoke sessions, remove forwarding and delegation, and force credential reissue before returning access.

Practitioner takeaway: Treat repeatable behavioural anomalies as the signal that matters most, because active compromise is usually revealed by persistence patterns, not by a single suspicious login.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org