Look for new inbox rules, especially ones that move mail to junk, RSS subscriptions, or notes, delete messages, or redirect mail to an external address. Also check for new mailbox delegates, unexpected mailbox forwarding settings, and successful logins shortly after conditional access failures. Those patterns often indicate active concealment rather than routine mailbox management.
Mailbox compromise often shows up as control changes, not just suspicious reading behavior
The most useful signs are usually changes inside the mailbox itself. In a BEC case, an attacker often tries to hide messages, redirect correspondence, or preserve access after login. That means mailbox rules, forwarding, delegates, and audit context are often more revealing than a single successful sign-in.
One practical way to think about the mailbox is that it becomes a staging area once the attacker wants to suppress alerts, intercept invoices, or keep a foothold without repeatedly reauthenticating. If the compromise is active, the mailbox often reflects that intent before the broader investigation does.
Mailbox rules, forwarding, and delegate changes are the strongest behavioral indicators
New inbox rules are a classic sign, especially when they move messages to junk, RSS subscriptions, notes, or another low-visibility folder, mark mail as read, delete messages, or forward mail externally. Those rule patterns are suspicious because they reduce the chance that the victim sees conversation threads, invoice requests, or security notifications.
Also check for unexpected mailbox forwarding settings and new mailbox delegates. Forwarding to an external address can be a straightforward exfiltration path, while delegate creation can indicate the mailbox is being opened from another account or that access has been broadened for persistence. In a BEC investigation, any new automation that changes message flow should be treated as potentially attacker-controlled until proven otherwise.
It is also worth comparing current rules against the user’s normal mail habits. A rule that archives newsletters or sorts by sender is not the same as a rule that selectively hides messages from finance, payroll, or security. The more targeted the rule, the more it suggests concealment rather than convenience.
Authentication anomalies and mailbox activity help confirm whether the compromise is active
Successful logins shortly after conditional access failures are important because they suggest the attacker may have probed access, hit a control, and then found another way in. That sequence is more concerning than a single failed login because it can show persistence, iteration, or use of a different token, session, or access path.
Mailbox signs become stronger when they line up with broader identity and session anomalies, such as unusual location, unfamiliar device patterns, or access outside the user’s normal working pattern. The key is correlation: one odd event can be noise, but multiple mailbox changes close to suspicious authentication activity usually raise the confidence level materially.
For that reason, investigators should treat the mailbox and the sign-in logs as one story. If the mailbox shows rule changes or forwarding and the log shows a recent failed-then-successful access sequence, the probability of compromise is much higher than either signal alone.
Risk and Threat Considerations
Mailbox compromise in BEC is dangerous because the attacker is not just reading mail, they are trying to control the conversation. That creates exposure for payment fraud, business process manipulation, and silent interception of security or finance communications.
Failure mechanism: The attacker uses mailbox rules, forwarding, or delegate access to conceal messages and preserve access while bypassing normal user visibility and, in some cases, triggering fewer obvious alerts than a direct password change or lockout.
Impact: The organisation can lose trust in the mailbox as a reliable communication channel, miss invoice tampering or reply-chain fraud, and allow the attacker to maintain foothold long enough to expand into other accounts or systems.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1114 — Email Collection | Mailbox concealment and message interception are core email abuse patterns. |
| T1098 — Account Manipulation | New delegates and forwarding changes are mailbox access manipulations. | |
| Recommendation — Map mailbox rule abuse to email collection patterns and hunt for unauthorized message access. Investigate delegate and forwarding changes as account manipulation for persistence. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | BEC investigations depend on correlating mailbox actions with sign-in evidence. |
| AC-6 — Least Privilege | Unexpected delegates and forwarding expand access beyond normal need. | |
| Recommendation — Review mailbox and sign-in audit records together to confirm suspicious post-login changes. Remove excess mailbox delegation and forwarding paths that exceed least privilege. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Mailbox forwarding and delegates are access-path changes that require control. |
| Recommendation — Revoke unauthorized mailbox access paths and forwarding relationships quickly. | ||
Practitioner Guidance
What to prioritise: Treat new rules, external forwarding, and new delegates as higher-signal evidence than generic suspicious login noise. If those mailbox changes exist, move quickly on containment, even if the user insists nothing looks wrong from their inbox view.
What to verify: Confirm when each rule, forwarding setting, or delegate was created, what it affects, and whether it aligns with the user’s documented workflow. The important question is whether the mailbox behaviour changes message visibility or delivery in a way the user would not normally expect.
Practitioner takeaway: In a BEC investigation, the mailbox is often the attacker’s persistence layer, so the most useful judgment is whether the observed changes are hiding mail, rerouting mail, or extending access beyond what the user would normally need.
Related resources from NHI Mgmt Group
- What actions should I take if my OAuth tokens are compromised?
- Why do compromised Microsoft 365 mailboxes and nested attachments make phishing harder to detect in cloud email environments?
- Who is accountable for reducing BEC risk when attackers target Microsoft 365 users?
- What are the signs that Microsoft 365 compliance controls are failing in practice?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org