Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› What are the signs that a Microsoft 365…
Threats, Abuse & Incident Response

What are the signs that a Microsoft 365 mailbox may be compromised in a BEC investigation?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 24, 2026 Domain: Threats, Abuse & Incident Response

Look for new inbox rules, especially ones that move mail to junk, RSS subscriptions, or notes, delete messages, or redirect mail to an external address. Also check for new mailbox delegates, unexpected mailbox forwarding settings, and successful logins shortly after conditional access failures. Those patterns often indicate active concealment rather than routine mailbox management.

Mailbox compromise often shows up as control changes, not just suspicious reading behavior

The most useful signs are usually changes inside the mailbox itself. In a BEC case, an attacker often tries to hide messages, redirect correspondence, or preserve access after login. That means mailbox rules, forwarding, delegates, and audit context are often more revealing than a single successful sign-in.

One practical way to think about the mailbox is that it becomes a staging area once the attacker wants to suppress alerts, intercept invoices, or keep a foothold without repeatedly reauthenticating. If the compromise is active, the mailbox often reflects that intent before the broader investigation does.

Mailbox rules, forwarding, and delegate changes are the strongest behavioral indicators

New inbox rules are a classic sign, especially when they move messages to junk, RSS subscriptions, notes, or another low-visibility folder, mark mail as read, delete messages, or forward mail externally. Those rule patterns are suspicious because they reduce the chance that the victim sees conversation threads, invoice requests, or security notifications.

Also check for unexpected mailbox forwarding settings and new mailbox delegates. Forwarding to an external address can be a straightforward exfiltration path, while delegate creation can indicate the mailbox is being opened from another account or that access has been broadened for persistence. In a BEC investigation, any new automation that changes message flow should be treated as potentially attacker-controlled until proven otherwise.

It is also worth comparing current rules against the user’s normal mail habits. A rule that archives newsletters or sorts by sender is not the same as a rule that selectively hides messages from finance, payroll, or security. The more targeted the rule, the more it suggests concealment rather than convenience.

Authentication anomalies and mailbox activity help confirm whether the compromise is active

Successful logins shortly after conditional access failures are important because they suggest the attacker may have probed access, hit a control, and then found another way in. That sequence is more concerning than a single failed login because it can show persistence, iteration, or use of a different token, session, or access path.

Mailbox signs become stronger when they line up with broader identity and session anomalies, such as unusual location, unfamiliar device patterns, or access outside the user’s normal working pattern. The key is correlation: one odd event can be noise, but multiple mailbox changes close to suspicious authentication activity usually raise the confidence level materially.

For that reason, investigators should treat the mailbox and the sign-in logs as one story. If the mailbox shows rule changes or forwarding and the log shows a recent failed-then-successful access sequence, the probability of compromise is much higher than either signal alone.

Risk and Threat Considerations

Mailbox compromise in BEC is dangerous because the attacker is not just reading mail, they are trying to control the conversation. That creates exposure for payment fraud, business process manipulation, and silent interception of security or finance communications.

Failure mechanism: The attacker uses mailbox rules, forwarding, or delegate access to conceal messages and preserve access while bypassing normal user visibility and, in some cases, triggering fewer obvious alerts than a direct password change or lockout.

Impact: The organisation can lose trust in the mailbox as a reliable communication channel, miss invoice tampering or reply-chain fraud, and allow the attacker to maintain foothold long enough to expand into other accounts or systems.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1114 — Email CollectionMailbox concealment and message interception are core email abuse patterns.
T1098 — Account ManipulationNew delegates and forwarding changes are mailbox access manipulations.
Recommendation — Map mailbox rule abuse to email collection patterns and hunt for unauthorized message access. Investigate delegate and forwarding changes as account manipulation for persistence.
NIST SP 800-53 Rev 5AU-6 — Audit Record Review, Analysis, and ReportingBEC investigations depend on correlating mailbox actions with sign-in evidence.
AC-6 — Least PrivilegeUnexpected delegates and forwarding expand access beyond normal need.
Recommendation — Review mailbox and sign-in audit records together to confirm suspicious post-login changes. Remove excess mailbox delegation and forwarding paths that exceed least privilege.
CIS Controls v8CIS-6 — Access Control ManagementMailbox forwarding and delegates are access-path changes that require control.
Recommendation — Revoke unauthorized mailbox access paths and forwarding relationships quickly.

Practitioner Guidance

What to prioritise: Treat new rules, external forwarding, and new delegates as higher-signal evidence than generic suspicious login noise. If those mailbox changes exist, move quickly on containment, even if the user insists nothing looks wrong from their inbox view.

What to verify: Confirm when each rule, forwarding setting, or delegate was created, what it affects, and whether it aligns with the user’s documented workflow. The important question is whether the mailbox behaviour changes message visibility or delivery in a way the user would not normally expect.

Practitioner takeaway: In a BEC investigation, the mailbox is often the attacker’s persistence layer, so the most useful judgment is whether the observed changes are hiding mail, rerouting mail, or extending access beyond what the user would normally need.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org