A common sign is the creation of hidden mailbox rules after account takeover. Attackers may add BCC rules to copy messages externally or auto-delete alerts containing words like phishing, hack, or alert. Those changes let them monitor communications quietly and suppress warnings that could alert the victim or security team.
How to Tell When Phishing Has Turned Into Persistence
Once phishing moves past the initial inbox compromise, the signal is no longer just a stolen login, but an attacker shaping how mail is handled over time. The clearest signs are mailbox rules or forwarding actions the user did not create, especially when they hide security messages, redirect traffic outside the organisation, or quietly preserve attacker visibility after the first access event.
In practice, persistence often shows up as a change in mail flow logic rather than a new overt login. That can include stealthy inbox rules, transport rules, delegate grants, or forwarding settings that make the attacker harder to notice and easier to retain access without repeatedly re-entering the account.
Hidden rules are especially important because they can suppress the very messages that would trigger investigation. A rule that auto-deletes alerts, moves them to archive, marks them as read, or forwards sensitive conversations externally is a strong indicator that the compromise is being used for follow-on access, not just one-time spam or credential theft.
Teams should also treat unusual changes to mailbox configuration as suspicious when they appear soon after a phishing login. That includes creation of new rules, modification of existing rules, changes to aliases or forwarding destinations, and unexpected admin or delegate activity that broadens what the attacker can observe or control.
What Persistence Looks Like in Mail Systems
Mailbox persistence usually works by exploiting trust in routine email behavior. Attackers use the mailbox itself as a foothold to watch replies, intercept resets, harvest sensitive messages, and keep learning from the victim’s communication patterns. A compromised inbox can therefore become both a surveillance point and a launch point for further fraud.
The most common persistence patterns are rule-based. An attacker may add a BCC or forwarding rule to duplicate messages externally, create filters that remove words like phishing or alert, or route messages into folders the user rarely checks. Those actions reduce visibility while preserving ongoing access to conversations and recovery notices.
Persistence can also extend beyond rules into identity control. If the attacker changes password recovery options, adds a new authenticator, authorises a new session, or enrolls additional access pathways, the inbox compromise becomes harder to unwind because the attacker is no longer relying only on the original phished session.
What Security Teams Should Look For First
The first thing to verify is whether the mailbox change is intentional and user-approved. If it is not, assume the rule or forwarding action is part of the compromise until proven otherwise. Identity Threat Detection and Response (ITDR) Guide is useful here because mailbox persistence is an identity incident as much as an email problem.
Then check for related post-login activity: new sessions from unfamiliar locations, changes to mailbox settings, suspicious OAuth consents, abnormal recovery changes, and message access patterns that line up with the time the phishing credential was used. The 52 NHI Breaches Report is a useful reminder that stolen access is often followed by deliberate persistence and lateral discovery, not just immediate exfiltration.
Response should not stop at deleting the rule. If the attacker had time to observe mail flow, there may be a broader compromise of sessions, tokens, or related accounts. Review whether sensitive mail, reset links, or internal approvals were exposed during the persistence window, and whether any downstream systems trusted the mailbox after takeover.
Risk and Threat Considerations
Mailbox persistence matters because it turns a short-lived phishing event into ongoing covert access. The attacker can keep reading mail, suppress warnings, and wait for higher-value opportunities such as payment fraud, password resets, or internal impersonation.
Failure mechanism: The compromise persists when the attacker adds rules, forwarding, or recovery changes that continue to function after the original phished login is closed.
Impact: The victim may never see the warning mail, the attacker may retain visibility into sensitive conversations, and the account can become a standing platform for fraud or deeper identity compromise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5, CIS Controls v8, NIST CSF 2.0 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1114 — Email Collection | Mailbox persistence often enables covert collection of communications. |
| T1098 — Account Manipulation | Attacker-made mailbox and recovery changes are account manipulation for persistence. | |
| Recommendation — Map suspicious mailbox rules and forwarding to email collection activity and hunt for follow-on access. Review account changes and revoke attacker-added persistence paths immediately. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Mailbox rule creation and forwarding changes require reviewable audit trails. |
| IA-5 — Authenticator Management | Persistence can extend through password resets, tokens, and recovery changes. | |
| Recommendation — Correlate mailbox and sign-in logs to spot unauthorized rule creation and session abuse. Rotate affected authenticators and validate recovery settings after phishing compromise. | ||
| CIS Controls v8 | CIS-8 — Audit Log Management | Detecting hidden mailbox persistence depends on retained and reviewed activity logs. |
| Recommendation — Centralize mailbox and identity logs so suspicious rule changes are reviewable. | ||
| NIST CSF 2.0 | DE.CM-01 — Network Monitoring | Monitoring must include account and mailbox behavior to catch persistent phishing activity. |
| RS.AN-01 — Investigations | Persistent mailbox compromise requires investigation of changes, sessions, and exposure. | |
| Recommendation — Extend monitoring to mailbox rule changes and suspicious forwarding after phishing events. Investigate mailbox persistence artifacts before closing the incident. | ||
| OWASP ASVS | V16 — Security Logging and Error Handling | Alert suppression and mailbox rule changes are only visible when logging is sufficient. |
| Recommendation — Ensure security-relevant mailbox actions are logged and reviewable. | ||
Practitioner Guidance
What to verify: Inspect mailbox rules, forwarding destinations, delegate permissions, and recovery settings together. A single suspicious rule is concerning, but a cluster of quiet changes is what usually confirms persistence.
Decision rule: If the mailbox can still suppress alerts or forward messages externally, treat the account as actively compromised even if the user reports no further odd logins. The persistence mechanism is the compromise signal.
What good looks like: Administrators should be able to show who created each rule, when it was created, and whether the action was consistent with documented user behavior. If that evidence is missing, the mailbox control is not trustworthy.
Practitioner takeaway: In phishing cases, the shift from “stolen login” to “persistent compromise” is usually visible in mail-flow changes, so response should prioritise rule, forwarding, and recovery-path investigation before assuming the threat is contained.
Related resources from NHI Mgmt Group
- What are the signs that a SaaS phishing compromise has already moved beyond credential theft?
- What are the signs that a compromise has moved from exploitation to persistence?
- What are the signs that browser-based phishing controls are needed beyond inbox filtering?
- What are the signs that a phishing attack is moving beyond email into account takeover or post-compromise activity?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org