Common signs include a new MFA device registration, login activity from an unusual operating system, ISP, or location, and suspicious mailbox rule changes such as filters for specific keywords. When these signals appear together after a session hijack or info-stealer event, they strongly indicate post-compromise activity and should trigger immediate containment.
Why non-email credential theft often shows up first in the account, not the inbox
When an attacker gets in through a stolen session token, browser cookie, API key, password dump, or info-stealer, the account itself often changes before the victim notices a loss of data. That means the earliest evidence is usually behavioural and configuration drift: new trusted devices, new authentication methods, unfamiliar login properties, or account rules that help the intruder stay hidden.
Look for changes that an ordinary user would not make in the same time window. A newly enrolled MFA device, a fresh recovery method, or a login that arrives from a different operating system, ISP, or geography than the account’s normal pattern is a strong signal that the attacker is operating with valid credentials rather than guessing them. For broader identity-hygiene context, NHIMG’s Ultimate Guide to NHIs is useful on credential lifecycle and visibility, even though the compromise pattern here is user-account focused.
Mailbox rule manipulation is another high-value indicator because it shows post-authentication control, not just logon success. Filters that auto-delete security alerts, forward messages externally, or sort specific keywords into hidden folders are common follow-on activity after credential theft, and they matter more when they appear after a session hijack or known info-stealer event. In practice, this is the kind of drift that turns a one-time intrusion into persistent access.
What makes these indicators trustworthy, and what they do not prove on their own
No single sign proves compromise in isolation. A travel login may be legitimate, a new MFA device may be part of a planned enrolment, and mailbox rules can be created for benign productivity reasons. The key is correlation: multiple anomalies together, especially when they align in time with token theft, phishing follow-through, malware on the endpoint, or impossible travel from a new environment, are far more diagnostic than any single event.
The most reliable signals are those that reflect attacker control of the account state, not just account access. A password change alone may occur after the user has already regained control; by contrast, hidden inbox rules, persistent forwarding, token refreshes from unusual devices, and newly trusted sessions show that the attacker is maintaining access. 52 NHI Breaches Analysis is a useful incident lens for understanding how compromised credentials are typically chained into lateral movement and persistence, and Cisco Active Directory credentials breach is a concrete example of credentials being used beyond the original point of compromise.
Security teams should also avoid overfitting to mailbox-only symptoms. Non-email credential theft often affects web apps, VPNs, cloud consoles, and collaboration tools first, so the same compromise may surface as new OAuth grants, unusual API activity, or session reuse without any obvious inbox change. The investigation should therefore test the broader account and session history, not just the mail client.
Containment decisions that follow once the pattern is credible
Once the signs line up, treat the account as actively compromised until proven otherwise. Revoke active sessions, remove unauthorized MFA devices, reset secrets or passwords where they still matter, and inspect related account settings for persistence paths such as forwarding, delegation, app consent, or recovery changes. If the compromise likely began with malware or a stolen browser session, the endpoint must be investigated as part of the same incident, not as a separate hygiene task.
Speed matters because attacker dwell time after credential exposure is often short. NHIMG’s research on exposed AWS credentials shows access attempts can begin within 17 minutes on average, and as quickly as 9 minutes in some cases, which is a good reminder that notification without immediate containment is usually too slow for live theft scenarios. If you need a defender-oriented reference for this class of activity, LLMjacking: How Attackers Hijack AI Using Compromised NHIs and JumpCloud Breach both show how stolen credentials are converted into downstream abuse.
If the suspicious activity includes forwarding, rule changes, or repeated logins from a new device, treat the account as a pivot point, not a single-user problem. The immediate question is whether the attacker can still authenticate, refresh, or re-establish access elsewhere.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Secrets and Credential Management | Stolen credentials and session material drive this compromise pattern. |
| NHI-04 — Authentication and Session Security | Unusual MFA, device, and session changes are core compromise indicators. | |
| NHI-06 — Visibility and Discovery | Detection depends on spotting abnormal account, device, and login drift. | |
| Recommendation — Rotate exposed secrets quickly and remove long-lived credential exposure paths. Review session and authenticator changes for unauthorized persistence and revoke them. Increase identity telemetry coverage so anomalous logins and rule changes are visible. | ||
| CIS Controls v8 | 5 — Account Management | Compromised accounts require rapid revocation of access and trust changes. |
| 6 — Access Control Management | Mailbox rules, forwarding, and session persistence reflect access-control abuse. | |
| 8 — Audit Log Management | Login context, MFA enrolment, and rule changes are log-based compromise signals. | |
| Recommendation — Enforce prompt account and authenticator review when suspicious access appears. Tighten access paths that allow unauthorized forwarding, delegation, or session reuse. Retain and correlate authentication and mailbox-change logs for incident triage. | ||
| MITRE ATT&CK | T1078 — Valid Accounts | The scenario is an attacker using legitimate credentials or sessions. |
| T1098 — Account Manipulation | New MFA devices and mailbox rule changes are account-manipulation activity. | |
| T1114 — Email Collection | Mailbox rules and forwarding can be used to hide or redirect messages. | |
| Recommendation — Hunt for valid-account abuse across authentication, session, and access logs. Detect unauthorized account-setting changes that support persistence or evasion. Inspect mail rules and forwarding paths for covert collection or exfiltration. | ||
Practitioner Guidance
What to prioritise: Correlate identity events with session and endpoint evidence. A new MFA enrolment plus unusual login context plus inbox-rule drift is much more actionable than any one of those signals alone.
What to verify: Confirm whether the suspicious activity is tied to a known change ticket, a legitimate roaming pattern, or a managed device rollover. If you cannot tie the event to a documented user action, treat it as hostile until containment is complete.
Decision rule: If the account can still mint fresh sessions, receive MFA prompts, or forward mail externally, containment should come before forensic perfection. Preserve evidence, but do not delay revocation while you search for the original theft vector.
Practitioner takeaway: Non-email credential theft is usually exposed by account-state drift, so the winning response is to collapse attacker persistence quickly and then validate scope across every authenticated surface the account can reach.
Related resources from NHI Mgmt Group
- What are the signs that an email account has been compromised and is being used for lateral movement?
- What happens when attackers use a compromised email account to move through connected SaaS apps?
- What are the signs that an account takeover campaign is extending beyond initial credential theft?
- What are the signs that a shared application is being accessed through a compromised partner account?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org