Look for unusual sending patterns, new forwarding rules, unexpected use from unfamiliar geographies or clients, and requests that deviate from the account's historical communications. A trusted account that suddenly pushes urgent disclosures or portal requests deserves immediate investigation.
How to recognise mailbox abuse when identity fraud is in progress
The most useful warning signs are behavioural, not just technical. A compromised mailbox often starts to look subtly out of character, for example through message timing, tone, recipient selection, or the way it requests action. The key question is whether the account is still communicating like the real owner, or whether it has become a delivery channel for impersonation and pressure.
A mailbox used for identity-driven fraud may still be authentic at the infrastructure level while being abused at the communication level. That makes the early signals valuable, because the attacker is relying on the trust already built into the account to make a request seem ordinary and urgent.
Which mailbox changes should raise immediate suspicion?
Start with changes that affect how the mailbox sends, routes, or shapes messages. New forwarding rules, unexpected delegation, replies that do not match the sender’s historical style, and sudden use from unfamiliar locations or clients all deserve attention. So do unusual bursts of outbound mail, especially when they are aimed at trusted internal contacts, suppliers, or customers.
Another strong signal is a mismatch between message content and past behaviour. If an established mailbox suddenly pushes urgent payment, disclosure, login, or portal instructions, treat that as a possible abuse pattern rather than a normal business request. The same applies when the account begins asking for exceptions, confidentiality, or fast action in a way that bypasses the usual review path.
Why these patterns matter to fraud operations
Identity-driven fraud works best when the attacker can borrow trust instead of building it from scratch. An abused official mailbox is useful because recipients tend to lower their guard when the sender is already known, appears legitimate, or sits inside an existing business relationship. That is why forwarding changes, anomalous login context, and message-content drift are not just hygiene issues, they are indicators that trust is being actively repurposed.
Mailbox abuse also tends to be iterative. Attackers often test with a few low-noise messages, then escalate once replies start arriving or forwarding rules preserve their access. For that reason, even small deviations can matter when they appear together, especially if the sender account is associated with finance, HR, executive communication, procurement, or customer onboarding.
Risk and Threat Considerations
Abused official mailboxes are dangerous because they turn a trusted identity into an impersonation platform. The risk is highest when the account can reach people who are likely to act quickly, such as finance teams, administrators, or external counterparties, and when the mailbox changes are subtle enough to survive casual review.
Failure mechanism: An attacker gains or hijacks mailbox access, adds persistence through forwarding or delegation, and then sends messages that exploit existing trust, urgency, or routine business workflows.
Impact: The result can be payment redirection, credential harvesting, data exposure, further account compromise, or wider business email compromise-style fraud across internal and external recipients.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1566 — Phishing | Mailbox abuse often delivers fraudulent requests and credential-harvesting messages. |
| T1114 — Email Collection | Abused mailboxes commonly involve forwarding, delegation, and message interception. | |
| Recommendation — Map suspicious mailbox activity to phishing tradecraft and hunt for follow-on compromise. Review mail flow rules and mailbox access for collection and persistence paths. | ||
| NIST CSF 2.0 | DE.CM-01 — Monitored Infrastructure and Software Assets | Anomalous client, geography, and sending patterns need continuous monitoring. |
| Recommendation — Monitor mailbox activity for deviations from established sender and access baselines. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Mailbox abuse is detected by reviewing rule changes, logins, and sending anomalies. |
| AC-6 — Least Privilege | Unauthorized forwarding and delegated access are access-control failures that widen abuse. | |
| Recommendation — Correlate mailbox audit logs with message and login anomalies to confirm abuse. Limit mailbox delegation and forwarding permissions to the minimum necessary. | ||
Practitioner Guidance
What to verify: Confirm whether the sending pattern, client, geography, and recipient mix fit the account’s normal history. Also check for mailbox rule changes, delegated access, and any sign that replies are being redirected or suppressed.
Decision rule: If a trusted mailbox is asking for unusual action, especially around portals, invoices, password resets, or confidentiality, treat it as suspicious until you can validate the request through an out-of-band channel.
What good looks like: The account’s communication style remains consistent, forwarding and delegation are expected and documented, and anomalous requests are caught before recipients act on them.
Practitioner takeaway: In identity fraud, the most important clue is often not a broken login, but a trusted mailbox behaving like a persuasive attacker.
Related resources from NHI Mgmt Group
- What are the warning signs that an identity recovery process is being abused?
- Why does identity matter more when vulnerabilities are discovered faster than they can be patched?
- How should teams reduce the risk of exposed AI credentials being abused?
- What is the difference between prompt injection risk and identity abuse in agents?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org