Forwarding rules turn a compromised or abused mailbox into a passive data pump, which means the attacker does not need to stay interactive. Once forwarding is set at the mailbox or transport layer, sensitive mail can leave continuously with little user-visible disruption. That is why rule changes should be treated as persistence signals.
Why forwarding rules turn mailbox compromise into a silent exfiltration path
Mailbox forwarding rules matter because they convert access into flow. Once an attacker can create or change a rule, the mailbox can keep copying mail out without repeated logins, making the compromise harder to notice and extending the time window for theft. In BEC, that passive collection is often more valuable than a one-time mailbox read.
At the mailbox layer, forwarding can be obvious, but transport rules and hidden redirect paths are often less visible to the end user. That is why rule-based exfiltration is often associated with persistence, not just convenience: the attacker is trying to make data movement survive beyond the initial intrusion.
Forwarding also changes the economics of the attack. The adversary no longer needs to keep interacting with the inbox or stay online during business hours, and sensitive messages such as invoices, payment instructions, thread context, and attachments can continue to leave the environment with little disruption to the victim.
Why BEC attackers prefer forwarding over simple mailbox reading
BEC is not only about impersonation, it is about access to business communications that can be monetised. Forwarding rules help attackers harvest exactly the material that makes follow-on fraud easier: payment timing, vendor names, approval chains, and subtle language that supports invoice redirection or urgent payment requests.
That matters because the attacker gains both visibility and patience. They can monitor a mailbox quietly, learn internal patterns, and use the same stream of correspondence to choose the best moment for fraud. A rule that copies mail externally creates a low-friction exfiltration channel that is difficult to distinguish from ordinary mailbox activity if monitoring is weak.
For defenders, the key point is that rule changes often indicate more than access abuse. They can reflect credential compromise, session hijacking, OAuth abuse, or malicious insider activity, and the forwarding configuration itself can outlast the initial access path if it is not removed.
What makes forwarding rules especially dangerous operationally
Forwarding rules are dangerous because they can be created quickly, are easy to overlook during an incident, and can keep leaking data until someone inspects the mailbox configuration. The control failure is not just theft of one message, but sustained disclosure of everything matching the rule criteria.
That is why mailbox and transport-layer rule changes should be treated as a high-signal security event. In many BEC cases, the attacker is exploiting a trusted business channel rather than breaking encryption or forcing malware delivery, which means the exfiltration path can look like normal mail flow unless the organisation monitors mailbox-level change activity.
Defenders should also remember that forwarding rules can be selective. An attacker may forward only messages containing finance keywords, threads from specific executives, or messages from external banking and payroll contacts, which reduces noise and lowers the chance of detection by the mailbox owner.
Risk and Threat Considerations
Mailbox forwarding creates a durable exfiltration channel because it can continue after the initial compromise, even when the attacker no longer has active access to the account. In BEC, that persistence increases the chance that sensitive correspondence, payment details, and negotiation context will be siphoned out over time.
Failure mechanism: The attacker abuses mailbox or transport rule creation to duplicate or redirect messages to an external destination, then relies on the rule to keep pulling data after the session, password, or token that enabled it has changed.
Impact: The organisation can lose confidentiality without an obvious service outage, while the attacker gains ongoing insight into business processes and more opportunities for invoice fraud, impersonation, or lateral abuse of trust.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | Forwarding rules can expose sensitive mail continuously, creating a disclosure path tied to stolen access. |
| Recommendation — Monitor mailbox rule changes and remove forwarding paths that disclose sensitive messages externally. | ||
| NIST SP 800-53 Rev 5 | AU-12 — Audit Record Generation | Mailbox rule changes and forwarding events need auditable records for detection and response. |
| IA-5 — Authenticator Management | BEC exfiltration via forwarding often follows compromised credentials or tokens that enabled the rule change. | |
| Recommendation — Log mailbox rule creation and modification events for investigation and alerting. Rotate compromised credentials and revoke tokens before restoring mailbox access. | ||
| MITRE ATT&CK | T1114 — Email Collection | Forwarding rules are a common mechanism for collecting mail at scale after mailbox access is obtained. |
| Recommendation — Map mailbox forwarding activity to email collection detections and hunt for related exfiltration paths. | ||
| NIST CSF 2.0 | DE.CM-01 — Monitoring for anomalies and events | Rule changes and unusual forwarding destinations are anomalous events that warrant monitoring. |
| Recommendation — Alert on mailbox configuration changes and unusual external forwarding destinations. | ||
Practitioner Guidance
What to verify: Treat any newly created or modified forwarding, inbox, or transport rule as a security-relevant change, and verify who made it, from where, and whether the destination is internal, external, or hidden behind a delegate path. Correlate the rule change with login anomalies and message access patterns before assuming it is benign.
What good looks like: High-confidence mailbox monitoring should surface rule creation, rule edits, and external forwarding destinations quickly enough that responders can remove the rule before a large volume of mail leaves the environment. If you cannot identify rule changes in near real time, exfiltration can continue too long to be operationally useful to defenders.
Practitioner takeaway: In BEC, the forwarding rule is often the theft mechanism, not just a by-product of compromise, so incident response should prioritise stopping mail flow as well as resetting access.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org