New inbox or forwarding rules
Rules that delete, archive, forward, or hide messages are a common compromise indicator.
Business email compromise, or BEC, is a practical fraud problem more than a technical spectacle. Attackers gain access to a mailbox or impersonate a trusted sender, then use normal business conversations to redirect payments, request gift cards, change banking details, or harvest confidential information.
Small businesses are attractive because payment approval is often relationship-based. A law clerk, clinic administrator, bookkeeper, or consultant may know the requester personally and want to keep work moving. The best defence combines Microsoft 365 controls with simple finance procedures that make unusual requests easier to verify.
BEC can involve full mailbox compromise, lookalike domains, display-name spoofing, or a changed reply-to address. In many cases, the message does not contain malware. It works because it fits into a real business process.
After mailbox access, attackers often search for words like invoice, payment, wire, closing, retainer, payroll, or tax. They may create forwarding rules, hide replies, and wait until the right conversation appears.
A professional office may have a small finance team, a managing partner who approves payments by email, and vendors that send invoices as PDFs. That is normal, but it creates predictable workflows attackers can study.
The impact can include misdirected funds, delayed closings, vendor disputes, client notification work, mailbox cleanup, and staff confidence issues. Even when money is recovered, the business loses time proving what happened and tightening the process.
Attackers change banking details during an active vendor or client conversation.
Rules can forward messages externally or move replies to folders users rarely check.
Messages from a real staff mailbox can bypass the healthy skepticism people apply to unknown senders.
Rules that delete, archive, forward, or hide messages are a common compromise indicator.
A message may look familiar while replies go somewhere else.
Attackers may send messages then delete traces or use rules to hide responses.
Banking detail changes should be verified through a known phone number or established out-of-band process.
MFA reduces password-only compromise, while alerts for new MFA methods help catch account takeover attempts.
Audit logs, inbox rule alerts, forwarding alerts, and suspicious sending alerts make response faster.
Verify new banking details or urgent payment changes through a known phone number, not by replying to the email thread.
Training should focus on practical moments: invoice changes, executive requests, new vendors, and unexpected secrecy.
Disable or tightly control automatic forwarding to external addresses unless there is a documented business need.
When we assess identity security, these are the specific areas we check against your actual Microsoft 365 tenant.
We check for suspicious rules, external forwarding, hidden folders, and unusual mailbox permissions.
We confirm that Microsoft 365 logging captures the events needed to investigate mailbox compromise.
We identify payment approval paths that rely only on email and recommend lightweight verification steps.
We review MFA methods, password resets, session revocation, and risky sign-in history for affected users.
We can review your Microsoft 365 sign-in posture, MFA coverage, Conditional Access policies, legacy auth exposure, admin roles, and mailbox permissions — practical and scoped to a small team.
FAQ
Microsoft 365 is a common target because email, files, Teams, and identity all meet there. The same principles apply to Google Workspace, accounting portals, CRM systems, and remote access tools.
MFA greatly reduces risk, but active session theft, phishing proxies, OAuth consent abuse, and compromised devices can still create access. That is why Conditional Access, endpoint protection, and logging matter.
Revoke sessions, reset the password and MFA methods, review inbox and forwarding rules, check sign-in logs, inspect sent mail, and preserve audit logs before cleanup.
Yes. Admin accounts should be separate from daily email accounts, protected with strong MFA, and used only for administration.