Inside The Inbox: What Recent BEC Incidents Tell Us About Modern Account Compromise
Expert: Joss Moor
Role: SOC Analyst
Specialises in: Security Operations
Business Email Compromise: A Quick Refresher
Business Email Compromise has become a commonplace tactic for threat actors, first formalised in 2013 when the FBI formally began tracking BEC as an emerging financial cyber threat.
Since then, the practice has only grown in popularity and sophistication, moving from the CEO impersonation commonly associated with early BEC campaigns towards compromising genuine business mailboxes. This access allows threat actors to monitor conversations, manipulate legitimate payment processes and target additional victims while appearing to be a trusted sender.
BEC looks like mail from a sender you have a history with, a third party you rely on, or a client you’ve worked with before. The catch is that the person behind the email isn’t really them. Yes, it came from their usual email address. Yes, it wasn’t blocked at the door by your usual phishing or spam policies. And yes, the signature you see seems familiar.
This email may not seem so conspicuous as you quickly work through your inbox without giving it a second thought, but within it there is a lure designed to compromise your mailbox and use that access against you, your company, and your contacts.
This lure might look like a shared document or an invoice. It might be hidden within an attached PDF or behind a QR code waiting to be scanned. What these lures have in common, and what makes them effective, is familiarity and routine. They are built to fit into the usual flow of your inbox and fool you just long enough to secure that click.
Behind the lure is an attacker-controlled sign-in flow, acting as a middleman between the victim and the legitimate service. The victim signs in and completes MFA as normal, but the authenticated session returned by the service can be captured by the threat actor and reused to gain access to the account.
What We’re Seeing in Recent BEC Investigations
The phishing remains familiar, but the lures continue to improve. Ultimately, they all aim to achieve the same thing: convincing a victim to hand over access to their mailbox. The vector might change too; it might be a Teams call from someone with support in their display name asking you to log into a malicious portal.
What’s evolving is the post-compromise playbook – a common thread in recent incidents is the use of mailbox rules to keep the victim in the dark.
These rules often center around hiding incoming mail to keep the victim unaware of the breach. These rules look to:
- Mark incoming messages as read
- Move messages into Archive or another folder
- Delete specific messages
- Hide replies relating to phishing emails the attacker has sent
This covert approach is an effort to continue the chain of mailbox breaches, ultimately leading to financial gain for the threat actor. Microsoft discusses how AiTM phishing and mailbox abuse combine to support modern BEC campaigns in their recent article on the resurgence of BEC
Perhaps equally notable is what we don’t see. Across the incidents reviewed for this article, overt changes to compromised accounts, such as password resets or the registration of additional MFA methods, were uncommon. Instead, attackers focused on the mailbox itself, avoiding unnecessary changes that might draw attention to the compromise.
This reflects a broader trend in modern BEC: attackers prioritise stealth over disruption. A small number of carefully chosen actions can conceal their activity, exploit existing business relationships and turn one trusted identity into a route to the next victim.
Who Is Being Targeted?
BEC is not reserved for large enterprises or multinational organisations. In line with the inconspicuous approach outlined above, even small organisations can be the victim of BEC.
The hook for threat actors is the relationships and processes sat behind the victim’s mailbox. An account that regularly communicates with suppliers, customers or partner organisations provides a threat actor with an established network of trust to exploit.
Finance teams and senior executives may represent obvious targets, but any mailbox with access to valuable information or trusted external relationships can provide an attacker with an opportunity. Once compromised, that trust can be exploited for payment fraud or used to place the next lure in someone’s inbox.
What Should Defenders Look For?
Signs of Suspicious Authentication
Identity telemetry often gives the first indication that something isn’t right, however as we’ve already noted defenders shouldn’t expect every compromise to result in obvious changes to the account. MFA additions or password modifications are not always present.
Keep an eye out for:
- Risky user or risky sign-in detections
- Authentication from previously unseen infrastructure or locations, VPNs or Proxies
- Unusual session behaviour
- Authentication occurring outside of the user’s normal pattern
- Suspicious MFA/authentication-method changes
Mailbox Changes
Once an identity is suspected of compromise, turning to the mailbox is the smart next step. The creation or modification of inbox rules, particularly those configured to delete messages, mark them as read, move them into less-visible folders or forward them externally should warrant investigation.
Changes in Email Behaviour
The final piece is what the mailbox starts doing.
Look for:
- Sudden increases in outbound emails
- Large numbers of external recipients
- Recipients the user doesn’t normally communicate with
- Similar messages being sent to many contacts
- Phishing URLs or attachments being distributed from the mailbox
- Unusual replies/deletions around those messages
The primary detection opportunity comes from joining these signals together. A mailbox rule on its own may be completely legitimate, as might an unusual sign-in. Linking a risky login to a new inbox rule and abnormal outbound email activity paints a much clearer picture of a BEC compromise.
Reducing the Risk of BEC
Strengthen Identity and Access Controls
Organisations should move towards phishing-resistant authentication and consider Conditional Access controls so that access is only granted to trusted, compliant devices. Together, these controls significantly raise the barrier for threat actors attempting to turn stolen credentials or sessions into abusable access.
Limit and Monitor Mailbox Abuse
Mailbox functionality available to legitimate users can also provide useful tools to an attacker. Automatic external forwarding should be restricted where it is not operationally required, while the creation or modification of mailbox rules should be closely monitored.
Rules that delete emails, mark them as read, move them to less visible folders or forward them externally are particularly important when observed alongside other indicators of compromise.
Detect the Compromise that Gets Through
No preventative control is infallible, so organisations must also be prepared to detect the compromise that gets through. Monitoring identity, mailbox and outbound email activity together can expose the sequence of behaviours that follows successful account compromise, even where no single event provides definitive evidence on its own. In many cases, it is the combination of these subtle indicators, rather than any single alert, that reveals a BEC compromise.
Final Thoughts
Modern BEC attacks don’t always leave obvious signs behind. Instead, they often rely on subtle mailbox activity, trusted relationships and small changes that can be easy to miss when viewed in isolation.
If you’d like to understand how your organisation can better detect and respond to account compromise, speak to our team of cyber security experts.










