Expert Intel

Inside The Inbox: What Recent BEC Incidents Tell Us About Modern Account Compromise

Published: September 24, 2026

Expert: Joss Moor

Role: SOC Analyst

Specialises in: Security Operations

What you will learn:
Modern Business Email Compromise (BEC) attacks often rely on compromised mailboxes rather than obvious account takeovers. In this article, we'll explore the tactics observed in recent investigations, the signs defenders should look for and practical steps organisations can take to reduce risk.
“In many cases, the strongest indicator of BEC isn't a single alert, but a series of subtle signals that only become meaningful when viewed together.”

Business Email Compromise: A Quick Refresher

Business Email Compromise has become a commonplace tactic for threat actors, first formalised in 2013 when the FBI formally began tracking BEC as an emerging financial cyber threat.

Since then, the practice has only grown in popularity and sophistication, moving from the CEO impersonation commonly associated with early BEC campaigns towards compromising genuine business mailboxes. This access allows threat actors to monitor conversations, manipulate legitimate payment processes and target additional victims while appearing to be a trusted sender.

BEC looks like mail from a sender you have a history with, a third party you rely on, or a client you’ve worked with before. The catch is that the person behind the email isn’t really them. Yes, it came from their usual email address. Yes, it wasn’t blocked at the door by your usual phishing or spam policies. And yes, the signature you see seems familiar.

This email may not seem so conspicuous as you quickly work through your inbox without giving it a second thought, but within it there is a lure designed to compromise your mailbox and use that access against you, your company, and your contacts.

This lure might look like a shared document or an invoice. It might be hidden within an attached PDF or behind a QR code waiting to be scanned. What these lures have in common, and what makes them effective, is familiarity and routine. They are built to fit into the usual flow of your inbox and fool you just long enough to secure that click.

Behind the lure is an attacker-controlled sign-in flow, acting as a middleman between the victim and the legitimate service. The victim signs in and completes MFA as normal, but the authenticated session returned by the service can be captured by the threat actor and reused to gain access to the account.

Caption: A simplified example of a modern Business Email Compromise (BEC) attack chain, showing how attackers move from an initial phishing lure to mailbox access, victim concealment and further fraud or compromise.

What We’re Seeing in Recent BEC Investigations

The phishing remains familiar, but the lures continue to improve. Ultimately, they all aim to achieve the same thing: convincing a victim to hand over access to their mailbox. The vector might change too; it might be a Teams call from someone with support in their display name asking you to log into a malicious portal.

What’s evolving is the post-compromise playbook – a common thread in recent incidents is the use of mailbox rules to keep the victim in the dark.

These rules often center around hiding incoming mail to keep the victim unaware of the breach. These rules look to:

  • Mark incoming messages as read
  • Move messages into Archive or another folder
  • Delete specific messages
  • Hide replies relating to phishing emails the attacker has sent

This covert approach is an effort to continue the chain of mailbox breaches, ultimately leading to financial gain for the threat actor. Microsoft discusses how AiTM phishing and mailbox abuse combine to support modern BEC campaigns in their recent article on the resurgence of BEC

Perhaps equally notable is what we don’t see. Across the incidents reviewed for this article, overt changes to compromised accounts, such as password resets or the registration of additional MFA methods, were uncommon. Instead, attackers focused on the mailbox itself, avoiding unnecessary changes that might draw attention to the compromise.

This reflects a broader trend in modern BEC: attackers prioritise stealth over disruption. A small number of carefully chosen actions can conceal their activity, exploit existing business relationships and turn one trusted identity into a route to the next victim.

Who Is Being Targeted?

BEC is not reserved for large enterprises or multinational organisations. In line with the inconspicuous approach outlined above, even small organisations can be the victim of BEC.

The hook for threat actors is the relationships and processes sat behind the victim’s mailbox. An account that regularly communicates with suppliers, customers or partner organisations provides a threat actor with an established network of trust to exploit.

Finance teams and senior executives may represent obvious targets, but any mailbox with access to valuable information or trusted external relationships can provide an attacker with an opportunity. Once compromised, that trust can be exploited for payment fraud or used to place the next lure in someone’s inbox.

What Should Defenders Look For?

Signs of Suspicious Authentication

Identity telemetry often gives the first indication that something isn’t right, however as we’ve already noted defenders shouldn’t expect every compromise to result in obvious changes to the account. MFA additions or password modifications are not always present.

Keep an eye out for:

  • Risky user or risky sign-in detections
  • Authentication from previously unseen infrastructure or locations, VPNs or Proxies
  • Unusual session behaviour
  • Authentication occurring outside of the user’s normal pattern
  • Suspicious MFA/authentication-method changes

Mailbox Changes

Once an identity is suspected of compromise, turning to the mailbox is the smart next step. The creation or modification of inbox rules, particularly those configured to delete messages, mark them as read, move them into less-visible folders or forward them externally should warrant investigation.

Changes in Email Behaviour

The final piece is what the mailbox starts doing.

Look for:

  • Sudden increases in outbound emails
  • Large numbers of external recipients
  • Recipients the user doesn’t normally communicate with
  • Similar messages being sent to many contacts
  • Phishing URLs or attachments being distributed from the mailbox
  • Unusual replies/deletions around those messages

The primary detection opportunity comes from joining these signals together. A mailbox rule on its own may be completely legitimate, as might an unusual sign-in. Linking a risky login to a new inbox rule and abnormal outbound email activity paints a much clearer picture of a BEC compromise.

Reducing the Risk of BEC

Strengthen Identity and Access Controls

Organisations should move towards phishing-resistant authentication and consider Conditional Access controls so that access is only granted to trusted, compliant devices. Together, these controls significantly raise the barrier for threat actors attempting to turn stolen credentials or sessions into abusable access.

Limit and Monitor Mailbox Abuse

Mailbox functionality available to legitimate users can also provide useful tools to an attacker. Automatic external forwarding should be restricted where it is not operationally required, while the creation or modification of mailbox rules should be closely monitored.

Rules that delete emails, mark them as read, move them to less visible folders or forward them externally are particularly important when observed alongside other indicators of compromise.

Detect the Compromise that Gets Through

No preventative control is infallible, so organisations must also be prepared to detect the compromise that gets through. Monitoring identity, mailbox and outbound email activity together can expose the sequence of behaviours that follows successful account compromise, even where no single event provides definitive evidence on its own. In many cases, it is the combination of these subtle indicators, rather than any single alert, that reveals a BEC compromise.

Final Thoughts

Modern BEC attacks don’t always leave obvious signs behind. Instead, they often rely on subtle mailbox activity, trusted relationships and small changes that can be easy to miss when viewed in isolation.

If you’d like to understand how your organisation can better detect and respond to account compromise, speak to our team of cyber security experts.

Our latest expert Intel

  • Mesh VON Abuse Post
    September 24, 2026
    Read full article
  • Mesh VON Abuse Post
    August 26, 2026
    Read full article
  • July 19, 2026
    Read full article
  • September 3, 2026
    Read full article
  • May 13, 2026
    Read full article
  • July 9, 2026
    Read full article
  • April 14, 2026
    Read full article
  • April 10, 2026
    Read full article
  • April 2, 2026
    Read full article
  • Cyber Background
    March 24, 2026
    Read full article
  • notepad compromise
    September 3, 2026
    Read full article
  • M365
    February 3, 2026
    Read full article