Loading
Security

Spotting and Blocking Silent Email Redirection After a Breach

Spotting and Blocking Silent Email Redirection After a Breach

Article summary: Attackers who compromise a business email account can create malicious email forwarding rules that secretly hide, delete, or redirect important messages. These rules can expose invoices, wire instructions, and password reset emails even after the original account compromise is discovered. Regular mailbox rule reviews and tighter forwarding controls can uncover this hidden access before it leads to data theft or financial fraud.

You caught the suspicious login, changed the password, and secured the account. Problem solved, right?

Not necessarily.

An attacker may have left behind an email rule that quietly forwards messages, hides security alerts, or moves important emails where nobody will see them. Changing the password does not always remove those rules.

That means the attacker may be locked out, but your email is still working for them.

Knowing what to look for can help you catch these hidden changes before they lead to a bigger problem.

Why Silent Forwarding Rules Are So Effective

Most people picture a hacked email account as something obvious: a suspicious login, a locked account, or an urgent password reset. Malicious forwarding rules are much quieter.

Once inside a mailbox, an attacker may create a rule that automatically sends copies of certain messages to an outside account. They can target emails containing invoices, payment requests, password resets, or other valuable information.

The original break-in may be discovered and the password changed, but a hidden forwarding rule can continue sending information outside the company until someone finds and removes it. That gives attackers a quiet way to monitor communications and look for opportunities to commit fraud.

How Attackers Set Up Malicious Email Forwarding Rules

Built-in inbox rules do the work

Outlook and Microsoft 365 let users create rules that automatically sort, move, delete, forward, or redirect incoming messages.

Those features are useful for managing a busy inbox, but an attacker who compromises an account can abuse them too. A malicious rule might target certain messages and forward them elsewhere or move them into a folder where the account owner is unlikely to notice them.

Microsoft confirms that Outlook rules can automatically forward or redirect incoming email to another account.

Some rules can be difficult to spot

Attackers may deliberately configure mailbox rules to avoid drawing attention. CISA’s guidance on compromised accounts warns organizations to investigate suspicious mailbox rules as part of responding to an account compromise.

That means simply changing the password may not be enough. Existing rules and forwarding settings should also be reviewed for anything the user did not create.

Attackers can act quickly

Proofpoint research found that approximately 10% of compromised Microsoft 365 accounts it observed in the fourth quarter of 2025 had malicious mailbox rules created shortly after attackers gained access.

The researchers also found that malicious rules frequently had meaningless names and were used to delete messages or move them into rarely checked folders such as Archive or RSS Subscriptions.

That gives an attacker a quiet way to manipulate what the victim sees, similar to the techniques used in reply-chain phishing attacks.

Signs Your Mailbox Has Been Quietly Redirected

A handful of small clues tend to show up before a full loss does. Watch for:

  • An expected email, like an invoice or a client reply, never shows up
  • A folder such as Archive or RSS Subscriptions fills with mail you never sorted there
  • A colleague mentions a reply you do not remember sending
  • Your Sent folder has messages you do not recognize
  • A rule appears in your mail settings with a vague or meaningless name


None of these alone proves a breach. Together, or even one on its own after a phishing attempt, they are worth a closer look.

Locking Down Forwarding Rules for Good

Review mailbox rules regularly

Do not wait for suspicious activity to check your mailbox rules. Make rule and forwarding reviews part of your regular email security routine, especially after a suspected account compromise.

Look for rules you do not recognize, unexpected forwarding addresses, or messages being automatically moved or deleted.

Restrict external email forwarding

If employees do not need to automatically forward business email to outside accounts, consider disabling the feature.

Microsoft allows Microsoft 365 administrators to block automatic external forwarding while using other controls when legitimate forwarding is required. That can prevent a malicious inbox rule from quietly sending company email to an outside address.

Protect accounts with MFA

Preventing attackers from getting into an email account in the first place is just as important as checking what they leave behind.

CISA recommends requiring multi-factor authentication for business accounts, including email. MFA adds another barrier even if an attacker obtains an employee’s password.

As we explain in our comparison of MFA methods, some forms of MFA offer stronger protection than others. Pairing strong authentication with regular reviews of mailbox rules helps address both sides of the problem: keeping attackers out and finding suspicious changes if an account is compromised.

Not Sure What’s Hiding in Your Mailbox Rules?

A compromised email account can leave behind changes that are easy to miss, even after the password has been reset.

Sound Computers can review your team’s mailbox rules and forwarding settings, strengthen controls around external forwarding, and help monitor for suspicious email activity before it leads to a bigger security problem.

Contact Sound Computers to schedule a consultation. Call (860) 577-8060, reach us online, or email info@soundcomputers.net.


Article FAQs

What is a malicious email forwarding rule?

A malicious email rule is a rule created inside a compromised mailbox to automatically forward, hide, move, or delete certain messages. An attacker may use these rules to continue receiving information or hide activity from the

How do I check my Outlook rules for something suspicious?

Open Outlook’s Settings, select Mail, and then Rules. Review the list for rules you do not recognize, unexpected forwarding addresses, or messages being moved or deleted automatically.

If you suspect an account has been compromised, have your IT provider or administrator perform a more thorough review of the account and its email activity.

Does changing my password remove a forwarding rule?

No. Changing your password does not automatically delete mailbox rules that were already created. A malicious rule may continue forwarding, moving, or deleting messages until it is found and removed.

September 16, 2026
Tech Marketing Engine
post

Spotting and Blocking Silent Email Redirection After a Breach

Tech Marketing Engine
post
Leave a Reply
Your email address will not be published.

The reCAPTCHA verification period has expired. Please reload the page.