Hidden Inbox Rules: How Fraudsters Hide in a Hijacked Mailbox

Business email compromise often relies on hidden mailbox rules that bury replies from real vendors. Learn the signs and how to check for them in Microsoft 365.

3 min readBy Ironfield Cyber Team

In many payment diversion cases, the attacker does not just send a fake email. They take over a real mailbox, then quietly set up rules that hide their activity. A real vendor's reply gets moved to a folder nobody looks at, while the attacker carries on the conversation. The victim sees nothing unusual because the evidence is out of sight.

Understanding this technique helps finance teams and IT staff catch compromised mailboxes earlier, often before money is lost.

How the technique works

After stealing a password, an attacker logs into an email account. Their next step is often to create inbox rules. A typical rule might:

  • Move messages containing words such as "invoice," "payment," "wire," or "bank" to an obscure folder
  • Mark messages as read automatically
  • Delete certain messages entirely
  • Forward copies of specific messages to an outside address

With those rules in place, the attacker can watch invoice conversations, wait for the right moment, and insert a change of bank details. Meanwhile the real mailbox owner may never see replies from a legitimate vendor who is confused by the request.

Signs of a hijacked mailbox

Teams should treat the following as potential warning signs.

  • A vendor says they replied to an email you never received
  • Messages appear as read when you did not read them
  • Sent items you do not remember writing
  • Colleagues receive odd messages from your account
  • Mail seems to be missing from the inbox
  • A login alert for an unfamiliar location or device
  • Rules or folders in your mailbox that you did not create

Do not dismiss these because they seem minor. Several together are a strong sign.

How to check for suspicious rules

Mailbox owners and IT staff can review rules in the mail settings. In Outlook and Microsoft 365, look for:

  1. Rules that move or delete mail based on keywords related to money
  2. Rules that forward mail to external addresses
  3. Rules with strange or blank names
  4. Folders with unusual names, such as a single letter or "RSS"

Administrators can also review mailbox forwarding settings and audit logs to see when rules were created and from where. If your IT provider offers monitoring, ask whether it alerts on new forwarding rules and rules that hide or delete mail.

What to do if you find one

  1. Do not simply delete the rule and move on. Contact IT or your provider first.
  2. Reset the account password and sign out all active sessions.
  3. Confirm MFA is enabled and review registered methods, since attackers sometimes add their own.
  4. Review recent sent items, deleted items, and the rule folders to see what the attacker saw and did.
  5. Check whether any payments or bank change requests were handled through that mailbox.
  6. Warn colleagues and, if appropriate, vendors and customers who received messages from the account.
  7. Contact your bank immediately if a payment may have been redirected.

If you believe funds were sent to a fraudulent account, time matters. The FBI's Internet Crime Complaint Center provides a way to report business email compromise, and your bank can sometimes attempt a recall when contacted quickly.

How to prevent it

  • Require MFA for every mailbox, with a stronger method than text messages where possible.
  • Block automatic forwarding to external addresses unless there is a specific business need.
  • Alert on creation of new inbox rules.
  • Use conditional access to flag sign-ins from unexpected countries.
  • Train staff to report odd mailbox behavior right away, without embarrassment.
  • Verify bank changes by calling a known number, regardless of how genuine an email looks.

A hypothetical example

Consider a hypothetical estimator at a specialty contractor whose password was stolen through a fake sign-in page. The attacker creates a rule moving any message with the word "invoice" to a hidden folder, then emails the contractor's accounts payable team from a lookalike address. The estimator's real mailbox looks normal. A monthly rule review or an alert on rule creation could expose the problem within days instead of weeks.

Make it part of routine

Add an inbox rule check to quarterly security reviews for people who handle money, such as accounts payable, payroll, executives, and project managers who approve invoices. Those mailboxes are the most valuable to attackers.

Where Ironfield Cyber helps

Ironfield Cyber helps contractors and energy companies harden Microsoft 365 against account takeover, including MFA, forwarding controls, sign-in monitoring, and alerting on suspicious rules. If you would like us to check how your mailboxes are configured, we can review them with your team.