ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Mailbox Rules and Forwarding: The Quiet Sign of a Hacked Email Account

Attackers often hide in a compromised mailbox using forwarding and inbox rules. Learn how to spot them, audit your accounts and prevent the behavior.

3 min readBy Counsel Cyber Team

When a law firm's email account is compromised, the attacker usually does not announce it. Instead, they quietly set up rules that forward copies of incoming messages, hide replies from the real owner, or delete security alerts. From there they can watch correspondence for weeks, waiting for a transaction worth redirecting. The FBI's guidance on business email compromise describes this kind of patient monitoring, and reviewing mailbox rules is a standard step in investigating a suspected incident.

This post explains what to look for and how to build defenses.

How attackers use mailbox rules

After stealing a password or session, an attacker may:

  • Create a forwarding rule that sends every message, or messages containing words like "wire," "invoice," "payment" or "closing," to an outside address.
  • Create a rule that hides messages by moving replies from certain people into obscure folders such as RSS feeds or Archive, or by marking them read, so the real user never sees them.
  • Delete security notifications, such as sign-in alerts or messages from your IT provider.
  • Set up automatic forwarding at the server level, which may not appear in the user's own rules list.
  • Add delegates or grant permissions to another account.
  • Register an application with permission to read mail, which survives a password change.

These persistence methods mean that changing a password alone may not evict the attacker.

Warning signs

Users or administrators might notice:

  1. Clients saying they replied to a message you never received
  2. Sent items you do not remember writing
  3. Messages marked read that you have not opened
  4. Unexpected folders or rules
  5. Sign-in alerts from unfamiliar locations or devices
  6. Colleagues receiving odd messages from your address
  7. A client reporting different payment instructions that look like they came from you

If a client mentions wire instructions the firm did not send, treat it as an emergency.

What to check in Microsoft 365

Details differ by tenant, but an IT administrator can generally review:

  • Inbox rules for each mailbox, including hidden rules, through PowerShell or the admin tools
  • Mailbox forwarding settings, both internal and external
  • Delegates and permissions on mailboxes
  • Connected and consented applications under enterprise apps
  • Sign-in logs, looking at unfamiliar IP addresses, countries and legacy protocols
  • Audit logs for rule creation and changes
  • Transport rules that forward or copy mail across the whole organization

Run a firm-wide review at least quarterly, and immediately after any suspected compromise.

Preventive controls

Block automatic external forwarding

Most firms have little legitimate need for users to automatically forward email outside the organization. Microsoft 365 policies can disable or restrict it. Make exceptions deliberately and review them.

Alert on new rules

Configure alerts for creation of inbox rules that forward externally or delete messages, and for new mailbox delegates. Your IT provider or managed detection service can monitor them and respond.

Enforce multi-factor authentication

Most compromised accounts lack MFA or have weak MFA. Require it for every user, disable legacy authentication protocols that bypass it, and prefer phishing-resistant methods where possible.

Use conditional access

Restrict sign-ins by location, device compliance and risk level. A user who normally signs in from Tulsa should not be able to sign in unchallenged from another continent.

Limit application consent

Prevent users from approving new applications that request access to mail without administrator review.

Train people to report oddities

Include mailbox rule examples in awareness training so staff know that unexplained behavior in their inbox is worth reporting.

If you find a malicious rule

  1. Do not just delete the rule. Preserve evidence by exporting rule details and logs first.
  2. Reset the password, revoke all sessions and tokens, and re-register MFA.
  3. Remove malicious rules, forwarding, delegates and consented apps.
  4. Search for the full scope: which messages were forwarded and to whom.
  5. Warn affected clients and parties in the open transactions by phone.
  6. Notify your bank if funds may be at risk, report to IC3 and inform your insurer.
  7. Determine how the compromise occurred and close that gap.
  8. Consider notification duties with counsel. Rule 1.4 and ABA Formal Opinion 483 are relevant starting points.

Make it routine

Add mailbox rule review to the quarterly security checklist. Many incidents that look sudden have been under way for weeks, and a routine check shortens that time.

Counsel Cyber monitors Microsoft 365 for law firms, including forwarding and rule changes, and can run a one-time review of your tenant to look for signs of past or present compromise.