ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX · Serving TX, AR, LA, OK & KS
(737) 325-2520

Spotting a Compromised Mailbox Before It Costs Your Firm Money

A hijacked email account often looks quiet at first. Learn the early warning signs, the first-hour response steps, and the settings that stop it from spreading.

3 min readBy Counsel Cyber Team

When a firm's email account is taken over, the first sign is rarely dramatic. There is no ransom note and no locked screen. Instead, there may be a few missing messages, a client saying they got a strange reply, or an inbox rule nobody remembers creating. Attackers who gain access to a mailbox often read quietly for days, learning who pays whom and when, before they strike.

Business email compromise is a category the FBI's Internet Crime Complaint Center has repeatedly highlighted for its financial impact. Catching a compromised account early is one of the highest-value skills a firm can build.

Warning signs

In the mailbox

  • Inbox rules the user did not create, especially ones that forward mail to outside addresses, move messages to RSS Feeds or Archive folders, or delete messages containing words like "wire," "invoice," or "payment"
  • Sent items the user does not recognize, or replies that appear to have been read and deleted
  • Contacts or distribution lists that changed
  • Unfamiliar mobile devices or apps listed as connected to the account

In sign-in activity

  • Logins from countries or cities where no one at the firm is
  • Sign-ins at odd hours
  • Multiple MFA prompts the user did not trigger, which can signal an attacker holding the password and hoping the user taps approve
  • Sign-in successes after a burst of failures

In behavior from outside

  • A client or opposing counsel mentions an email you did not send
  • Replies to your own messages that look slightly off in tone or wording
  • A lookalike domain appears in a thread, differing by a single character

First-hour response

Speed is critical. A short, rehearsed sequence helps.

  1. Reset the password from a clean device and sign out all active sessions.
  2. Revoke tokens and app consents so the attacker cannot return through a stored session or a malicious app.
  3. Check and remove rogue rules and forwarding settings, including those at the server level that users cannot see.
  4. Confirm MFA methods and remove any the user does not recognize.
  5. Preserve evidence. Export sign-in logs and mailbox audit data before they roll off.
  6. Alert finance and anyone handling wires. Pause pending payment changes and verify them by phone.
  7. Notify your insurer or its breach hotline according to your policy.
  8. Warn recipients who may have received malicious messages from the account.

Then work with counsel and your IT provider to determine what the attacker could have seen. The ABA, in Formal Opinion 483, discussed lawyers' obligations to monitor for breaches and take reasonable steps once they find one. Confirm with your state bar what applies to you.

Settings that make takeovers harder

  • MFA for every account, with number matching or app-based approval rather than simple tap-to-approve
  • Block legacy authentication protocols that bypass MFA
  • Disable automatic external forwarding by policy, with exceptions approved individually
  • Conditional access policies that block sign-ins from countries where you do no business
  • Alerts for new inbox rules, forwarding, and impossible-travel logins
  • Anti-impersonation protection for your executives and your domain
  • Audit logging turned on and retained long enough to be useful

Train your people on what to report

Staff often notice something odd and say nothing because they worry they caused it. Make reporting easy and blame-free. A user who reports an unexpected MFA prompt at 2 a.m. may have just saved the firm a large loss.

Teach these simple rules:

  • Never approve an MFA request you did not initiate.
  • Report odd client replies, even if you are unsure.
  • If you clicked something and then felt unsure, tell IT right away.

A hypothetical timeline

Consider a hypothetical firm where an assistant enters her password into a fake login page on Monday. By Tuesday, a forwarding rule is copying all mail mentioning "closing" to an outside address. By Friday, a fraudulent message with new payment instructions goes to a buyer's agent. An alert on the new forwarding rule on Tuesday would have ended the incident before any money was at risk.

Get monitoring in place

Most small firms cannot watch sign-in logs around the clock. Counsel Cyber provides monitoring and response for Microsoft 365 environments used by law firms, and we can start with a review of your current settings to find the gaps that attackers rely on.