Business Email Compromise (BEC) attackers usually sit quietly in the inbox for days before launching invoice scams. Confirming what's been sent and what rules they've planted is step one.
Where attackers hide
- Forwarding rules that send copies to an external address
- Filters that auto-delete replies from finance teams
- OAuth-connected apps that re-establish access if you change the password
- Hidden delegated-mailbox permissions
Was this guide helpful?
Know someone who needs this? Send them the guide.
JD
Written by
Jordan DicksonFounder, CyberSecurityGuides
Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.
Reviewed by CSG Security Engineers