Confirm the inbox is actively compromised

    Pin down which account, who's been emailed, and which sessions are unfamiliar.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated June 2026 · 1 min read

    Business Email Compromise (BEC) attackers usually sit quietly in the inbox for days before launching invoice scams. Confirming what's been sent and what rules they've planted is step one.

    Where attackers hide

      • Forwarding rules that send copies to an external address
      • Filters that auto-delete replies from finance teams
      • OAuth-connected apps that re-establish access if you change the password
      • Hidden delegated-mailbox permissions

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Communications Security