logo

Microsoft 365 mailbox rules abused for exfiltration, persistence

ID: 97912ade-9869-5a3b-b64f-deee8542606c

STIX ID: report--97912ade-9869-5a3b-b64f-deee8542606c

Feed Name: Proofpoint Blog

Threat Score
70/100

Date Published: 2026-04-13

Date Updated: 2026-04-28

...
...

Security vendors report attackers are creating malicious Microsoft 365 mailbox rules to automatically forward, delete, or suppress emails — including security alerts, MFA notifications, and password resets — enabling stealthy data exfiltration and persistence that survives password resets and MFA enrollment. Proofpoint observed this technique in roughly 10% of compromised accounts in Q4 2025; recommended mitigations include removing unauthorized inbox rules, invalidating sessions and refresh tokens, removing unrecognized apps, and user education.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.