logo

Hackers Create Hidden Mailbox Rules in Microsoft 365 to Intercept Sensitive Business Emails

ID: 820b9895-999d-5eb2-ba0f-a7f8442fb493

STIX ID: report--820b9895-999d-5eb2-ba0f-a7f8442fb493

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-04-15

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**Hidden mailbox rules in Microsoft 365 are being abused by attackers to silently forward, hide, or manipulate emails after account compromise, enabling business email compromise, payroll fraud, and long-term persistence; Proofpoint observed malicious rules in roughly 40% of compromised accounts and rule creation occurring as fast as eight seconds post-compromise.** Recommended defenses include disabling automatic external forwarding, enforcing MFA with conditional access, auditing mailbox rules regularly, monitoring OAuth consent grants, revoking active sessions after suspected breaches, and reviewing Entra ID sign-in logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.