Hackers Create Hidden Mailbox Rules in Microsoft 365 to Intercept Sensitive Business Emails
ID: 820b9895-999d-5eb2-ba0f-a7f8442fb493
STIX ID: report--820b9895-999d-5eb2-ba0f-a7f8442fb493
Feed Name: cybersecurityNews.com
**Hidden mailbox rules in Microsoft 365 are being abused by attackers to silently forward, hide, or manipulate emails after account compromise, enabling business email compromise, payroll fraud, and long-term persistence; Proofpoint observed malicious rules in roughly 40% of compromised accounts and rule creation occurring as fast as eight seconds post-compromise.** Recommended defenses include disabling automatic external forwarding, enforcing MFA with conditional access, auditing mailbox rules regularly, monitoring OAuth consent grants, revoking active sessions after suspected breaches, and reviewing Entra ID sign-in logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
