logo

Hackers Exploit Hidden Microsoft 365 Mailbox Rules to Steal Sensitive Business Emails

ID: f9ed14b5-6650-59c4-9309-f6ae3a1dc365

STIX ID: report--f9ed14b5-6650-59c4-9309-f6ae3a1dc365

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-04-15

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Attackers are abusing Microsoft 365 mailbox rules to silently forward, move, or delete emails—enabling persistent access, hiding security alerts, and facilitating business email compromise and financial fraud. After initial access via phishing, password spraying, or stolen OAuth tokens, adversaries create automated malicious mail rules (often with innocuous names) across many accounts using Microsoft Graph or PowerShell; these rules can survive password resets and intercept verification and transaction emails. Proofpoint telemetry and demonstrations (e.g., ATOLS) show this technique is automated at scale, and organizations are advised to disable external auto-forwarding, enforce MFA/conditional access, and monitor mailbox rules and OAuth consent changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.