Hackers Exploit Hidden Microsoft 365 Mailbox Rules to Steal Sensitive Business Emails
ID: f9ed14b5-6650-59c4-9309-f6ae3a1dc365
STIX ID: report--f9ed14b5-6650-59c4-9309-f6ae3a1dc365
Feed Name: GBHackers
Attackers are abusing Microsoft 365 mailbox rules to silently forward, move, or delete emails—enabling persistent access, hiding security alerts, and facilitating business email compromise and financial fraud. After initial access via phishing, password spraying, or stolen OAuth tokens, adversaries create automated malicious mail rules (often with innocuous names) across many accounts using Microsoft Graph or PowerShell; these rules can survive password resets and intercept verification and transaction emails. Proofpoint telemetry and demonstrations (e.g., ATOLS) show this technique is automated at scale, and organizations are advised to disable external auto-forwarding, enforce MFA/conditional access, and monitor mailbox rules and OAuth consent changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
