Seven ways to spot a business email compromise in Office 365
ID: 0e4b6473-43bb-5513-9c4c-4f9eb33c8352
STIX ID: report--0e4b6473-43bb-5513-9c4c-4f9eb33c8352
Feed Name: Expel Blog
This report explains Business Email Compromise (BEC): common scam categories (CEO impersonation, full account takeover, false invoice schemes), the frequent O365 techniques attackers use (malicious inbox rules, automatic forwarding/deletion, mailbox delegation, and VPN-based conditional-access bypass), and concrete detection/response guidance including sample logs, Sumo Logic queries, investigative playbooks, and recommended controls such as enabling mailbox auditing and integrating O365 logs with a SIEM.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
