logo

Seven ways to spot a business email compromise in Office 365

ID: 0e4b6473-43bb-5513-9c4c-4f9eb33c8352

STIX ID: report--0e4b6473-43bb-5513-9c4c-4f9eb33c8352

Feed Name: Expel Blog

Threat Score
55/100

Date Published: 2019-02-14

Date Updated: 2026-04-27

Author: Jon Hencinski

...
...

This report explains Business Email Compromise (BEC): common scam categories (CEO impersonation, full account takeover, false invoice schemes), the frequent O365 techniques attackers use (malicious inbox rules, automatic forwarding/deletion, mailbox delegation, and VPN-based conditional-access bypass), and concrete detection/response guidance including sample logs, Sumo Logic queries, investigative playbooks, and recommended controls such as enabling mailbox auditing and integrating O365 logs with a SIEM.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.