Business email compromise usually has a quiet phase first
By the time a fraudulent invoice or wire request lands, the attacker has often had access to a mailbox for days or weeks already, reading real conversations, learning who approves payments, and waiting for the right moment. That quiet phase leaves signs, if anyone is looking for them.
Signs to check in the mailbox itself
Most business-email-compromise cases share a small set of quiet indicators. None of these alone proves compromise, but any of them should trigger a closer look.
- New forwarding rules the user does not recognize, especially forwarding to an external or personal address
- Inbox rules that delete or move messages containing words like invoice, payment, wire, or password
- Sent items containing messages the user does not remember sending
- Read receipts or replies to messages the user does not recall opening
- A sudden change in the user's writing style reported by colleagues, even if subtle
Signs to check in sign-in and account activity
Cloud email platforms log sign-in activity, and this log is one of the most useful places to look for evidence of unauthorized access before it turns into fraud.
- Sign-ins from unfamiliar countries or impossible-travel patterns (two logins from distant locations minutes apart)
- A spike in failed sign-in attempts followed by a success
- New devices or app registrations the user does not recognize
- Multi-factor authentication prompts the user did not initiate ('MFA fatigue' attempts)
Why finance and vendor threads deserve extra attention
Attackers who reach a mailbox with real invoice history have a much higher success rate than cold phishing, because the fraudulent message can reference a real project, a real invoice number, or a real ongoing negotiation. Any mailbox with regular access to invoices, banking discussions, or vendor payment threads should be treated as a higher-priority target for both monitoring and MFA hardening.
A simple proactive check you can run this week
You do not need a formal audit to catch the most common signs. A short, structured review across the accounts that touch money is often enough to catch active compromise before it costs anything.
- Export and review forwarding rules and inbox rules for every account with finance or vendor access
- Review the last 30 days of sign-in activity for those accounts, filtering for unfamiliar locations or devices
- Confirm MFA is enabled with a phishing-resistant method for every one of those accounts
- Ask finance staff directly whether anything about recent vendor communication felt slightly off
Frequently asked questions
If MFA is enabled, can the mailbox still be compromised?
Yes. Real-time phishing pages can relay a one-time code the moment a user types it, and 'MFA fatigue' attacks bombard a user with approval prompts until one is accidentally approved. MFA reduces risk significantly but does not eliminate it, which is why sign-in activity and mailbox rules still need periodic review.
How far back should we check sign-in logs?
Most cloud platforms retain useful sign-in history for 30 to 90 days depending on license tier. If a fraud attempt has already occurred, check as far back as your logs allow, since business-email-compromise access often starts weeks before the fraudulent message is sent.
What should we do the moment we find a suspicious forwarding rule?
Disable the rule, force a password reset, revoke active sessions, and re-enroll MFA on a device you trust, in that order and quickly. Then review what the rule may have exposed, including any invoices or client data it forwarded, before assuming the incident is closed.