Jeyki SecurityCybersecurity consulting
Business email compromise

Business Email Compromise: Warning Signs Before the Fraud Happens

The quiet signs that a business mailbox has been compromised before a fraudulent payment request goes out, and how to check for them proactively rather than after money is gone.

← Back to guidesPublished 2026-08-20 · Updated 2026-08-20

Business email compromise usually has a quiet phase first

By the time a fraudulent invoice or wire request lands, the attacker has often had access to a mailbox for days or weeks already, reading real conversations, learning who approves payments, and waiting for the right moment. That quiet phase leaves signs, if anyone is looking for them.

Signs to check in the mailbox itself

Most business-email-compromise cases share a small set of quiet indicators. None of these alone proves compromise, but any of them should trigger a closer look.

  • New forwarding rules the user does not recognize, especially forwarding to an external or personal address
  • Inbox rules that delete or move messages containing words like invoice, payment, wire, or password
  • Sent items containing messages the user does not remember sending
  • Read receipts or replies to messages the user does not recall opening
  • A sudden change in the user's writing style reported by colleagues, even if subtle

Signs to check in sign-in and account activity

Cloud email platforms log sign-in activity, and this log is one of the most useful places to look for evidence of unauthorized access before it turns into fraud.

  • Sign-ins from unfamiliar countries or impossible-travel patterns (two logins from distant locations minutes apart)
  • A spike in failed sign-in attempts followed by a success
  • New devices or app registrations the user does not recognize
  • Multi-factor authentication prompts the user did not initiate ('MFA fatigue' attempts)

Why finance and vendor threads deserve extra attention

Attackers who reach a mailbox with real invoice history have a much higher success rate than cold phishing, because the fraudulent message can reference a real project, a real invoice number, or a real ongoing negotiation. Any mailbox with regular access to invoices, banking discussions, or vendor payment threads should be treated as a higher-priority target for both monitoring and MFA hardening.

A simple proactive check you can run this week

You do not need a formal audit to catch the most common signs. A short, structured review across the accounts that touch money is often enough to catch active compromise before it costs anything.

  • Export and review forwarding rules and inbox rules for every account with finance or vendor access
  • Review the last 30 days of sign-in activity for those accounts, filtering for unfamiliar locations or devices
  • Confirm MFA is enabled with a phishing-resistant method for every one of those accounts
  • Ask finance staff directly whether anything about recent vendor communication felt slightly off

Frequently asked questions

If MFA is enabled, can the mailbox still be compromised?

Yes. Real-time phishing pages can relay a one-time code the moment a user types it, and 'MFA fatigue' attacks bombard a user with approval prompts until one is accidentally approved. MFA reduces risk significantly but does not eliminate it, which is why sign-in activity and mailbox rules still need periodic review.

How far back should we check sign-in logs?

Most cloud platforms retain useful sign-in history for 30 to 90 days depending on license tier. If a fraud attempt has already occurred, check as far back as your logs allow, since business-email-compromise access often starts weeks before the fraudulent message is sent.

What should we do the moment we find a suspicious forwarding rule?

Disable the rule, force a password reset, revoke active sessions, and re-enroll MFA on a device you trust, in that order and quickly. Then review what the rule may have exposed, including any invoices or client data it forwarded, before assuming the incident is closed.

Official resources