top of page
Search

The Hidden Microsoft 365 Inbox Rules Hackers Create After They Break In

  • Hanna Korotka
  • 4 days ago
  • 5 min read
The Hidden Microsoft 365 Inbox Rules Hackers Create After They Break In

A compromised Microsoft 365 account does not always look compromised.


An employee might still be able to sign in normally. Outlook may continue working. There may be no obvious warning that someone else has accessed the mailbox.


But behind the scenes, an attacker who gains access to a mailbox can create rules that automatically forward, move, delete, or hide certain emails.


Microsoft specifically identifies suspicious inbox rules as a common sign of a compromised Microsoft 365 email account. These rules are also commonly used during phishing and Business Email Compromise (BEC) attacks.


For small and midsize businesses, this is important because resetting a compromised user's password is only part of the response. You also need to determine what the attacker changed while they had access.


What Can an Attacker Do With an Inbox Rule?


Inbox rules are a legitimate Exchange Online feature. Employees use them every day to automatically organize email.


For example, a user might create a rule that moves messages from a specific sender into a particular folder.


An attacker who gains access to the mailbox can misuse the same functionality.


According to Microsoft, malicious rules can be configured to:

  • Forward messages to an external email address.

  • Move messages into less noticeable folders, such as RSS Subscriptions or Junk Email.

  • Delete messages.

  • Mark messages as read.

  • Act only on messages containing particular words in the subject or body.


That last capability is particularly important.


An attacker does not necessarily have to forward every email in the mailbox. Microsoft explains that a malicious rule can target messages containing keywords such as “finance” or “invoice.”


That allows an attacker to focus on communications that may be valuable for financial fraud or other attacks.


Why Would a Hacker Hide Your Emails?


Imagine an attacker compromises the Microsoft 365 account of someone in your accounting department.


The attacker creates a rule targeting certain financial messages.


Instead of those messages appearing where the employee normally expects them, the rule could move, delete, or forward them.


The employee may simply think an email never arrived.


Meanwhile, the attacker may be monitoring information useful for a Business Email Compromise attack.


Microsoft warns that attackers can use compromised accounts for activities including reading emails, forwarding emails to external accounts, deleting traces of their activity, and sending phishing messages.


This is one reason mailbox compromise can be much more than a stolen password.


Microsoft 365 Inbox Rules You Should Consider Suspicious


Not every unfamiliar rule is malicious. Employees legitimately create rules, so each one needs to be reviewed in context.


However, Microsoft recommends investigating rules with characteristics such as:

  • Forwarding messages to an unknown external address.

  • Moving emails into unexpected or less noticeable folders.

  • Automatically deleting messages.

  • Marking messages as read.

  • Acting on specific sensitive or unusual keywords.

  • Forwarding all incoming email externally.

  • Having an unusual, obscure, or unexpected rule name.


Microsoft also recommends checking whether the forwarding destination belongs to the user or your organization and whether any keywords used by the rule appear related to suspicious activity.


An unexpected rule is therefore not proof by itself that an account has been hacked—but it can be an important indicator that requires investigation.


How Can You Check a User's Inbox Rules?


Administrators can review a mailbox's existing rules using Exchange Online PowerShell.

Microsoft documents the following command:

Get-InboxRule -Mailbox user@company.com

This returns the inbox rules configured for the specified mailbox.


Administrators investigating suspicious activity can review what the rules do—for example, whether they move, delete, or forward messages.


But checking the rules that exist right now is only part of the investigation.


Microsoft Purview Audit can also be used to investigate mailbox rule changes and determine whether rules were created, modified, or deleted. This can be valuable when investigating a suspected compromise because an attacker might remove a malicious rule after using it.


Don't Forget About Mailbox Forwarding


Inbox rules aren't the only mechanism that can automatically send email elsewhere.


An administrator can configure a mailbox so incoming messages are automatically forwarded to another recipient.


Microsoft specifically warns that automatic external forwarding can create a security risk because information can be disclosed outside the organization.


Can Microsoft 365 Detect Suspicious Forwarding?


Yes. Microsoft Defender includes detection capabilities for suspicious email forwarding activity.


Microsoft documents a Suspicious email forwarding activity alert that can be generated when someone in the organization automatically forwards email to a suspicious external account.


Microsoft describes this alert as an early warning of behavior that could indicate an account compromise.


Depending on your Microsoft 365 licensing and security configuration, administrators may also have additional Defender investigation capabilities for suspicious forwarding and inbox manipulation activity.


The important point is that these alerts need to be monitored and investigated. A security capability provides much less value if nobody is reviewing the alerts it generates.


What Should You Do If You Find a Malicious Rule?


Deleting the rule is not enough.


If an attacker created it, you should treat the situation as an account compromise.

Microsoft's recommended response includes:

  1. Disable or remove the malicious rule.

  2. Reset the affected user's credentials.

  3. Investigate other activity performed by the account.

  4. Review sign-in activity for suspicious IP addresses, locations, applications, or failed sign-ins.

  5. Determine whether emails were forwarded outside the organization.

  6. Look for other suspicious activity associated with the affected account or the same suspicious IP address.


The objective is not simply to remove the rule. You need to understand how the account was compromised, what the attacker did, and whether the compromise affected anything else.


Why SMBs Should Pay Attention


Small businesses often assume that an account compromise will be obvious: the password stops working, thousands of spam emails are sent, or Microsoft immediately blocks the account.


That is not always what happens.


A mailbox rule can allow an attacker to manipulate email quietly while the employee continues using their account.


This is why Microsoft 365 inbox rules should be included when investigating a suspected mailbox compromise.


A password reset can help regain control of an account, but it does not tell you what happened before the reset. Reviewing mailbox rules, forwarding settings, sign-in activity, audit logs, and related security alerts helps determine the actual scope of the incident.


How We Can Help


As a Microsoft-focused Managed Security Service Provider (MSSP), we help SMBs monitor and secure their Microsoft 365 environments.


We can review suspicious mailbox activity, investigate compromised accounts, identify malicious forwarding and inbox rules, review Microsoft Defender alerts, and help implement security controls designed to reduce the risk of Business Email Compromise.


If you are unsure whether your Microsoft 365 environment is properly monitored for these threats, a security review can identify the gaps before an attacker does.



 
 
 

Comments


Get the Latest News to Your Inbox

bottom of page