Infosecurity-Magazine Surge in Mailbox Rule Abuse Threatens Microsoft 365 Security
Article Content
- •10% of compromised Microsoft 365 accounts had malicious mailbox rules created shortly after access.
- •Attackers use mailbox rules to delete or hide emails, manipulating victim perception.
- •Malicious rules can persist even after password changes, allowing ongoing data exposure.
Security researchers have reported a significant increase in the abuse of mailbox rules within Microsoft 365 environments, with attackers leveraging these native email features to maintain access and exfiltrate data after account compromise. According to findings from Proofpoint, approximately 10% of compromised accounts in Q4 2025 had malicious mailbox rules created within seconds of initial access. These rules are often named minimally or nonsensically, allowing attackers to delete emails or move them to less monitored folders, thereby controlling what victims see in their inboxes. Common objectives include forwarding sensitive emails to external accounts, hiding security alerts, and intercepting ongoing communications. The persistence of these rules means they can remain active even after credentials are reset, allowing continued data exposure. Attackers are also using automation tools to deploy these rules across multiple accounts, making detection more challenging. Organizations are advised to disable external auto-forwarding, enforce strong access controls, and monitor OAuth activity closely.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…