Surge in Mailbox Rule Abuse Threatens Microsoft 365 Security

Surge in Mailbox Rule Abuse Threatens Microsoft 365 Security

First seen 13 Apr 2026, 16:07 UTC ProofpointInfosecurity-MagazineGbhackersCybersecuritynewsItbrief 69.0

Article Content

Browse articles
ThreatCluster

Security researchers have reported a significant increase in the abuse of mailbox rules within Microsoft 365 environments, with attackers leveraging these native email features to maintain access and exfiltrate data after account compromise. According to findings from Proofpoint, approximately 10% of compromised accounts in Q4 2025 had malicious mailbox rules created within seconds of initial access. These rules are often named minimally or nonsensically, allowing attackers to delete emails or move them to less monitored folders, thereby controlling what victims see in their inboxes. Common objectives include forwarding sensitive emails to external accounts, hiding security alerts, and intercepting ongoing communications. The persistence of these rules means they can remain active even after credentials are reset, allowing continued data exposure. Attackers are also using automation tools to deploy these rules across multiple accounts, making detection more challenging. Organizations are advised to disable external auto-forwarding, enforce strong access controls, and monitor OAuth activity closely.

Key Points: • 10% of compromised Microsoft 365 accounts had malicious mailbox rules created shortly after access. • Attackers use mailbox rules to delete or hide emails, manipulating victim perception. • Malicious rules can persist even after password changes, allowing ongoing data exposure.

Timeline

2025-01-01
Increase in mailbox rule abuse detected by security researchers.
2025-10-01
10% of compromised accounts reported with malicious rules.
2026-04-13
Proofpoint findings published highlighting mailbox rule abuse.