When attackers compromise a mailbox, they may create forwarding or inbox rules to hide their activity.
A malicious rule can silently forward copies of messages to an outside address. Another rule may move security alerts, password reset messages, or replies from customers into hidden folders.
This allows the attacker to keep watching the mailbox even after the employee notices something is wrong.
After any suspected email compromise, IT should review inbox rules, forwarding settings, delegated access, connected applications, and sign-in activity.
Businesses should also restrict automatic forwarding to outside domains unless there is a clear business reason.
Mailbox compromise can lead to invoice fraud, data theft, and customer impersonation. That is why email security should include both prevention and regular monitoring.
A changed password is important, but it may not remove every change an attacker made inside the account.
