When Attackers Don't Spoof Your Email—but Send from Your Real Account

Many organizations have become more cautious about phishing emails. Employees are taught to check the sender's name, inspect suspicious links, and avoid unexpected attachments.

However, incidents investigated by D SCAPE show a more difficult threat: the attacker does not merely impersonate an employee. They gain access to a real organizational account and use it as if they were the legitimate owner.

An email sent from a genuine account can include the correct name, address, previous conversation history, and familiar contacts. This makes it significantly more convincing than an ordinary phishing message.

What Is This Type of Attack Called?

The broadest and most accurate terms are Email Account Compromise (EAC) and Email Account Takeover (ATO). Both describe an attacker gaining unauthorized access to a legitimate user's email account.

If the attacker uses that account to deceive employees, customers, or business partners—for example, by requesting a payment, changing bank details, sending a fraudulent invoice, or asking for sensitive information—the incident may become Business Email Compromise (BEC).

When the compromised account is used to send phishing messages to colleagues or existing contacts, the behavior is commonly described as Lateral Phishing. The attacker expands the campaign from one trusted identity to other people within the victim's business network.

Put simply, conventional phishing is like an attacker standing outside the door wearing a disguise. Account takeover means the attacker has obtained a real key, entered the building, and started communicating in the organization's name.

Three Common Attacker Activities

Based on incidents investigated by D SCAPE, three activities appear frequently after an email account is compromised.

1. Reading Messages in the Inbox

After gaining access, an attacker may review historical emails to understand the organization, its customers, suppliers, executives, approval processes, and payment schedules.

This information can be used to construct highly believable messages. The attacker may refer to an active project, continue an existing conversation, attach a modified document, or strike shortly before a genuine payment is due.

The impact therefore extends beyond someone reading an email. Business information, personal data, attachments, and relationship details may all be exposed and reused in further attacks.

2. Sending Phishing Emails from the Real Account

The attacker may send messages to an entire contact list, identify recipients from previous correspondence, or reply within an existing email thread.

Thread-based attacks are particularly dangerous. The recipient sees a familiar name, a legitimate email address, and genuine conversation history. They may therefore be more willing to open a file, follow a link, disclose credentials, or approve a request.

One compromised identity can consequently become a launch point for attacks against the entire organization, its customers, and multiple business partners.

3. Creating or Modifying Mailbox Rules

Attackers often configure Malicious Inbox Rules to control email flow and conceal their activity. These rules may:

  • Forward messages to an external account.
  • Move emails containing words such as “invoice,” “payment,” “phishing,” or “fraud” into rarely visited folders.
  • Delete warnings or replies sent by suspicious recipients.
  • Hide messages in Junk Email, RSS, or Deleted Items.
  • Prevent the account owner from seeing notifications about unusual activity.

Microsoft notes that malicious inbox rules are common in BEC and phishing incidents. They can help attackers monitor conversations, extract information, and remove evidence that could alert the legitimate user.

Why Changing the Password May Not Be Enough

Changing the password is necessary, but it does not complete the response.

The attacker may still have an active session or token. They may have registered their own MFA method, authorized a malicious application, configured forwarding, or left hidden inbox rules behind.

If an organization resets only the password without investigating these additional access paths, the attacker may retain access or return later.

What Should You Do Immediately?

Organizations should begin a structured incident response as soon as an account compromise is suspected.

1. Contain the Account

Temporarily disable the affected account—or reset it to a strong, unique password—and revoke all active sessions and refresh tokens.

Do not send the new password to an email account that is still under investigation.

2. Remove Attacker-Controlled Access

Review at least the following:

  • Registered MFA methods, phone numbers, and devices.
  • Applications and permissions approved through user consent.
  • Administrative roles and other privileged access.
  • Inbox rules, including hidden rules.
  • Mail forwarding to internal or external addresses.
  • Delegated mailbox permissions.
  • Sign-in logs, locations, devices, IP addresses, and unusual behavior.

3. Determine the Scope of the Incident

Use audit logs, sign-in logs, and message trace data to establish when the incident began, which messages were accessed or sent, whether information was downloaded from OneDrive or SharePoint, and whether other accounts were affected.

Do not rely solely on the Sent Items folder. Attackers can delete messages or use rules to move evidence elsewhere.

4. Warn Potential Recipients

Notify employees, customers, and business partners who may have received malicious messages from the compromised account. Clearly identify the relevant time window, subject lines, links, and attachments.

If personal data, confidential information, or financial transactions may be involved, coordinate with legal, privacy, risk, and executive stakeholders to assess applicable reporting or notification obligations.

5. Look for Secondary Victims

Identify whether any employee or external contact clicked a link, entered credentials, opened an attachment, or approved an unexpected MFA prompt. The incident may have spread beyond the first account.

How Can Organizations Reduce the Risk?

Require MFA for Every User

MFA reduces the risk created by stolen passwords. Where possible, organizations should adopt phishing-resistant methods such as passkeys, FIDO2 security keys, Windows Hello for Business, or certificate-based authentication—especially for administrators and users with access to sensitive information.

Traditional MFA can still be targeted through MFA fatigue or session-token theft, so it should not be treated as the only control.

Use Conditional Access and Risk-Based Policies

Conditional Access can evaluate factors such as sign-in risk, user risk, device status, location, and application sensitivity. Depending on the organization's configuration and licensing, suspicious access can be blocked, challenged with stronger authentication, or restricted to managed devices.

Reduce Unnecessary Access Paths

Disable legacy authentication, restrict external email forwarding, control application consent, and apply least-privilege access. These measures limit both the probability and potential impact of an account takeover.

Monitor Identity Behavior, Not Only Malware

Security monitoring should detect unusual sign-ins, suspicious inbox rules, abnormal outbound email volume, new MFA methods, unexpected applications, and risky identity behavior.

An attacker may not need to install malware. A stolen identity and the organization's existing cloud tools may be enough to cause significant damage.

Apply Identity Threat Detection and Response

Identity Threat Detection and Response (ITDR) brings together identity signals, access activity, risk detection, investigation, and remediation. It helps security teams identify compromised identities and suspicious access before they develop into broader incidents.

ITDR should complement—not replace—strong authentication, email security, endpoint protection, user awareness, and a tested incident-response process.

Prepare an Incident-Response Playbook

Organizations should decide in advance who can disable an account, who investigates logs, who communicates with customers, and who makes decisions about affected transactions.

Response speed directly influences how many messages an attacker can read, how many recipients can be targeted, and how far the damage to business trust may spread.

Identity Security Is Business-Trust Security

When an organizational account is taken over, the impact extends beyond the account owner. Every customer, colleague, and partner who trusts the organization's domain can become part of the attack chain.

Protection must therefore cover identity, email, endpoints, data, monitoring, and incident response. Security awareness and password changes alone are not enough.

D SCAPE helps organizations investigate account-compromise incidents, determine the scope of exposure, remove attacker access, and strengthen Microsoft 365 and cloud identity security according to each organization's risk profile.

If you discover an unusual sign-in, unexplained outbound email, or a mailbox rule the user did not create, begin investigating immediately. Every minute may represent more information—and more trust—being used to extend the attack.

References