惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
SegmentFault 最新的问题
月光博客
月光博客
大猫的无限游戏
大猫的无限游戏
GbyAI
GbyAI
博客园 - 叶小钗
小众软件
小众软件
WordPress大学
WordPress大学
I
InfoQ
Last Week in AI
Last Week in AI
Vercel News
Vercel News
博客园 - Franky
Stack Overflow Blog
Stack Overflow Blog
P
Proofpoint News Feed
A
About on SuperTechFans
Engineering at Meta
Engineering at Meta
腾讯CDC
D
DataBreaches.Net
有赞技术团队
有赞技术团队
宝玉的分享
宝玉的分享
Jina AI
Jina AI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
G
Google Developers Blog
V
Visual Studio Blog
酷 壳 – CoolShell
酷 壳 – CoolShell

Todyl Blog

CyberChef: How to Decode & Decrypt Malicious Scripts (Step-by-Step Guide) Achieving Zero Trust with SASE: A Practical Roadmap for Modern Network Securityso like MSP Security Maturity Assessment: Why 79% of MSPs Are Stuck in 2025 The Rising Threat of Malicious AI: What Every Organization Needs to Know Iran Cyber Threat 2026: What SMBs and MSPs Need to Know The OneStart AI Browser Deception Cyber Insurance Requirements Based on Industry Why Third-Party Security Certification Is Your MSP's Competitive Edge Why Cyber Insurance Carriers Are Shifting to Security Assurance Iran Conflict and Cyber Risk: What North American Organizations Need to Know ‍ Why Cyber Resilience Requires Security, Compliance, and Insurance MSP Security Services: How to Position Identity Protection as Competitive Advantage Identity Security Gap Assessment: A Step-by-Step Guide for MSPs How Credential Theft Attacks Are Costing MSP Clients Millions Do I Need Cyber Insurance as a Small Business? Advanced Persistent Threats (APTs) Explained Preparing for CMMC Level 1: What Your Organization Needs to Do The Real Cost of Doing Nothing in Cybersecurity MSP Security: Build vs Buy SOC The Rise of a Cybercrime Alliance: What LockBit, Qilin, and DragonForce Mean for Business Risk Cyber Threat Recovery Strategies for MSPs What MSPs Need to Know about CIRCIA Final Rule ClickFix: The Evolution of Copy-Paste Social Engineering Akira Ransomware: Threat Assessment of a Scalable RaaS Operation The Dos and Don’ts of Applying for a Cyber Insurance Policy What Is Threat Hunting? A Practical Guide for MSPs and SMBs The Business Case for Cyber Threat Management Evaluating Free and Open Source SIEM Tools in 2026 How organizations can combat BEC Using SASE to help meet cyber insurance requirements
Threat Advisory: Email Account Compromise
Keira Stevens · 2026-01-09 · via Todyl Blog

Amidst recent rises in business email compromise (BEC) campaigns, the Todyl Threat Research team has uncovered a similar emerging threat: email account compromise, or EAC.

What is Email Account Compromise (EAC)?

EAC is a specific subset of BEC, relying on full account takeover (ATO) as a means for attacking an organization from within. In an EAC scenario, an attacker first gain access to an individual’s email account through:

  • Social engineering/phishing attacks
  • Brute force attacks like password spraying
  • Purchasing credentials through initial access markets

Once inside, the real attack begins, shifting into BEC. The bad actor uses emails, calendar invites and meetings, company directories, and shared files to study the victim and develop an understanding of who they are and how they operate. Attackers will even build forwarding rules to ensure a constant flow of information, tweaking account permissions to avoid detection and maintain access.

Once they understand their victim, the attacker assumes their identity. They will mimic the user’s behavior, sending emails and responses in a timely manner, making them almost indistinguishable from the victim. This differs from other BEC approaches that use spoofing and other detection tactics to trick people into thinking something is legitimate. Instead, the attacks come directly from a legitimate account, controlled by a bad actor like a puppet.

The Use of AI in EAC and BEC

Artificial intelligence is already being used to create convincing wording for phishing and other BEC campaigns, but it takes an even more sinister turn in the case of EAC. Specifically, AI deepfakes and voice cloning now give attackers even more ways to fully impersonate EAC victims. The result is even more convincing mimicry, making it difficult for blue teams to discern that an account is compromised.

Todyl’s Findings

While defending our partners, the Todyl Threat Research team noticed a few key commonalities across EAC cases like this one.

A screenshot of a phoneAI-generated content may be incorrect.

Inbox rules

As discussed earlier, inbox forwarding rules are often used in EAC attacks to obscure an attacker’s activity. Specifically, our teno thankam found that a bad actor will use these rules to hide emails they have sent as the victim. For example, an attacker will move a sent email to lesser used folders such as the RSS or Conversation History folders. That way, they can use these emails for other BEC attacks without losing record of conversations for maintaining their victim profile.

Attackers will determine where to route these emails based on the information gathered in their initial reconnaissance. One scenario would be a user who rarely if ever checks their Spam or Junk folders. The attacker’s emails can be stored there, hiding in plain sight, and then automatically deleted after 30 days, leaving no trace.

Although not definitive, our team noticed that these rules will usually be named with 1-3 characters, such as:  

  • ?
  • ??
  • ...
  • ....
  • ,,,

Email deletion

According to our team’s findings, more active/enterprising attackers will take a step further. Instead of rerouting sent emails to an unused folder, they will actively delete the email from Sent, and then quickly remove it from the Deleted Items folder as well. This removes any apparent evidence of their activity, leaving the victim none the wiser.  

Here is an example case:

A screenshot of a computerAI-generated content may be incorrect.

How to Defend Against EAC  

Because attackers go to great lengths to hide their activities, detecting and stopping EAC can be difficult. Amongst the cases we’ve seen so far, here are a few prevailing trends to look for within your SIEM:

  • Email logins at unusual hours
  • Logins from unusual or foreign locations (geolocation)
  • Impossible Travel
  • Unusual user-agent
  • ASNs with a bad reputation
  • VPNs with a bad reputation
  • IPs with a bad reputation
  • Multiple failed logins and then a success (also brute force from multiple IPs)
  • MFA Bypass

You can also search for abnormal forwarding rules, especially ones with naming conventions like those detailed above. Other potential signs of this type of account compromise include:  

  • RSS Feeds folder activity
  • Volume of emails being sent out exceeds normal threshold per day/hour/minute
  • Emails being sent out at unusual times (after midnight and before 6am)
  • Sending an email and then deleting it out of Sent Items in less than a minute

How Todyl can Help

Thanks to the efforts of our Threat Research team, the Todyl Platform is already tuned to detect these indicators of compromise to help you root out and stop potential EAC threats. With Microsoft Entra ID and Google Workspace integrations, Todyl helps you uncover and address email-based threats quickly to prevent EAC from happening within your environments.

To learn more, contact us to see how you can get started proactively defending yourself and your clients from these threats. You can read what other new and emerging threats our team are tracking—and how to stop them—on our threat intelligence feed.

About Keira Stevens

Keira Stevens is a Senior Security Research Engineer at Todyl, where she spends most of her time writing and tuning detection rules, and researching threats seen at Todyl. She has almost two decades of experience in the security field that includes giving talks at conferences, writing papers and publishing blogs. Keira as helped stop APT actors attacking companies, working with LE on criminal group takedowns, and mentor new people coming into the security field. When not at work Keira likes to spend time with her family and smashing buttons in online video games.