惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
C
CXSECURITY Database RSS Feed - CXSecurity.com
S
Schneier on Security
博客园 - 叶小钗
博客园 - 三生石上(FineUI控件)
C
Cybersecurity and Infrastructure Security Agency CISA
Engineering at Meta
Engineering at Meta
Google DeepMind News
Google DeepMind News
酷 壳 – CoolShell
酷 壳 – CoolShell
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园_首页
T
Threat Research - Cisco Blogs
C
Cisco Blogs
Recent Announcements
Recent Announcements
S
Securelist
N
Netflix TechBlog - Medium
The Register - Security
The Register - Security
P
Privacy & Cybersecurity Law Blog
宝玉的分享
宝玉的分享
D
Darknet – Hacking Tools, Hacker News & Cyber Security
L
LINUX DO - 热门话题
T
Tor Project blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
月光博客
月光博客
AWS News Blog
AWS News Blog
P
Proofpoint News Feed
博客园 - 司徒正美
L
LINUX DO - 最新话题
Stack Overflow Blog
Stack Overflow Blog
博客园 - 聂微东
H
Help Net Security
Spread Privacy
Spread Privacy
PCI Perspectives
PCI Perspectives
Project Zero
Project Zero
I
Intezer
T
The Blog of Author Tim Ferriss
有赞技术团队
有赞技术团队
The Last Watchdog
The Last Watchdog
C
Check Point Blog
Blog — PlanetScale
Blog — PlanetScale
B
Blog RSS Feed
MyScale Blog
MyScale Blog
V
Vulnerabilities – Threatpost
Recorded Future
Recorded Future
T
Tenable Blog
Jina AI
Jina AI
D
DataBreaches.Net
阮一峰的网络日志
阮一峰的网络日志

Todyl Blog

CyberChef: How to Decode & Decrypt Malicious Scripts (Step-by-Step Guide) Achieving Zero Trust with SASE: A Practical Roadmap for Modern Network Securityso like MSP Security Maturity Assessment: Why 79% of MSPs Are Stuck in 2025 The Rising Threat of Malicious AI: What Every Organization Needs to Know Iran Cyber Threat 2026: What SMBs and MSPs Need to Know The OneStart AI Browser Deception Cyber Insurance Requirements Based on Industry Why Third-Party Security Certification Is Your MSP's Competitive Edge Why Cyber Insurance Carriers Are Shifting to Security Assurance Iran Conflict and Cyber Risk: What North American Organizations Need to Know ‍ Why Cyber Resilience Requires Security, Compliance, and Insurance MSP Security Services: How to Position Identity Protection as Competitive Advantage Identity Security Gap Assessment: A Step-by-Step Guide for MSPs How Credential Theft Attacks Are Costing MSP Clients Millions Do I Need Cyber Insurance as a Small Business? Advanced Persistent Threats (APTs) Explained Preparing for CMMC Level 1: What Your Organization Needs to Do The Real Cost of Doing Nothing in Cybersecurity MSP Security: Build vs Buy SOC The Rise of a Cybercrime Alliance: What LockBit, Qilin, and DragonForce Mean for Business Risk Cyber Threat Recovery Strategies for MSPs What MSPs Need to Know about CIRCIA Final Rule ClickFix: The Evolution of Copy-Paste Social Engineering Akira Ransomware: Threat Assessment of a Scalable RaaS Operation The Dos and Don’ts of Applying for a Cyber Insurance Policy What Is Threat Hunting? A Practical Guide for MSPs and SMBs The Business Case for Cyber Threat Management Evaluating Free and Open Source SIEM Tools in 2026 How organizations can combat BEC Using SASE to help meet cyber insurance requirements Introducing the Anomaly Framework Stopping Identity Threats with ITDR through MXDR Security Operations Over Tools Beyond Tools: A Strategic Approach to Data Security Cyber Threat Response Strategies for MSPs BECs In the Wild: When Millions of People Are Expecting the Same Email Michigan and Wisconsin Proposed Age Verification Bills and the Impact on VPNs and SASE: What You Need to Know Cyber Threat Detection Strategies for MSPs Cyber Threat Prevention Strategies for MSPs Simplifying CMMC Level 1 with Todyl GRC How to Complete Your CMMC Level 1 Self-Assessment: A Step-by-Step Walkthrough Cyber Threats Don't Take Time Off How MSPs Build Lasting Client Relationships Through Proactive Operations Risk Management for MSPs: Why Business Context Changes Everything 5 Pillars for Security Program Growth in 2025 One Action MSPs can take to Address Risk and Secure Clients Building Resilience in a Perimeter-less World with Defense-in-Depth Aligning Technology Implementation to Business Outcomes Top 5 Myths about Cybersecurity How Conditional Access Transforms Your Cybersecurity Program Why MSPs need to embrace a prescriptive model How Texas SB 2610 Positions MSPs as Strategic Risk Advisors Simplifying cybersecurity maturity with managed cloud SIEM Addressing firewall vulnerabilities Understanding the Pitfalls of RDP MSP Zero-Day Response Plan: When Security Tools Can't Help You Old is Gold: Tackling Persistent Vulnerabilities How MXDR drives operational efficiencies Using SASE for secure remote access How to find the best endpoint security solution The Cyber Insurance Crisis: Why MSPs and Their Clients Are Struggling What to ask of a prospective endpoint security vendor Thinking Red, Acting Blue: Turning Attack Tactics in Your Favor Zero-Day Attacks and False Alarms: Lessons for MSPs Dissecting the Recent Rise in 2025 Zero Days MSP Security Monitoring Strategy: Identity and Cloud Blind Spots Introducing the Todyl Community: A Collaborative Platform for MSPs Threat Advisory: PDFast Freeware Compromise Navigating Today’s Cybersecurity Threat Landscape: Where MSPs Should Start Threat Advisory: Understanding the Recent SonicWall SSL VPN Vulnerability and How to Protect Your Clients Partner Spotlight: GoTech IT Solutions Threat Advisory: SQL Injection in FortiClient CVE-2023-48788 The Importance of SSL Inspection Navigating Compliance Frameworks: Common Challenges and Effective Solutions Making the most of SASE Web Filtering Iran & Middle-East Geopolitical Shifts: Emerging Cyber Risks for SMBs MSP Security KPIs That Matter: Beyond Vanity Metrics to Business Outcomes MSP Challenges Looking into 2025 Combining EDR and NGAV for Defense-in-Depth Starting Your Security Framework Journey: A Practical Implementation Guide Cyber Insurance vs. Warranties: Key Risk Management Elements Akira Ransomware: A Persistent Threat to MSP Operations Transforming Cyber Insurance for MSPs and Their Clients Two Truths, Double Whammy: Why Vulnerability Remediation Needs a Rethink Using LAN ZeroTrust for segmentation The role of SIEM in incident response Partner Spotlight: 917 Solutions Threat Advisory: Business Email Compromise Campaign using OVPN for Obfuscation Beyond Implementation: Creating an Ongoing Security Framework Program ClickFix: Fake Captcha Leads to Real Damage Streamlining Security and Compliance Information Gathering with Assessments EpiBrowser: A Sophisticated PUP Masquerading as Chromium Partner Spotlight: AnchorSix Tips to Help MSPs Set Goals for the New Year How SIEM helps detect insider threats Massive Wave of Network Security Vulnerabilities Demands Immediate Action FortiJump: The FortiManager Zero-Day Vulnerability Explained Use cases of SASE: Software-defined perimeter Threat Advisory: LightPerlGirl Malware Why MSPs Must Prioritize CIS Critical Security Controls v8.1 for Client Success
Threat Advisory: Email Account Compromise
Keira Stevens · 2026-01-09 · via Todyl Blog

Amidst recent rises in business email compromise (BEC) campaigns, the Todyl Threat Research team has uncovered a similar emerging threat: email account compromise, or EAC.

What is Email Account Compromise (EAC)?

EAC is a specific subset of BEC, relying on full account takeover (ATO) as a means for attacking an organization from within. In an EAC scenario, an attacker first gain access to an individual’s email account through:

  • Social engineering/phishing attacks
  • Brute force attacks like password spraying
  • Purchasing credentials through initial access markets

Once inside, the real attack begins, shifting into BEC. The bad actor uses emails, calendar invites and meetings, company directories, and shared files to study the victim and develop an understanding of who they are and how they operate. Attackers will even build forwarding rules to ensure a constant flow of information, tweaking account permissions to avoid detection and maintain access.

Once they understand their victim, the attacker assumes their identity. They will mimic the user’s behavior, sending emails and responses in a timely manner, making them almost indistinguishable from the victim. This differs from other BEC approaches that use spoofing and other detection tactics to trick people into thinking something is legitimate. Instead, the attacks come directly from a legitimate account, controlled by a bad actor like a puppet.

The Use of AI in EAC and BEC

Artificial intelligence is already being used to create convincing wording for phishing and other BEC campaigns, but it takes an even more sinister turn in the case of EAC. Specifically, AI deepfakes and voice cloning now give attackers even more ways to fully impersonate EAC victims. The result is even more convincing mimicry, making it difficult for blue teams to discern that an account is compromised.

Todyl’s Findings

While defending our partners, the Todyl Threat Research team noticed a few key commonalities across EAC cases like this one.

A screenshot of a phoneAI-generated content may be incorrect.

Inbox rules

As discussed earlier, inbox forwarding rules are often used in EAC attacks to obscure an attacker’s activity. Specifically, our teno thankam found that a bad actor will use these rules to hide emails they have sent as the victim. For example, an attacker will move a sent email to lesser used folders such as the RSS or Conversation History folders. That way, they can use these emails for other BEC attacks without losing record of conversations for maintaining their victim profile.

Attackers will determine where to route these emails based on the information gathered in their initial reconnaissance. One scenario would be a user who rarely if ever checks their Spam or Junk folders. The attacker’s emails can be stored there, hiding in plain sight, and then automatically deleted after 30 days, leaving no trace.

Although not definitive, our team noticed that these rules will usually be named with 1-3 characters, such as:  

  • ?
  • ??
  • ...
  • ....
  • ,,,

Email deletion

According to our team’s findings, more active/enterprising attackers will take a step further. Instead of rerouting sent emails to an unused folder, they will actively delete the email from Sent, and then quickly remove it from the Deleted Items folder as well. This removes any apparent evidence of their activity, leaving the victim none the wiser.  

Here is an example case:

A screenshot of a computerAI-generated content may be incorrect.

How to Defend Against EAC  

Because attackers go to great lengths to hide their activities, detecting and stopping EAC can be difficult. Amongst the cases we’ve seen so far, here are a few prevailing trends to look for within your SIEM:

  • Email logins at unusual hours
  • Logins from unusual or foreign locations (geolocation)
  • Impossible Travel
  • Unusual user-agent
  • ASNs with a bad reputation
  • VPNs with a bad reputation
  • IPs with a bad reputation
  • Multiple failed logins and then a success (also brute force from multiple IPs)
  • MFA Bypass

You can also search for abnormal forwarding rules, especially ones with naming conventions like those detailed above. Other potential signs of this type of account compromise include:  

  • RSS Feeds folder activity
  • Volume of emails being sent out exceeds normal threshold per day/hour/minute
  • Emails being sent out at unusual times (after midnight and before 6am)
  • Sending an email and then deleting it out of Sent Items in less than a minute

How Todyl can Help

Thanks to the efforts of our Threat Research team, the Todyl Platform is already tuned to detect these indicators of compromise to help you root out and stop potential EAC threats. With Microsoft Entra ID and Google Workspace integrations, Todyl helps you uncover and address email-based threats quickly to prevent EAC from happening within your environments.

To learn more, contact us to see how you can get started proactively defending yourself and your clients from these threats. You can read what other new and emerging threats our team are tracking—and how to stop them—on our threat intelligence feed.

About Keira Stevens

Keira Stevens is a Senior Security Research Engineer at Todyl, where she spends most of her time writing and tuning detection rules, and researching threats seen at Todyl. She has almost two decades of experience in the security field that includes giving talks at conferences, writing papers and publishing blogs. Keira as helped stop APT actors attacking companies, working with LE on criminal group takedowns, and mentor new people coming into the security field. When not at work Keira likes to spend time with her family and smashing buttons in online video games.