
Your Employee Didn’t Get Hacked. Their Inbox Did the Hacking for Them.
Most business owners picture an email attack the same way.
Someone clicks a bad link.
A password gets stolen.
A hacker gets into the account.
That still happens.
But some of the most dangerous email attacks today do not start with an obviously fake message.
They start with a real mailbox.
Once an attacker gains access to an employee’s email account, they can quietly watch conversations, learn how your company communicates, identify vendors, track payment activity, and wait for the right moment to step in.
At that point, the scam does not look fake.
It looks like business as usual.
What Business Email Compromise Really Looks Like
Business email compromise, often called BEC, is not always a dramatic account takeover.
The attacker may not immediately send spam or reset passwords.
Instead, they may quietly observe.
They can look for:
- Vendor invoices
- Payment approvals
- Payroll conversations
- Customer requests
- Executive instructions
- Contract negotiations
- Password reset emails
- Financial attachments
- Calendar activity
They learn who talks to whom, how decisions are made, and which messages usually get fast responses.
Then they wait.
The goal is not necessarily to cause chaos.
The goal is to become believable.
The Most Dangerous Email May Come From the Right Address
Imagine an employee receives an email from a vendor they have worked with for years.
The sender’s address is correct.
The email is part of an existing thread.
The tone sounds normal.
The message says:
“We recently updated our banking information. Please use the attached instructions for future payments.”
Nothing looks suspicious.
Because technically, the email really did come from the vendor’s account.
The attacker compromised the mailbox and inserted themselves into the conversation.
That is what makes business email compromise so effective.
Employees are trained to check the sender.
In this case, the sender is real.
Attackers Can Turn Your Inbox Into a Surveillance Tool
Once inside an email account, an attacker may spend days or weeks learning how the business operates.
They may search for words such as:
- Invoice
- Wire
- Payment
- ACH
- Payroll
- Banking
- Contract
- Confidential
- Password
- Credentials
They may study recurring conversations with vendors and customers.
They can identify which employees authorize payments and which executives travel frequently.
They may even learn when someone is out of the office.
The longer they remain undetected, the more convincing their eventual request can become.
Inbox Rules Can Hide the Attack
One of the quieter tricks attackers use is creating email rules.
For example, they may create a rule that automatically:
- Moves bank notifications into another folder
- Deletes replies from a vendor
- Forwards certain emails to an outside address
- Hides password reset messages
- Moves security alerts out of the inbox
- Marks specific messages as read
Now the attacker can communicate without the employee seeing every response.
A vendor may reply:
“We never changed our banking details.”
But the legitimate employee never sees that message because the attacker’s rule moved it somewhere else.
The mailbox is no longer just compromised.
It is actively helping conceal the fraud.
Sometimes the Employee Never Notices
One reason BEC can remain undetected is that the mailbox still works.
The employee can send and receive email.
Nothing crashes.
There is no ransom note.
No screen turns red.
No one announces that the account has been compromised.
The employee may continue working normally while someone else quietly has access.
That creates a dangerous assumption:
“My email works, so my account must be fine.”
Unfortunately, those are two different things.
How Attackers Get Into the Mailbox
Business email compromise can begin in several ways.
Common entry points include:
- Phishing emails
- Stolen passwords
- Reused credentials from another breach
- Fake Microsoft 365 login pages
- MFA fatigue attacks
- Malicious QR codes
- Session token theft
- Weak or outdated authentication methods
Once access is established, the attacker may try to remain invisible.
That is why prevention matters, but monitoring matters too.
Warning Signs Your Inbox May Be Compromised
Email compromise is not always obvious, but there are signs worth watching for.
These may include:
- Unexpected MFA prompts
- Sign-ins from unfamiliar locations
- Messages appearing as read unexpectedly
- New inbox or forwarding rules
- Emails missing from expected folders
- Sent messages the employee does not remember sending
- Customers reporting strange requests
- Password reset emails that were not requested
- New authentication methods added to the account
- Recovery phone numbers or email addresses being changed
- Unusual file-sharing activity
Any one of these deserves attention.
Several together should trigger an immediate investigation.
The Payment Request Is Usually the Final Step
Once attackers understand the business, they often move toward money.
They may send:
- A fake vendor banking update
- A fraudulent wire request
- An altered invoice
- A payroll direct deposit change
- A request to purchase gift cards
- An urgent executive payment instruction
- A fake customer refund request
The message may be short and calm.
That is intentional.
The better scams do not sound like emergencies.
They sound routine.
Four Rules That Make BEC Much Harder
Email security is not only about filtering spam.
Businesses need processes that assume a legitimate mailbox could still be compromised.
1. Verify all payment changes outside email
If a vendor changes bank information, call them using a phone number already stored in your records.
Do not use the number listed in the email.
Email should never be the only source of verification for payment changes.
2. Treat forwarding rules as a security setting
Most employees never look at their inbox rules.
Your IT team should.
Unusual forwarding or deletion rules can be an early sign of compromise.
Accounts should be monitored for unexpected changes.
3. Use strong multifactor authentication
MFA remains essential, but stronger methods reduce risk.
Where possible, businesses should consider phishing-resistant authentication such as passkeys or hardware security keys for higher-risk accounts.
Privileged users, finance employees, and executives deserve additional protection.
4. Train employees to verify behavior, not just addresses
Employees are often taught:
“Check the sender.”
That is no longer enough.
A better question is:
“Does this request make sense?”
A legitimate address can still send a fraudulent request if the account has been compromised.
Unusual payment instructions, urgency, sensitive document requests, and sudden changes in normal procedures should always be verified separately.
What to Do If You Suspect an Email Account Is Compromised
Changing the password is important, but it should not be the only step.
A proper response may include:
- Resetting the password
- Revoking active sessions
- Reviewing recent login history
- Removing unknown devices
- Checking inbox and forwarding rules
- Reviewing sent and deleted messages
- Removing unauthorized authentication methods
- Checking recovery settings
- Reviewing file-sharing activity
- Alerting affected vendors or customers
- Monitoring financial accounts
- Investigating whether other accounts were accessed
The faster the response, the better the chances of containing the problem.
A Quick Business Email Compromise Check
Ask your team:
- Does every employee use MFA?
- Are unusual logins monitored?
- Are forwarding rules reviewed?
- Are vendor payment changes verified by phone?
- Can employees quickly report suspicious activity?
- Are former employee accounts disabled immediately?
- Are finance and executive accounts protected more strongly?
- Does your team know that a legitimate sender address can still be compromised?
If several of those answers are unclear, there may be gaps worth fixing.
The Takeaway
The most dangerous email scams are not always the ones that come from fake accounts.
Sometimes the attacker is already inside a real one.
Once that happens, they can study the business, copy normal behavior, hide responses, and send requests that look completely legitimate.
That is why email security needs more than spam filters and password policies.
It requires:
- Strong authentication
- Account monitoring
- Payment verification
- Secure access controls
- Clear reporting procedures
- A fast incident response plan
Your employee may never have clicked a suspicious attachment that morning.
But if someone else is already inside the mailbox, the inbox itself can become the attacker’s most powerful tool.
Protect the Conversations Your Business Depends On
Capital Network Solutions helps businesses strengthen Microsoft 365 security, account monitoring, authentication, email protections, and incident response procedures.
If you are unsure whether your organization could detect a compromised mailbox before it turns into a payment scam or data breach, a discovery call can help identify practical improvements.
No scare tactics. Just a clear look at how your business protects one of its most important systems: email.










