What is Malicious Email Forwarding Rules?
After gaining mailbox access, attackers often create hidden forwarding or redirect rules that copy sensitive mail to an external address — or move fraud-related threads out of sight. Victims keep working while the attacker silently watches invoices, resets, and executive threads.
How a Malicious Email Forwarding Rules Attack Works
Compromise the mailbox
Phishing, stuffing, or OAuth grants provide access.
Plant persistence
Forwarding rules, mobile devices, or app passwords keep the tap open.
Monitor high-value threads
Finance, HR, and M&A conversations are watched for timing.
Act at the right moment
Payment details are altered or secrets are stolen with minimal noise.
Real-World Example
A controller's mailbox silently forwarded anything with the word "invoice" for six weeks. Fraudulent payment changes were coordinated using real vendor threads the attacker was reading live.
How AiVERSARY Detects Malicious Email Forwarding Rules Risk
AiVersary helps you see which identities are most worth compromising for this tactic — executives and finance staff with heavy public exposure — so monitoring and mailbox hardening can be prioritized.
Is your organization exposed to malicious email forwarding rules?
AiVERSARY scans your public footprint and identifies the exact data attackers would use against you. $499 per report.
Get Your Threat ReportRelated Terms
Business Email Compromise
Business email compromise is when an attacker impersonates a senior executive — usually the CEO or CFO — to trick an employee into wiring money or sharing sensitive data. These attacks don't require any malware or hacking; they rely entirely on convincing someone that a fraudulent request is coming from their boss. The FBI reports BEC has caused over $50 billion in losses worldwide.
OAuth Phishing
OAuth phishing does not always steal your password. It tricks you into clicking "Allow" on a third-party app consent screen, granting mailbox or files access to an attacker-controlled application — access that can survive a password change.
Tenant Compromise
Tenant compromise is when an attacker gains administrative control over your organization's cloud environment — your Microsoft 365 tenant, Google Workspace, or AWS account. Unlike stealing a single employee's password, this gives the attacker the keys to everything: every email, every file, every application, and every user account in your cloud infrastructure. It is the most devastating outcome of a successful credential attack.
Session Hijacking
Session hijacking lets an attacker reuse an already-authenticated session — browser cookies, tokens, or SSO artifacts — instead of guessing your password. MFA that only protects login can be bypassed if the session itself is stolen.