ChecklistCONSTRUCTEDUntested
First 15 minutes: a new inbox rule forwards, deletes or hides mail
An inbox rule is rarely the attack. It is the evidence that somebody is inside the mailbox and wants to stay unseen. Keep it, read it for intent, and close the account behind it.
high severityCollectionT1114.003T1564.008
The clock starts when
An alert or a user reports a new inbox rule that forwards mail outside, deletes it, or moves it to an obscure folder such as RSS Feeds, Archive or Conversation History.
Keep the rule as evidence
Close the account behind it
Find what it was hiding
Do not
- Do not delete the rule before exporting it.
- Do not treat the rule as the incident. Somebody created it from inside the account.
- Do not warn the other party to a payment thread by email from the affected mailbox.
Escalate now if
- The rule filters on invoice, payment, bank, remittance or wire.
- Mail was forwarded to an external address.
- Other mailboxes have similar rules.
Minute sixteen. The checklist ends here and the response does not.
Open the business email compromise planWhy this order
Deleting the rule feels like remediation and destroys the best evidence of intent you will get. A rule that moves anything containing "invoice" to RSS Feeds is a statement of what the operator is waiting for, and it is the thing that lets you warn finance before the fraudulent invoice arrives.
What this does not cover
A payment that has already been sent. If one has, stop reading and follow the invoice fraud playbook: the bank recall has a window measured in hours.