Comserv Connect
← Back to Blog
Cybersecurity

The Email Came From Your Vendor's Real Account

By Comserv Connect TeamReviewed by Chris Ferrera

A reply lands in a thread you started three weeks ago. Same vendor, same signature block, and the message answers the question you actually asked. At the bottom it says the remittance details have changed and asks you to send this month's payment to a new account.

Nobody registered a lookalike domain. Checking the sender's address confirms the mail came from your vendor, because it did. Somebody else is signed into your vendor's mailbox and is typing from inside it.

This Has a Name, and the Name Is Not About Email Alone

The FBI's Internet Crime Complaint Center calls this family of fraud business email compromise. Its 2025 annual report defines it as:

"BEC is a scam targeting businesses or individuals working with suppliers and/or businesses regularly performing wire transfer payments. These sophisticated scams are carried out by fraudsters by compromising email accounts and other forms of communication such as phone numbers and virtual meeting applications, through social engineering or computer intrusion techniques to conduct unauthorized transfer of funds."

Compromising the account comes first in that definition. The wire is the payoff, not the method.

MITRE, which maintains the public catalog of attacker techniques, describes the move plainly in T1586.002:

"Adversaries can use a compromised email account to hijack existing email threads with targets of interest."

And on why it works:

"Utilizing an existing persona with a compromised email account may engender a level of trust in a potential victim if they have a relationship with, or knowledge of, the compromised persona."

The term to search for is thread hijacking. MITRE uses it in T1566, describing an attacker "including the intended target as a party to an existing email thread."

The Spoofing Question Has a Clean Answer Here

Owners reasonably assume a mail filter is the layer that handles this. Read how the spoofing check actually works, in Microsoft's own description:

"Spoofed messages appear to originate from someone or somewhere other than the actual source."

"Anti-spoofing technology in Microsoft 365 specifically examines forgery of the From header field... When Microsoft 365 has high confidence the From header is forged, the message is identified as spoofed."

In this attack the From header is not forged. The domain is the vendor's domain, the mail left the vendor's tenant, and the authentication records say so correctly, because all of that is true. The message is not a forgery of your vendor. It is your vendor's mailbox, operated by someone who should not have it.

The Rules That Decide How Long It Lasts

The compromise is the start. What determines whether this runs for a day or for months is a feature every mail client ships with.

MITRE catalogs it as Hide Artifacts: Email Hiding Rules, T1564.008:

"Adversaries may use email rules to hide inbound emails in a compromised user's mailbox. Many email clients allow users to create inbox rules for various email functions, including moving emails to other folders, marking emails as read, or deleting emails."

Microsoft's playbook for grading these alerts opens by saying how routine this is:

"Malicious inbox rules are common during business email compromise (BEC) and phishing campaigns and it's important to monitor for them consistently."

And describes the shapes they take:

"Attackers might set up email rules to hide incoming emails in the compromised user mailbox to obscure their malicious activities from the user. They might also set rules in the compromised user mailbox to delete emails, move the emails into another less noticeable folder (like RSS), or forward mails to an external account."

CISA documented the same pattern in the field in an analysis report released in January 2021. New rules forwarded certain messages "to the legitimate users' Really Simple Syndication (RSS) Feeds or RSS Subscriptions folder in an effort to prevent warnings from being seen." An existing rule on a user's account was modified to redirect mail to an account the actors controlled. That report is five years old and scoped to one intrusion set, so treat it as documentation that this happens rather than as a picture of this week.

Follow what those rules do to the conversation. Your reply asking the vendor to confirm the new bank details arrives in their mailbox and never reaches their inbox. Your vendor sees a thread that went quiet. You see a thread that is still moving. Forwarding has its own catalog entry, T1114.003, because the rule can also hand the attacker a copy of the mail that keeps arriving after they lose the password.

The Mailbox Is Not Only the Delivery Route

A mailbox is a filing cabinet that has been accumulating for years. MITRE's entry for Email Collection states it directly:

"Adversaries may target user email to collect sensitive information. Emails may contain sensitive data, including trade secrets or personal information, that can prove valuable to adversaries."

The mailbox contents are themselves worth taking. And if the mailbox belongs to someone with administrative rights, the reach extends further, because elevated permissions are what an attacker needs to go beyond what that one account already touches: "Adversaries can often enter and explore a network with unprivileged access but require elevated permissions to follow through on their objectives."

Now Turn the Story Around

Everything above assumed it was your vendor's mailbox. Run it with yours.

New York's breach notification statute, General Business Law 899-aa, defines private information to include:

"a user name or e-mail address in combination with a password or security question and answer that would permit access to an online account"

The credential is the private information. Not a Social Security number behind it, not a card number in an attachment. The login itself. And the trigger in 899-aa(1) is unauthorized access to or acquisition of that information, so being in the account counts without anything leaving it.

A compromised mailbox can put a business inside a breach notification statute with no wire sent, no invoice paid and no money lost.

There is a deadline, and plenty of guidance still circulating says there is not one. From 899-aa(2):

"The disclosure shall be made in the most expedient time possible and without unreasonable delay, provided that such notification shall be made within thirty days after the breach has been discovered"

Subdivision 8 adds notice to the state attorney general, the department of state and the division of state police, and, where more than five thousand New York residents are notified at one time, to consumer reporting agencies. Those subdivisions carry exceptions and conditions the sentences above do not contain.

Two scope points. The law follows the New York resident, not your address: a New Jersey business holding data on New York residents is inside it. And the companion section, 899-bb, requires "reasonable safeguards," with a technical category written into the statute that expressly includes safeguards that detect, prevent and respond to "attacks or system failures" and that regularly test and monitor "the effectiveness of key controls, systems and procedures." There is a defined small-business tier that scales that standard rather than removing it. We covered the whole of 899-bb, including who qualifies as a small business and the safe harbor most write-ups skip, in NY SHIELD Act compliance for small businesses.

What to Do, Cheapest First

Call before you change a payment detail. Use a phone number you already had, from your own records, and speak to a person you have spoken to before. Not the number in the signature block of the message asking for the change. This costs nothing and it is the control that works against this specific attack, because it leaves the channel the attacker controls.

Write the rule down so a junior person is allowed to use it. Any mid-thread change to bank details, remittance addresses or payment instructions is unverified until a voice confirms it, and nobody gets in trouble for holding a payment for a day. An informal norm fails under pressure from a message that looks like it came from a client.

Audit your mailboxes for rules, and turn on the logging that lets you. Rules that forward to an internal address or quietly file replies away are the ones that survive. The configuration work, including the audit logging that is off by default on the small-business Microsoft 365 plans, is in Microsoft 365 security settings every NYC small business should turn on.

Make your own mailboxes expensive to take. Strong MFA, weak factors removed rather than left registered alongside the strong ones, and policy that limits where a sign-in is accepted from. Identity is the new perimeter walks through how account takeover happens without malware, and what each identity control does and does not stop.

Know your clock before the day you need it. Decide now who makes the call about notification, which lawyer you phone, and where your logs are. Thirty days is not long to spend discovering you cannot reconstruct what happened.

How Comserv Helps

Two of the pillars on our cybersecurity services page are the ones that speak to this attack.

Identity and Access Security is where a stolen password stops being enough: MFA enforced everywhere it belongs, and conditional access policies that control who can sign in and from where. In a Microsoft 365 environment, that is a real boundary. We can restrict sign-ins so the environment only accepts them from the places your business actually works, which takes a credential sold in a dump and makes it a lot less useful to whoever bought it.

24/7 Threat Monitoring and Response is the part that notices. Live security analysts watch your environment around the clock, backed by SIEM and EDR. A session from a country you do not operate in, a sign-in pattern that does not match the person, a new mailbox rule filing a vendor's replies into RSS Feeds: those are the signals we are watching for, and the response we run is to disable the account and kill the session first, then work out the rest with the log.

Our inline mail protection carries real load against phishing and BEC as a category. The message in this post is the harder case, because the sender genuinely is your vendor, which is why identity and monitoring are the layers that matter here. Backup and disaster recovery sits behind all of it as the fallback, not the control.

Want to know whether a stolen mailbox credential would get anyone anywhere in your tenant? Book a free strategy call or call (347) 273-1200, and we will go through it with you.

This post summarizes New York General Business Law sections 899-aa and 899-bb in plain English and quotes the statute as published by the New York State Senate. It is general information, not legal advice, and it does not create an attorney-client relationship. Whether and how these sections apply to your business depends on your specific facts, so talk to your own counsel before relying on any of it.

Sources

  1. FBI Internet Crime Complaint Center, 2025 IC3 Annual Report (Appendix B)
  2. MITRE ATT&CK T1586.002, Compromise Accounts: Email Accounts
  3. MITRE ATT&CK T1566, Phishing
  4. MITRE ATT&CK T1564.008, Hide Artifacts: Email Hiding Rules
  5. MITRE ATT&CK T1114, Email Collection
  6. MITRE ATT&CK TA0004, Privilege Escalation
  7. Microsoft, Anti-spoofing protection in Microsoft 365
  8. Microsoft Defender XDR, Inbox manipulation rules alert grading playbook
  9. CISA Analysis Report AR21-013A (January 2021)
  10. New York General Business Law 899-aa
  11. New York General Business Law 899-bb

Want the Checklist We Actually Use?

The same checks we run for the businesses we protect, in plain language. Free PDF, no vendor pitch.