You detect a compromised mailbox by monitoring for the tell-tale signs, especially new mail-forwarding or inbox rules, unusual sign-ins from odd locations, and unexpected sending. Catching these early lets you lock the account and investigate before an attacker uses it to commit fraud. A quietly hijacked mailbox is one of the most dangerous things at a financial firm, because the criminal reads your mail and waits.
Attackers who get into a mailbox often set it up to serve them silently. Here’s what to watch for.
1. Suspicious mail rules
A classic move is to create a rule that auto-forwards or hides certain emails, so the attacker sees everything and the real user misses the warning signs. An alert when a new forwarding or inbox rule appears is one of the strongest early signals of compromise.
2. Unusual sign-ins
Logins from unexpected countries, or several failed attempts followed by success, can indicate a stolen password in use. Monitoring sign-ins helps us spot an account being accessed by someone who should not have it.
3. Unexpected sending
A mailbox suddenly sending unusual volumes, or messages the user did not write, is a red flag. Catching this quickly limits the damage and the spread to clients and colleagues.
4. Act fast, with MFA already in place
When a sign of compromise appears, we lock the account, reset access and investigate. MFA across your firm makes compromise far less likely in the first place, and monitoring catches the cases that slip through.
A real example: a mail-rule alert caught early
We supported a technology firm serving financial trading firms where a mail-rule-creation alert let us spot suspicious mailbox activity early, the kind of signal that catches a compromised account before it is used for fraud. That early warning is exactly what monitoring is for.
For a software, technology or financial trading firm, this is part of managed IT and security that usually costs about £45 to £100 per user per month, scaling with your headcount, your security needs and how much uptime the business depends on.
Why technology and trading firms choose First Stop IT
First Stop IT has supported businesses since 2002, including software and technology companies and firms that serve financial markets. We know the systems these teams depend on: secure VPN and remote access, source control and build pipelines, virtual dev and test environments, Microsoft 365 and Teams, and the security that banks and regulators expect, from multi-factor authentication and endpoint protection to application allowlisting and email security. We work with technology and trading firms in London and across Essex and Hertfordshire. Our credentials include:
- Cyber Essentials Certified
- IASME Cyber Assurance (Gold)
- NCSC Assured Service Provider (Cyber Advisor for Cyber Essentials)
- Microsoft Partner
- Crown Commercial Service Supplier (G-Cloud)
- Quality Principles Certified
We look after more than 2,000 endpoints across 50 companies, we’ve been named a Top 50 UK MSP for three years running, and we support organisations with 10 to 100 employees across Essex, Hertfordshire and London, including Harlow and Bishop’s Stortford.
Book a free IT and cyber security review
Want early warning of a compromised account? Book a free IT and cyber security review with First Stop IT and we’ll put monitoring in place.