The Email Account Takeover Crisis: Why Password Resets Alone Won't Stop Modern Attackers
Email account compromise has become the entry point for enterprise-wide breaches, with 74% of organizations targeted by business email compromise (BEC) attacks in 2025. But the real danger isn't the initial breach itself; it's what happens after attackers gain access. Password resets, the traditional response, no longer work against sophisticated adversaries who establish persistence mechanisms that survive credential changes.
What Are the Hidden Signs of Email Compromise Before It's Too Late?
Security teams often miss the early warning signals of account takeover because they're looking for the wrong things. Unauthorized password changes and suspicious forwarding rules are obvious red flags, but attackers have learned to hide their tracks more carefully. The most insidious compromise indicators include inbox rules with deliberately inconspicuous names, OAuth permissions granted to unrecognized applications, and recovery email addresses modified without the user's knowledge.
Red Canary's threat detection data ranked email forwarding rules as the sixth most prevalent threat technique across its customer base in 2025, affecting 9.2% of monitored organizations and generating 527 distinct threat detections. These rules are often named with single characters like a period or semicolon, or bland acronyms like "IT" or "ACH" that blend seamlessly into legitimate configurations during routine audits.
When an attacker gains access to an email account, the first action is often to create auto-forwarding rules that siphon every incoming message to an external address they control. Simultaneously, they may establish inbox rules that delete or hide incoming messages, suppressing evidence of their activity. A finance department email questioning an unfamiliar wire request, for example, gets routed directly to the deleted items folder before the legitimate user ever sees it.
How Are Attackers Maintaining Access Even After Password Resets?
The most critical gap in current remediation practices is the assumption that resetting a password will stop an attacker. In adversary-in-the-middle (AiTM) phishing campaigns, this assumption is dangerously wrong. Microsoft Defender researchers uncovered a multi-stage AiTM and BEC campaign targeting energy sector organizations that demonstrates why conventional response procedures fail.
In AiTM attacks, the attacker doesn't just steal the password; they steal the active session cookie that authenticates the user to the email system. Even if the legitimate user resets their password, the attacker's stolen session cookie remains valid. More critically, attackers add new multi-factor authentication (MFA) methods to the compromised account, such as one-time password (OTP) authentication tied to a phone number they control. This means the attacker can regain access at will, regardless of password changes.
The energy sector campaign Microsoft analyzed involved a phishing email sent from a compromised trusted vendor, using a SharePoint URL that appeared legitimate. Once users clicked and entered credentials, the attacker gained access and immediately created inbox rules to delete incoming emails and mark them as read. The attacker then launched a large-scale phishing campaign to 600+ contacts, both internal and external, using the compromised account's trusted relationship to increase click-through rates.
Steps to Detect and Contain Email Compromise Before It Cascades
- Monitor for account recovery changes: Audit recovery email addresses, backup phone numbers, and security questions on a regular basis. Email providers log every administrative change to these settings, so any modification without the user's explicit action is a compromise indicator that demands immediate investigation.
- Audit OAuth permissions and active sessions: Attackers use consent phishing to trick users into approving malicious OAuth applications that grant persistent mailbox access even after password resets. Revoking unrecognized OAuth grants and terminating active session cookies is as urgent as resetting stolen passwords.
- Hunt for suspicious inbox rules and forwarding: Implement automated scanning for inbox rules with suspicious names, forwarding rules to external domains, and rules that delete or hide messages. These are among the most common persistence mechanisms attackers use to maintain control and evade detection.
- Revoke MFA settings changes: If an attacker modifies MFA methods on a compromised account, password resets alone will not regain control. Organizations must revoke all MFA settings changes and re-enroll the user with MFA methods they control.
- Implement continuous access evaluation: Deploy conditional access policies that evaluate sign-in requests using additional identity signals like user location, device status, and IP address. Risk-based policies can automatically block suspicious sign-ins that match attacker patterns.
The FBI's Internet Crime Complaint Center reports over $55 billion in cumulative business email compromise losses between 2013 and 2023. The scale of financial damage reflects how quickly a single compromised email account can escalate into wire fraud, vendor impersonation, and lateral network movement.
Why AI-Generated Phishing Makes Detection Even Harder?
The threat landscape has shifted dramatically with the weaponization of artificial intelligence in phishing campaigns. Generative AI tools are dramatically increasing the effectiveness of phishing emails. Control-group phishing emails achieved a 12% click-through rate, while fully AI-generated phishing emails reached 54%, and human-in-the-loop AI approaches achieved 56%.
Attackers are using purpose-built AI models like WormGPT and FraudGPT, which are specifically designed to generate phishing emails and malicious code without the safety guardrails of mainstream tools like ChatGPT or Gemini. These models are sold on dark web marketplaces and enable attackers to scale personalized phishing campaigns at unprecedented speed.
Beyond email text, attackers are using AI to predict which employees are most vulnerable to specific attack angles. Machine learning models analyze open-source intelligence (OSINT) from social media, gaming profiles, and even Spotify listening habits to build detailed profiles of target employees. Voice cloning technology, which requires only brief audio samples from public sources, enables attackers to impersonate executives in phone calls or voicemail messages.
The 2024 deepfake CFO scam that CNN reported, in which a cloned executive's voice convinced an employee to wire $25 million, has become a template for attackers. Now that sufficient public data exists for most professionals, attackers can predict who on a target list is likely to fall for a given pitch before the attack even begins.
What Remediation Steps Go Beyond Password Resets?
Microsoft Defender Experts identified that standard identity compromise remediation is insufficient for AiTM attacks. Organizations must take additional steps beyond password resets to fully contain the breach.
The recommended remediation approach includes revoking all active session cookies in addition to resetting passwords, revoking any MFA setting changes made by the attacker, and deleting all suspicious inbox rules created on the compromised account. These steps must be executed rapidly; containment windows are measured in minutes rather than days.
Organizations should also complement MFA with conditional access policies that evaluate sign-in requests using additional identity-driven signals. These signals include user or group membership, IP location information, and device status. Risk-based access policies can automatically block sign-in attempts that match known attacker patterns, even if the attacker possesses valid credentials.
Implementing continuous access evaluation ensures that compromised sessions are revoked in real time, rather than remaining valid until the next scheduled token refresh. Advanced anti-phishing solutions that monitor incoming emails and visited websites provide an additional layer of defense against AI-generated phishing and credential harvesting attacks.
The operational complexity of modern email compromise campaigns demands that security teams move beyond reactive password resets and implement proactive detection of the early warning signs. Account-level anomalies like unauthorized password changes, suspicious forwarding rules, and MFA prompts no one initiated surface long before a breach becomes public. Organizations that learn to detect these signals systematically can stop account takeovers before they cascade into cloud compromise, regulatory exposure, and financial loss.