The Email Rule Nobody Wrote
At 10:28 last night, a monitoring alert fired on a mailbox we look after. Nobody had logged in from a strange country. No password had been guessed. No email had gone out. What happened was smaller than that: an inbox rule appeared on the account, the kind you set up in Outlook to file newsletters into a folder. Within the same minute the monitoring system acted on it and raised the alert to a person.
That is the whole story, and it is one of the most important patterns in small-business email security. So here is what a rule like that is actually for.
Why an attacker's first move is a filing rule
Picture someone who has just got hold of an employee's Microsoft 365 password. Maybe it was phished, maybe it was reused from a site that got breached years ago. They log in. They can now read everything, and they can send as that person.
What they want is money, and the reliable way to get it is patience. The FBI's running tally of this crime, which it calls business email compromise, sits at more than $55 billion in reported losses across three hundred thousand incidents. Almost none of that came from a single dramatic email. It came from an attacker sitting inside a real conversation about a real invoice and changing one bank account number at the right moment.
To do that, they need two things. They need the mailbox owner not to notice them, and they need time. An inbox rule gives them both.
The rules they create do three jobs. Some forward copies of everything to an outside address, so the attacker keeps reading even after the password is changed. Some watch for replies from a particular vendor or the bank and move them straight into an obscure folder, so when the attacker sends a fake payment-change request from the real account, the real reply never reaches the real employee. And some simply delete: any message containing words like "invoice," "wire," "password," or "suspicious" vanishes before the owner sees it.
Microsoft's own guidance on this describes the pattern plainly: after gaining access, the attacker's next step is to establish a way to stay in, and Outlook rules are one of the two mechanisms they reach for. Microsoft also notes the part most people find unsettling. Because rules live in the mailbox and not on the computer, giving the employee a new laptop changes nothing. The rule syncs right back.
Why nobody notices
An inbox rule is invisible in normal use. It does not appear in the inbox, it does not generate a notification, and Outlook does not tell you when one was created. The employee keeps working. Mail keeps arriving, minus the messages the rule is quietly hiding. The first sign anyone gets is usually a vendor calling to ask why the payment went to a different account, or a customer asking why they were told to pay a new one.
That is why the rule creation itself is the alert worth having. It is the earliest observable moment in the whole sequence. Everything before it (the phishing email, the stolen password, the login) can be made to look normal. Everything after it is the attacker being careful. The rule is the one step they cannot skip and cannot hide from a system that is watching for it.
What "watching for it" means in practice
Microsoft 365 keeps a record every time a rule is created or changed on any mailbox in a company. What most businesses lack is anything reading that record.
The setup that caught last night's rule reads it continuously. A new rule on any monitored account triggers an automatic action inside a minute and a person is told. The follow-up is a forced password reset and a review of where the account has been signing in from. The first step is automatic because the window matters. An attacker who gets a forwarding rule in place has a copy of every message from that point on, and the value of a mailbox to a criminal is measured in the number of conversations they get to read.
Last night's rule may well turn out to be a member of staff setting up a filter from a new device. The account gets the same treatment either way, because the check cannot tell the difference until someone looks, and that is the right way round. The cost of a false alarm is a password reset and a five-minute call. The cost of the other outcome is a wire transfer.
What to ask about your own mailboxes
You do not have to run any of this yourself. You do have to know whether anyone is.
Is anyone watching for new inbox rules and forwarding rules on your accounts? Not quarterly, continuously. If your IT provider cannot answer that in one sentence, the answer is no.
What happens when one appears? The right answer includes the words "removed" and "password reset" and a time measured in minutes. "We would see it in the logs" means nobody would see it.
Is multi-factor sign-in turned on for every account, including the shared ones? Rules only matter once an attacker has the password. Microsoft is blunt that this is the first line, and we would add that the accounts most often skipped are the generic ones: accounting@, info@, the old owner's mailbox that still receives things.
Does anyone review the rules that already exist? A rule planted six months ago is still running today. A one-time sweep of every mailbox for forwarding and deletion rules is an afternoon's work and tends to turn up at least one surprise.
The part worth sitting with
Every business owner has been told to worry about phishing, and they should. But the phishing email is the doorbell. The inbox rule is the attacker moving in. If you only watch the door, you find out what happened when the money is already gone. If you watch for the moving in, you catch it while the boxes are still in the hallway.
When was the last time anyone looked at the rules running on your mailboxes, and would you know within a minute if a new one appeared tonight?
Sources: Microsoft Learn, "Detect and remediate Outlook rules and custom forms injection attacks," updated August 2026; FBI Internet Crime Complaint Center, "Business Email Compromise: The $55 Billion Scam," September 11, 2024 (305,033 incidents, $55.5 billion in reported losses, October 2013 to December 2023); Microsoft Security, "Email threat landscape: Q2 2026 trends and insights," July 23, 2026. The alert described is from our own monitoring and identifies no organization or person.
Get the next one by email
A new post most Tuesdays, written for the person who runs the business. One email per post, unsubscribe any time.