Business email compromise (BEC) is consistently one of the highest-value cyber crimes targeting Australian businesses. Unlike ransomware, which announces itself loudly, email account takeover often goes undetected for days or weeks. An attacker with access to a business email account can monitor correspondence, intercept payment requests, and position themselves to redirect funds before anyone notices anything is wrong. These are the signs to look for.
Mailbox changes that matter
The first thing an attacker typically does after gaining access to an email account is set up persistence — a way to maintain access even if the password is changed. The most common method is creating a mailbox forwarding rule that silently copies all incoming mail to an external address. This means that even after a password reset, new emails continue to go to the attacker.
Check your inbox rules or filters in your email settings. Look for any rules you did not create, particularly those that forward email to an external address, mark messages as read without displaying them in your inbox, or move emails to folders (especially Deleted Items or subfolders) automatically. These rules may be set up to hide specific types of correspondence — like bank notifications or supplier invoices — from your view while forwarding them to the attacker.
Also check whether any auto-reply or out-of-office messages are active without your knowledge. An attacker may configure an auto-reply to gather information about who is contacting you, or to buy time by explaining your "absence" to correspondents who might otherwise raise an alarm about unusual activity on your account.
Suspicious sign-ins and impossible travel
Most email platforms log sign-in activity, including the location (based on IP address), device, and time of each login. Review this log regularly — it is usually found under Security settings or Activity. Look for sign-ins from countries you have not visited, cities you do not recognise, or times when you were clearly not working (the middle of the night, or during a period when you were travelling somewhere else).
"Impossible travel" is a term used in security monitoring: a login from Sydney at 9am followed by a login from Eastern Europe at 9:30am is physically impossible and indicates that a second party has your credentials. Even without sophisticated tooling, reviewing your sign-in log periodically will surface this kind of anomaly.
New devices appearing in your "trusted devices" or "connected apps" list without your knowledge are also worth investigating. Attackers sometimes add their device as a trusted device to avoid triggering further MFA prompts.
Why one mailbox can expose a whole business
A compromised business email account is not just a problem for the account holder. For a small business, the owner or finance manager's email account is typically the one receiving bank statements, supplier invoices, payment confirmations, and staff communications. An attacker with access to this account has a complete picture of the business's financial flows — who you pay, when, how much, and using which bank accounts.
They can use this knowledge to send convincing fake invoices to your clients (using your email address), intercept a supplier payment by substituting their own bank account at the right moment, or conduct reconnaissance over weeks before executing a larger fraud.
- Check inbox rules and filters — look for any that forward, hide, or redirect email.
- Review sign-in activity in your email platform's security settings.
- Look for sign-ins from unexpected locations or at unusual times.
- Check connected apps and trusted devices for anything you did not authorise.
- Enable multi-factor authentication if not already active — it significantly raises the bar for attackers.
- If you find a forwarding rule you did not create, treat it as a confirmed compromise and act accordingly.
Business email compromise often starts quietly before money or data is touched.
Check email login security