July 31st, 2026
The Inbox Threat: Why Email Compromise Deserves Your Attention
Cybersecurity is a top priority for businesses and individuals alike, and ransomware usually gets the headlines because it locks up systems and halts operations. But a quieter, more common threat costs just as much: email compromise.
Email compromise doesn’t discriminate. Businesses and individuals are both targeted, and both can be devastated. Attackers often extract more from a business account, but a compromised personal account can be just as painful proportionally – sometimes wiping out a person’s savings in one transaction.
It’s almost always about money or sensitive information. Attackers can’t drain every account they break into, but their tactics are effective. Once an account is compromised, attackers often use it to phish that person’s own contacts. It works well because the message comes from someone already trusted. The attack then spreads person to person.
From there, attackers cash in. A common method is wire fraud: after reading a compromised inbox, the attacker learns who’s expecting a payment and inserts themselves into that conversation to redirect the wiring instructions. They’ll also often set up hidden mail-flow rules that bury replies from the real recipient, so the victim never sees the conversation continuing and never gets alerted.
The basics still matter. Use a strong, unique password, and enable multi-factor authentication (MFA) everywhere it is offered. Be suspicious of any email pushing you to log in via a link, change payment details, or share sensitive information – especially under urgency.
But attackers have adapted around MFA. One method, adversary-in-the-middle phishing, can allow an attacker to compromise an account, even if it is protected by MFA. The victim clicks a link to what looks like a normal login page – really it is a proxy that passes everything typed, including the MFA code, through to the real site in real time. Because the login is genuine, MFA succeeds. The attacker isn’t stealing a password; they’re stealing the active session afterward, letting them into the account without ever entering credentials themselves.
We’ve also seen attackers phish victims into installing legitimate remote access software, then quietly take control of the computer — sending emails, running further malware, and pulling saved browser passwords, all while the victim is away from their desk.
A newer trick circumventing MFA entirely is device code flow abuse, which has gained a lot of popularity recently. Microsoft built this feature to let devices without an easy sign-in method — like a physical conference phone — display a code that a user enters on another device to log in, similar to signing a smart TV into a streaming service. Attackers now send victims a code and link, and when the victim signs in, they’re unknowingly logging the attacker’s device into their account. Since it’s a genuine sign-in, MFA succeeds and offers no protection.
For businesses, this calls for more than user training. Email platforms need monitoring that flags risky sign-ins and can automatically contain them, plus a tenant configuration reviewed for security — not just left on defaults. Microsoft 365’s out-of-the-box settings favor productivity over security, and many default configurations leave real gaps that attackers know to look for.
What this means for you. Strong passwords and MFA remain essential, but they’re no longer a complete answer. Treat any unexpected request to log in, verify your identity, or approve a payment as worth a second look, and confirm anything involving money through a separate channel, like a phone call. Email compromise spreads through trust – staying a little skeptical, even with messages from people you know, is one of the best defenses available.