Blog Post

Is Your Email Being Hijacked?

In the world of email security, most people worry about spam, phishing, and hacked passwords. However, a sneakier threat often goes unnoticed, these are malicious forwarding rules. This type of attack involves someone creating a hidden rule in your inbox that forwards every email you send or receive, to an external address controlled by the attacker. This allows them to silently monitor your communications, gather sensitive information, and execute more targeted attacks without raising any immediate alarms.

How Does This Attack Work?
If a hacker gains access to your email account, even briefly, they can create a forwarding rule that automatically sends a copy of every email to a malicious address. This isn’t just limited to obvious rules like “forward all emails.” Attackers often use more subtle methods, such as rules that only forward emails containing specific keywords or from particular senders, making them even harder to detect.

How to Check for Malicious Forwarding Rules

  1. Microsoft Outlook (Desktop & Web)
    • Go to Settings > View all Outlook settings > Mail > Rules
    • Look for any rules you don’t recognize, especially those involving forwarding. Delete any suspicious rules immediately
    • Also, check Settings > Forwarding to ensure no unexpected forwarding address is listed
  2. Gmail
    • Go to Settings > See all settings > Filters and Blocked Addresses
    • Review any forwarding rules or filters that seem unfamiliar
    • Then, go to Forwarding and POP/IMAP to see if any unexpected addresses are set to receive your emails
  3. General Tips
    • Change your password immediately if you find anything suspicious
    • Enable multi-factor authentication (MFA) to add an extra layer of security
    • Review sign-in activity for any unfamiliar devices or locations

Malicious forwarding rules are a subtle yet powerful way for attackers to spy on your communications without raising alarms. Regularly reviewing your email settings is a simple but effective way to protect your data and privacy.

For more information on protecting your sensitive data and personal information, get in touch with us at JGC IT Services.

author avatar
Gary Curtis