Skip to content
BreachPathAttack Path LibraryStart
IntermediateAccount takeoverData theft

Phishing to executive communications compromise

A targeted lure compromises an executive or assistant mailbox, which is quietly monitored to harvest sensitive correspondence and impersonate leadership for further reach.

Technologies
Microsoft 365, Google Workspace
Entry points
Phishing
Sectors
Legal, Financial services, Professional servicesโ€ฆ
Stages
3
01

An executive or assistant mailbox is phished

The attacker crafts a tailored lure aimed at an executive or their assistant, capturing credentials and session, and gaining access to correspondence that carries unusual weight and sensitivity.

Attacker objective

Compromise a high-value mailbox close to leadership.

Controls that should stop this
  • Phishing-resistant MFA, prioritised for high-risk roles
  • Elevated monitoring and protection for executive accounts
  • Fast lure reporting and takedown
What defenders should see
  • Risky sign-ins on VIP-tagged accounts
  • Access from unfamiliar devices or locations
  • Session activity inconsistent with the user's pattern
What a pentest validates
  • Targeted social-engineering assessment of leadership and assistants
  • Review of VIP-account protections
  • Test detection tuned to high-value identities
Business impact

The attacker can read some of the most sensitive communications in the organisation.

02

The mailbox is monitored and correspondence harvested

The attacker sets quiet collection โ€” rules and synchronisation โ€” to gather ongoing and historical correspondence about deals, legal matters, finances and strategy without drawing attention.

Attacker objective

Collect sensitive information while staying invisible.

Controls that should stop this
  • Alerting on inbox-rule creation and external forwarding
  • DLP on sensitive communications
  • Session and token revocation in response playbooks
What defenders should see
  • New hide/forward inbox rules
  • Bulk historical mail access
  • External auto-forwarding configuration
What a pentest validates
  • Test detection of covert mailbox collection
  • Validate forwarding-rule alerting
  • Confirm DLP covers executive communications
Business impact

Confidential leadership correspondence is continuously exposed.

03

Leadership is impersonated for further gain

The attacker leverages the compromised mailbox โ€” or a convincing look-alike โ€” to issue instructions that others act on, from payment changes to access requests, exploiting the authority of the role.

Attacker objective

Use the trusted executive voice to drive fraud or wider access.

MITRE ATT&CK
Controls that should stop this
  • Out-of-band verification for instructions carrying financial or access impact
  • A culture where staff can question unusual executive requests
  • Look-alike-domain monitoring and external-sender banners
What defenders should see
  • Unusual executive instructions correlated with mailbox anomalies
  • Look-alike sender domains in sensitive threads
  • Requests that bypass normal process
What a pentest validates
  • Tabletop or controlled test of executive-impersonation resistance
  • Validate out-of-band verification for high-impact requests
  • Review external-sender and look-alike-domain controls
Business impact

The attacker turns leadership's authority into fraud or deeper access.

ATT&CK techniques in this chain

If this chain completes

Exposure of confidential board, deal and legal communications, plus a trusted channel for impersonating leadership โ€” enabling fraud, insider-style advantage and reputational damage.

Should you test this against your environment?

Turn this chain into a scoped red-team brief โ€” objective, systems and identities in scope, testing assumptions and the questions to answer before commissioning.