← Back
Category 14: Channel Security, Account Safety, Phishing & Hack Prevention

Email forwarding rules can silently redirect security-sensitive messages after an email account compromise.

Problem

Email forwarding rules can silently redirect security-sensitive messages after an email account compromise.

Solution

Root Cause / Diagnostic:
Infostealers and session hijackers frequently create silent mail forwarding rules immediately upon gaining inbox access. These rules forward 2FA verification emails, Google security alerts, and brand correspondence to an attacker-controlled drop address without triggering user warnings.

Actionable Fix:
1. Navigate to Google Admin Console (Apps > Google Workspace > Gmail > Routing) and disable automatic external email forwarding across the entire domain.
2. Run an immediate API audit via Google Workspace Security Investigation Tool to query all user mailboxes for active forwarding rules and POP/IMAP filters.
3. Review user mailbox settings in Gmail (Settings > Forwarding and POP/IMAP) and remove any unrecognized external addresses.

Pro Tip:
Enable automated compliance rules in Gmail to quarantine outgoing messages containing keywords like 'verification code', 'security alert', or 'password reset' sent to external domains.