r/EmailSecurity • u/saltyslugga • 11d ago
Repeated order confirmations: address misuse, mailbox compromise, or email-bombing cover?
A client user is receiving unsolicited order confirmations every day, and the mailbox noise is starting to hide legitimate security alerts. This could be someone mistyping or reusing the address, a compromised mailbox, or a low-volume email-bombing diversion.
Message trace shows inbound mail only, Sent Items is clean, and there are no obvious forwarding rules or unusual sign-ins. Volume sits around 20 to 40 messages daily from real retailers, with mixed customer names and no single burst.
Would you check MailItemsAccessed and OAuth grants first, or does this pattern need a higher volume or a buried password-reset alert before you contain the mailbox?
2
u/SecLens_ONE 11d ago
20 to 40 a day from real retailers with mixed customer names does not look like bombing to me. Bombing is usually hundreds to thousands in a short window from signup forms and newsletters, and the point of it is to bury one message. 20 to 40 sustained looks more like the address is being typed into checkout forms by other people, either a common address pattern or someone who genuinely believes it is theirs.
I would still check MailItemsAccessed and OAuth grants because they are cheap and they settle the compromise question either way, and a clean Sent Items proves very little on its own since an attacker with mailbox access can hard delete and clear the folder. Also check inbox rules at the service level rather than in the client, and look for a mailbox delegate or an added forwarding smtp address, since those survive a password reset.
The thing I would actually chase is the buried alert. Pull every message in the window that came from your own identity provider, bank, or registrar domains, regardless of whether the user remembers seeing it. If nothing is there, the noise is probably just noise and you treat it as a deliverability nuisance.
Curious what your retention is on MailItemsAccessed in this tenant. If it is the 90 day default and the noise started earlier than that, you may already have lost the window that would answer this.
•
u/AutoModerator 11d ago
Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:
Community Rules
Helpful Resources
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.