Spoofed Emails

angel ready-contractors.com 0 Reputation points
2026-09-11T17:28:20.31+00:00

I am receiving emails from addresses with a letter or number off asking to receive payments by ACH and vice versa. I have had customers call me saying have received emails from "me" asking to be paid by ACH. I have changed passwords several times. They are also adding rules to my email. I go in and delete, but they keep popping back up. Please help

Outlook | Windows | Classic Outlook for Windows | For business

2 answers

Sort by: Most helpful
  1. Jay1 Tran 605 Reputation points Independent Advisor
    2026-09-11T18:43:49.8866667+00:00

    Hi,

    Based on what you described, including fraudulent ACH requests, messages sent from lookalike email addresses, and inbox rules that keep returning, your Microsoft 365 email account may be compromised.

    Changing the password alone may not remove an attacker if they still have an active session, a connected application, automatic forwarding, or another method of access. Please contact your Microsoft 365 administrator or IT security provider immediately and ask them to try the following steps:

    1. Temporarily block access to the account
    • Sign in to the Microsoft 365 Admin Center with a Global administrator account.
    • Go to Users > Active users.
    • Select the affected user.
    • Select Block sign-in.

    User's image

    • This temporarily prevents additional access while the account is being secured.
    1. Reset the password from a trusted device
    • Still on the affected user page, select Reset password.

    User's image

    • Use a new, unique password that has not been used for any other account.
    • Reset the password from a trusted computer after the computer has been scanned for malware.
    • Do not save the new password in an unfamiliar browser extension or password manager.
    1. Revoke all active sessions

    User's image

    • This is important because an unauthorized person may still have an authenticated session, even after the password has been changed.
    1. Enable multifactor authentication
    • On the affected user page, select Authentication methods.
    • Remove any authentication method, phone number, email address, or device that is not recognized.

    User's image

    1. Remove suspicious inbox rules
    • Sign in to Outlook on the web: https://outlook.office.com
    • Select Settings > Mail > Rules.
    • Delete any rule that is not recognized.
    • Pay particular attention to rules that:
      • Forward or redirect messages
      • Delete messages automatically
      • Mark messages as read
      • Move messages to Archive, Junk Email, Deleted Items, Notes, or RSS Subscriptions
      • Contain terms such as “payment,” “ACH,” “invoice,” “bank,” “fraud,” or “phishing”
    • Because the rules keep returning, the Microsoft 365 administrator should also check for hidden inbox rules using Exchange Online administrative tools.
    • If a rule returns after being deleted, treat that as an indication that unauthorized access may still be active.
    1. Check mailbox forwarding
    • Sign in to the Exchange Admin Center.
    • Go to Recipients > Mailboxes.
    • Select the affected mailbox.
    • Open Mailbox settings > Manage email forwarding.

    User's image

    • Remove any forwarding address that is not recognized or authorized.
    • The affected user should also sign in to Outlook on the web at https://outlook.office.com and check Settings > Mail > Forwarding.
    • Confirm that forwarding is disabled unless there is a legitimate business reason for it.
    1. Review mailbox permissions and delegates
    • On the affected mailbox page, open Delegation or Mailbox delegation.
    • Review the following permissions:
      • Send as
      • Send on behalf
      • Read and manage, also called Full Access

    User's image

    • Remove any person, mailbox, or account that should not have access.
    1. Review recent sign-in activity

    User's image

    • Review the entries for unfamiliar:
      • Locations
      • IP addresses
      • Devices
      • Applications
      • Browsers
      • Sign-in dates and times
    • IP-based locations are approximate, so the administrator should review all available details together.
    • Save or export suspicious sign-in information before making changes, since it may be needed for the investigation.

    I hope the information I shared earlier was somewhat helpful in addressing your issue. If you have any further questions or updates, please don’t hesitate to share. I’m always happy to assist further if needed.   

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-09-11T17:28:39.26+00:00

    This points to account compromise, not just spoofing. Reappearing mailbox rules and customers receiving payment-change messages indicate someone may still have access to the mailbox.

    Recommended actions:

    1. Check and remove malicious mailbox rules and forwarding
      • In Outlook.com settings, go to Settings > View all Outlook settings > Mail.
      • Check Rules and delete any rule that was not created intentionally.
      • Check Forwarding and turn it off if it was enabled without approval.
      • If attackers created rules before, they can use them to monitor or redirect mail even after a password change.
    2. Secure the account again
      • Change the password to a strong, unique password that is not used anywhere else.
      • Turn on multi-factor authentication. Microsoft states MFA defeats 99% of the password attacks it sees.
      • If any passwords are weak or reused on other sites, change them immediately.
    3. Treat payment-change emails as phishing/BEC activity
      • Messages asking customers to switch to ACH or change payment details are a common phishing and business email compromise pattern.
      • Do not trust the display name alone. Spoofed messages can make the From field look legitimate.
    4. Verify whether messages were actually sent from the mailbox
      • Check Sent Items.
      • If the suspicious payment emails are not there, some of the activity may be sender spoofing.
      • If rules keep reappearing, assume the mailbox is still exposed even if some messages are spoofed.
    5. Warn customers and staff immediately
      • Tell them to ignore any email requesting ACH changes or payment redirection unless verified through a known phone process.
      • This reduces the risk of fraudulent payments while the mailbox is being secured.
    6. Be cautious with suspicious messages in the mailbox
      • In Outlook, a ? in the sender image or a via tag can indicate the sender could not be verified or the actual sending address differs from the displayed From address.
      • Hover over the sender in Outlook on the web or new Outlook to inspect the real address when available.
    7. Report suspicious messages and tune filtering
      • Report phishing or junk messages so filtering improves.
      • If blocked senders still get through, the sender may be changing addresses or hiding the real address. Checking message headers can help identify the real sender address.
    8. If the account may already be hacked, follow the account recovery guidance
      • Microsoft specifically directs compromised-account cases to the hacked-account recovery article linked from its Outlook protection guidance.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.