Using classic Outlook for Windows in business environments
This points to account compromise, not just spoofing. Reappearing mailbox rules and customers receiving payment-change messages indicate someone may still have access to the mailbox.
Recommended actions:
- Check and remove malicious mailbox rules and forwarding
- In Outlook.com settings, go to Settings > View all Outlook settings > Mail.
- Check Rules and delete any rule that was not created intentionally.
- Check Forwarding and turn it off if it was enabled without approval.
- If attackers created rules before, they can use them to monitor or redirect mail even after a password change.
- Secure the account again
- Change the password to a strong, unique password that is not used anywhere else.
- Turn on multi-factor authentication. Microsoft states MFA defeats 99% of the password attacks it sees.
- If any passwords are weak or reused on other sites, change them immediately.
- Treat payment-change emails as phishing/BEC activity
- Messages asking customers to switch to ACH or change payment details are a common phishing and business email compromise pattern.
- Do not trust the display name alone. Spoofed messages can make the From field look legitimate.
- Verify whether messages were actually sent from the mailbox
- Check Sent Items.
- If the suspicious payment emails are not there, some of the activity may be sender spoofing.
- If rules keep reappearing, assume the mailbox is still exposed even if some messages are spoofed.
- Warn customers and staff immediately
- Tell them to ignore any email requesting ACH changes or payment redirection unless verified through a known phone process.
- This reduces the risk of fraudulent payments while the mailbox is being secured.
- Be cautious with suspicious messages in the mailbox
- In Outlook, a ? in the sender image or a via tag can indicate the sender could not be verified or the actual sending address differs from the displayed From address.
- Hover over the sender in Outlook on the web or new Outlook to inspect the real address when available.
- Report suspicious messages and tune filtering
- Report phishing or junk messages so filtering improves.
- If blocked senders still get through, the sender may be changing addresses or hiding the real address. Checking message headers can help identify the real sender address.
- If the account may already be hacked, follow the account recovery guidance
- Microsoft specifically directs compromised-account cases to the hacked-account recovery article linked from its Outlook protection guidance.
References:
- Spam emails in junk - Microsoft Q&A
- What to do if your email address is leaked
- Anti-spoofing protection for cloud mailboxes
- my user name is being used to send me email - Microsoft Q&A
- Phishing and suspicious behavior in Outlook
- Receiving email from blocked senders in Outlook.com
- Help protect your Outlook.com email account