Blog/Account security

Malicious Email Forwarding and Filter Rules

After breaking into an email account, attackers often add hidden forwarding and filter rules to keep reading your mail and hide security alerts. How to find and remove them.

CyberWatch AI29 September 2026 · 2 min read
A laptop and phone on a desk by a sunny window

Changing your password after a hack feels like the end of the problem. Often it is not. Before they are locked out, attackers frequently set up email rules: quietly forwarding your mail to themselves, moving messages from your bank into a folder you never open, or deleting security alerts the moment they arrive. These rules keep working until you find and remove them.

What malicious rules look like

RuleWhat it does for the attacker
Forward all mail to an outside addressKeeps reading your email after you change the password.
Forward messages containing "invoice", "payment", "password", "bank"Collects the most valuable messages only, less noticeable.
Move or delete messages from your email provider or bankHides security alerts and fraud warnings.
Move replies from a particular contact to an obscure folderHides a conversation they are running in your name.
Mark as read and archiveStops you noticing new messages.

How to check

  1. Sign in to your email on the web, through the official site.
  2. Open Settings and look for:
    • Forwarding (and POP/IMAP forwarding)
    • Filters, Rules or Inbox rules
    • Blocked addresses
    • Auto-reply and signature
  3. Check any desktop email app too, as some rules live there.
  4. Look at unusual folders, such as RSS feeds, archive or folders you did not create, for moved messages.

Rules with odd names are a red flag. Attackers often give rules names like "." or ".." or a single letter so they do not stand out.

What to do if you find one

  1. Take a screenshot of the rule, including the forwarding address, for your records and any report.
  2. Delete the rule and any forwarding address you did not set.
  3. Change your password and turn on two-step verification.
  4. Sign out of all sessions and remove unknown connected apps. See checking sessions and apps.
  5. Check the hidden folders for messages that were moved, and read them. They may show what the attacker was doing.
  6. If it is a work account, tell your IT team immediately. If invoices or payments were involved, see invoice fraud and changed bank details.

Received an unexpected payment or invoice email? Paste it into CyberWatch AI Scan for a free check, and confirm by phone with the sender.

For the full recovery process, see how to recover a hacked email account and our guide to identity theft and account security.

Frequently asked questions

Why would an attacker create email rules?

To keep a copy of your mail after you change your password, to hide replies from people they are scamming in your name, and to delete security alerts so you do not notice.

Where do I find email rules?

In your email settings, under sections such as 'Forwarding', 'Filters', 'Rules' or 'Inbox rules'. Check both the web version and any desktop app you use.

Are these rules common in business email fraud?

Yes. In business email compromise, attackers often use rules to hide conversations about invoices and payments while they redirect money.

Sources

  1. Recovering a hacked account, UK National Cyber Security Centre
  2. How To Recover Your Hacked Email or Social Media Account, US Federal Trade Commission
  3. Suspicious email actions, UK National Cyber Security Centre
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.