Hidden Inbox Rules: How Philadelphia Insurance Agencies Can Prevent Email Fraud

A producer at an insurance agency clicks a login page that looks right, enters her password, and realizes a minute later that it wasn’t. She changes the password, turns on MFA, and breathes out. Two weeks later, a client says they paid a premium to a new bank account “per your email.” She never sent it.

The password was never the whole story. Somewhere in that mailbox is a small, quiet setting—an inbox rule—that the attacker created while they were in. For insurance brokerages handling premiums, policy changes, and certificates for dozens of clients, hidden inbox rules and email compromise in Philadelphia offices are a pattern worth knowing. They follow the same playbook as the scam emails that look real we’ve written about.

What an Inbox Rule Actually Does

An inbox rule is the same feature you use to file newsletters into a folder. In an attacker’s hands, it can become a way to keep receiving copies of your mail without signing in again.

Common Inbox Rules Attackers Create

  • Forwarding every message containing words like “invoice,” “payment,” or “wire” to an outside address.
  • Moving replies from clients into RSS Feeds, Archive, or Deleted Items so you never see them.
  • Marking certain messages as read so nothing looks unusual.
  • Naming the rule something blank, a single dot, or a string of symbols so it’s easy to miss.

Why a Password Reset Doesn’t Remove the Rule

Because the rule lives inside the mailbox, resetting the password doesn’t remove it. If external forwarding remains enabled, the attacker can read along, then send a convincing message from a lookalike address at exactly the right moment.

Why Insurance Offices Get Targeted

Agencies sit in the middle of money and trust. Clients expect emails about premiums, endorsements, and certificates of insurance, so a message about “updated payment instructions” may not raise eyebrows.

An attacker reading those threads can time a fraudulent request to match a real renewal, which is far more believable than a cold phish.

How to Check Your Own Mailbox in Five Minutes

Review Your Inbox Rules

Open Outlook on the web, go to Settings, then Mail, then Rules. Look for anything you didn’t create, especially rules that forward, redirect, or delete messages.

Check Mailbox Forwarding

Also check Forwarding in the same Settings area. Look for an unfamiliar destination address or forwarding you didn’t enable.

Save Evidence Before Removing Anything

If you find something odd, don’t just delete it. Screenshot it first, because it’s evidence of what the attacker was after. Share it with your IT provider so they can investigate.

What Your Agency Should Have in Place

Block Automatic External Forwarding

Block automatic external forwarding at the Microsoft 365 level so mailbox rules cannot automatically send messages outside the agency.

Set Alerts for Suspicious Inbox Rules

Set alerts for new inbox rules, especially forwarding, deleting, or hiding rules. Send those alerts to someone who actually reads them.

Use Phishing-Resistant Sign-In

Moving staff to passkeys helps address stolen-password attacks at the source.

Follow a Mailbox Compromise Checklist

After any suspicious login, check rules, forwarding, connected apps, and sign-in history—not just the password.

If you’ve ever wondered why “we reset it” doesn’t always end the story, this can be why. Cleanup has to include what the attacker left behind.

The Rule Isn’t the Only Thing They Leave Behind

Review Other Ways an Attacker Could Keep Access

Attackers may also authorize third-party apps that retain access after a password change, add their own phone number as a sign-in method, or set up forwarding on a shared mailbox the team rarely opens.

A thorough cleanup reviews rules, forwarding, connected apps, authentication methods, registered devices, and recent sign-in activity. Unfamiliar locations can help identify suspicious activity, although location alone doesn’t establish what was exposed.

Notify Affected Clients

It’s also worth discussing prompt client notification with your IT provider and the appropriate person at your agency if client emails were exposed. A short, honest heads-up can help clients recognize a fraudulent payment request before acting on it.

When Something Already Looks Wrong

Call your IT provider before replying to the suspicious thread, and verify any changed payment instructions by phone using a number you already have on file.

Our step-by-step guide on what to do in case of a cyberattack walks through the first hour.

Have Abuzz Technologies Check Your Agency’s Mailboxes

Want someone to check your mailboxes for rules you didn’t write? Call (215) 600-0349 or visit www.abuzztech.com.