Man in the Middle Attack | Email Security Scenario
An email man-in-the-middle (MITM) attack occurs when a cybercriminal intercepts email communications between two parties without either party initially realising that their messages have been compromised.
In an email environment, attackers may gain access to a user’s mailbox through phishing, stolen credentials or a Business Email Compromise (BEC) attack. Once access is established, they can monitor conversations and wait for a suitable opportunity to intervene.

A common example involves an ongoing discussion about an invoice or financial transaction. The attacker may impersonate one of the parties and provide different bank account details, causing a legitimate payment to be redirected to an account controlled by the attacker.
Attackers can also create mailbox forwarding rules, delete messages or use lookalike domains to make the fraudulent communication appear genuine.
Effective email security therefore requires MFA, strong identity controls, mailbox monitoring, secure email authentication and procedures for independently verifying changes to payment instructions.
How to Detect an Email Man-in-the-Middle Attack
Detecting an email man-in-the-middle attack can be difficult because attackers often deliberately avoid disrupting normal email communications. Instead, they monitor conversations and intervene only when there is an opportunity to redirect a payment, obtain sensitive information or impersonate a trusted contact.
Warning signs can include unexpected changes to bank account details, unusual requests for urgent payments, subtle changes in an email address or domain, and messages that appear inconsistent with previous correspondence.
Within Microsoft 365, organisations should also investigate suspicious mailbox forwarding rules, unusual sign-in locations, unfamiliar devices, unexpected inbox rules and changes to authentication methods.
Email forensic analysis can help determine whether a mailbox was compromised and reconstruct what happened. This may involve examining email headers, message trace information, Microsoft 365 audit logs, Entra ID sign-in records and mailbox activity.
For financial transactions, any unexpected change to payment instructions should always be independently verified using a previously trusted telephone number or other communication channel.
How a Cyber Security Assessment Can Help Prevent Email Attacks
Following an email security incident—or before one occurs—a cyber security assessment can identify weaknesses that could allow man-in-the-middle attacks, Business Email Compromise (BEC) and other forms of email fraud to succeed.
A cyber assessment examines the organisation’s existing security controls and identifies areas where additional protection may be required. For Microsoft 365 environments, this can include reviewing MFA and Conditional Access, administrator privileges, mailbox forwarding, external email controls, Microsoft Defender policies, audit logging and suspicious sign-in detection.
The assessment can also review technical email security measures including SPF, DKIM and DMARC, together with newer protections such as MTA-STS, TLS-RPT and ARC.