Now Available: Active Cyber Insurance for Enterprises
Cyber Incident? Get Help

Inbox In-Fighting: A Window Into BEC Subculture

Inbox In-Fighting: A Window Into BEC Subculture

If you work in cybersecurity incident response, threat detection, or cyber insurance, you know the standard Business Email Compromise (BEC) playbook.

A threat actor compromises an inbox and immediately sets up email routing rules to hide their tracks and intercept targeted communications. The rules these threat actors create display easily detectable, obvious characteristics.

But what happens when two independent attackers bump into each other inside the same corporate inbox? They don't just quietly ignore each other: they talk. And surprisingly, they often use the names of the inbox rules themselves as a rudimentary chat channel, meaning rules can teach us even more about them than how they redirect email.

These hidden conversations offer a fascinating, rarely seen window into the BEC subculture and provide insights into threat actors' geographies, operational tactics, attitudes, and collaborative dynamics.

How threat actors abuse email routing rules

Abusing inbox rules to evade detection (MITRE ATT&CK T1564.008) is a widespread tactic. Threat actors seek persistent access to compromised accounts to gather sensitive data, launch secondary phishing campaigns, or communicate with high-value targets. In the meantime, they do not want the compromised individual to notice any strange incoming emails or security alerts. 

To the attacker’s advantage, most email platforms support automated rules by default. Threat actors can easily exploit this functionality to hide, redirect, or forward emails containing flagged keywords, such as “invoice” or “confidential.”

Inside the rule name chat room

When multiple attackers compromise a high-value target, their paths can overlap. One threat actor might delete another’s hiding rules or launch a clumsy attack that risks exposing the compromise for everyone.

Less commonly observed, individual threat actors may actually communicate within the name of an inbox rule, as Coalition Incident Response* (CIR) recently documented in an investigation:

"brr ... i've been observing this box for a while and i knew when you wrote this job, i'm sure you noticed i moved some stuffs too, i didn't want to ruin your job, [and make] a mess of the whole thing. write me on TG (telegram) @[username]. let's talk"

The recorded threat actor is observing, calculating, and highly aware of the other intruder's presence. They act independently but appear willing to work together to ensure neither ruins the payout.

Sometimes, the interactions are far less polite. In another incident, CIR observed a prolonged, heated argument between two threat actors fighting for control over an inbox, all documented in a sequence of rule names.

Note: The following sequence contains the exact rule names created by the attackers, featuring heavy use of language consistent with Nigerian Pidgin and similar regional vernaculars:

"Bro.. I See U De Inside The Box But Na Diff Job | De Do Entirely Naw. Make We Nor Cast The Box. Let Work It Togeda. Gv Me Ur ICQ"

"bro u doing like u smart …..u all fool jst know cos i can even stll call the pelle diredit spoil everthing ...so make we all comply"

"u dey very stupid.. U ENTER boss see person still dey delete my filter.. God punish u there"

"BRO.. GIVE ME UR ICQ... STOP! DELETING FILTERS. I'M TRYING TO COMMUNICATE WITH YOU BRO."

"IF YOU DE INSIDE FOR 100 YEARS DOES THAT MATTER? I DE DO MY OWN JOB AND YOU ARE DOING YOURS. NA TODAY YOU START THIS GAME? DON'T ADDRESS PPLE YOU DON'T KNOW AGGRESSIVELY. GV ME UR ICQ."

"Of course, I have studied the box and I see na CEO dem approved all wire payment from their online wire Portal. Meanwhile, ACH needs no approval from Administrator so I know what I'm doing. ICQ: @[username]"

"DOESN'T MEAN WORK DON CAST. Controller, CEO and CFO direct fake invoice Instructions these days is by God's Grace. I will still respond to her."

"BRO IF U RELAX AND AGREE TO WORK WITH ME WE GO CHOP THIS BOX. NA PATIENCE WE NEED.."

"Bro... Make U No Use $12K Job Spoil Dis Box Naw... Owfa Wetin De ?"

rules-ui-screenshot

Takeaways from attacker activity 

Beyond the sheer novelty of attackers fighting across inbox rule names, these chats provide important threat intelligence:

Geography and Culture

The heavy use of Nigerian Pidgin ("Make We Nor Cast" / "Owfa Wetin De") strongly ties this specific activity to well-documented West African BEC rings, although language alone does not establish the threat actors’ location or identity. "Nor cast the box" can be read as "don't expose or ruin the compromised inbox," while "chop this box" means to profit from it.

Tactics and Target Casing

The attackers aren't just blindly sending invoices; they often study the organization's specific approval workflows. One threat actor explicitly notes that wire transfers require CEO approval via an online portal, but ACH transfers do not require administrator approval. They are doing their homework once in the inbox. The time this takes can benefit the defender, and it also shows the importance of non-IT protections such as secure payment approval workflows.

Tradeoff Analysis

"Make U No Use $12K Job Spoil Dis Box Naw." The attackers are actively weighing the risk vs. reward. One actor is warning that the other is attempting a "small" $12,000 scam that might alert the victim and ruin a potentially much larger payday.

Email providers should adopt a “secure by default” posture 

The fact that threat actors can comfortably create dozens of rules with full-sentence names, explicitly routing "invoice" and "wire" emails to the RSS Feeds folder, is a serious gap in default platform security. 

Microsoft and other major email providers have the telemetry to see this happening at scale, yet organizations remain vulnerable to the exact same rudimentary techniques year after year. In most organizations, legitimate rule creation is rare, and legitimate use of some of these built-in folders is even rarer.

If we want to actually materially reduce BEC, providers need to adopt a "secure by default" posture. For example:

  • Disable inbox rules by default. Most users do not need complex, custom email routing rules. Email providers should make this an opt-in feature that requires admin approval, and keep an eye on the much-reduced attack surface.

  • Alert on or even block sentence-length or nonsensical rule names. No legitimate user names a rule BRO IF U RELAX AND AGREE TO WORK WITH ME WE GO CHOP THIS BOX. Or a few commas or periods (,, or ..).

  • Alert on payment-related criteria. A rule automatically moving emails containing "ACH", "Wire", or "Invoice" out of the primary inbox should immediately trigger a high-severity alert, in the spirit of risky Sign-ins and other Entra protections.

  • Disable common "hiding places" by default. Threat actors love routing emails to the RSS Feeds or Conversation History folders because users rarely check them. These should be disabled by default, and even when available, should only accept routing from known-approved sources (not via rules).

  • Disable external forwarding by default. Whether via SMTP or an inbox rule, auto-forwarding corporate mail to an external address should be blocked out of the box.

Threat actors are quite literally chatting with each other in our inboxes because they feel safe doing so. If teams or users really need these features, their administrators can turn them back on, in the meantime improving baseline defaults. Until the platforms we rely on start aggressively blocking these easily detectable evasion techniques by default, BEC will continue to drive cyber claims. 

Start monitoring for suspicious activity

We believe that email providers play an important role in systematically reducing the popularity of BEC among cyber attackers. But we also know that a sweeping change to inbox rule features is likely not coming tomorrow. In the meantime, businesses should take appropriate measures to reduce their risk and mitigate suspicious activity before it escalates to financial loss.

To prevent the fraudulent transfer of funds, every second counts. Wirespeed Automated Detection & Response (ADR) is designed to contain threats in milliseconds and automatically take action when suspicious mailbox rules are created. Wirespeed ADR uses deterministic logic to confirm threats as malicious and reset credentials via API to block further activity — with 99% of detections resolved in under 754 milliseconds.**

Learn more about how Wirespeed stops attacks with deterministic speed.


LIGHTNING-FAST SPEED. LASER PRECISION.

Wirespeed Automated Detection & Response 

Start your free 30-day trial >


* Coalition Incident Response, Inc. dba Coalition Security, an affiliate of Coalition Inc., provides security products and services globally. Coalition Security does not provide insurance products and products and services may not be available in all countries and jurisdictions.
** Based on average Wirespeed data from March–June 2026. Response time refers to how quickly Wirespeed determines whether an alert requires escalation; excludes ingestion-source delays from third-party platforms.
This blog post is designed to provide general information on the topic presented and is not intended to construe or render legal or other professional services of any kind. If legal or other professional advice is required, the services of a professional should be sought. Neither Coalition nor any of its employees make any warranty of any kind, express or implied, or assume any legal liability or responsibility for the accuracy, completeness, or usefulness of any information, product, or process disclosed. Any action you take upon the information contained herein is strictly at your own risk. Coalition and its affiliates will not be liable for any losses and damages in connection with your use or reliance upon the information. The blog post may include links to other third-party websites. These links are provided as a convenience only. Coalition does not endorse, have control over, nor assumes responsibility or liability for the content, privacy policy, or practices of any such third-party websites.
Copyright © 2026. All rights reserved. Coalition, Wirespeed and their associated logos are trademarks of Coalition, Inc. 

Related blog posts

See all articles
Security

Blog

AI SOC Hype is Overdue for a Reality Check

There’s a massive difference between a tool that uses AI as a marketing veneer and a production-grade AI SOC built on real security engineering.
Gregory AndersenAugust 27, 2026
Security

Blog

MSPs Report Losing Clients Over Slow Threat Containment

New study reveals 53% of MSPs lost a client in the past 24 months because they were unable to contain an incident fast enough.
Dara BernsteinAugust 26, 2026
Security

Blog

Risky Tech Ranking: Q2 2026 Updates

See how Coalition’s Risky Tech Ranking evolved in Q2 2026 with updates on the number of vendors scored, contributing vulnerabilities, Vendor Scores, and more.
Lucio Fernandez-ArjonaAugust 19, 2026