Family Sentinel
Scam Watch · September 28, 2026 · 5 min read

How a scammer who gets into your email hides the warnings

When someone breaks into an email account, the first move usually isn't to steal anything. It's to go quiet — to set one small rule that makes sure the bank's fraud alert, the "did you mean to send this?" from a worried friend, and the provider's own security warning never reach the inbox at all.

Picture the account afterward: it looks completely normal. Mail still arrives. Nothing is obviously broken. That's the point — a scammer who has your password doesn't want you to notice, so rather than announcing themselves, they quietly set the mailbox to filter out exactly the messages that would tip you off, and let everything else through so nothing looks wrong at a glance.

The quiet rule that does the hiding

The FBI's Internet Crime Complaint Center (IC3) has warned about this tactic for years in the context of business email compromise, and the mechanics are the same whether the target is a company or a family member. As the FBI puts it, "often, the actors configure mailbox rules of a compromised account to delete key messages. They may also enable automatic forwarding to an outside email account." The Bureau's recommended defense is blunt: prohibit automatic forwarding to outside addresses.

Microsoft's security guidance describes the same pattern from inside an Outlook or Microsoft 365 account. Attackers "might set up email rules to hide incoming emails in the compromised user mailbox to obscure their malicious activities from the user." Those rules can delete messages, move them into a folder nobody looks at, mark them as already read, or forward them to an outside address — and some are set to catch only messages containing particular words, such as "suspicious email" or "do not reply." Once a rule like that is in place, it keeps running on its own. The scammer doesn't need to touch the account again.

Why it's easy to miss

This isn't a gap in judgment — it's a gap in visibility. Nothing about a working inbox rule announces itself: there's no pop-up and no warning banner, and a message that was filtered away simply never appears. It sits in a settings menu most people never open, doing its job silently. Google's own guidance for a compromised account tells users, as a recovery step, to check their Gmail filters and forwarding settings — because that is exactly where an attacker tends to leave a trace.

The one thing to remember: a hidden mailbox rule doesn't announce itself — it just quietly removes the one email that would have. If something has gone unusually quiet, or a bank or provider says they warned you and you never saw it, that silence is itself worth checking.

The signs that leak through

The rule only touches what's inside the account, so it can't erase what happens outside it. A few things tend to surface anyway: a friend or relative says "I got a strange email from you" or "did you mean to send that?" and you never saw it go out, or their reply either; a bank or the email provider later says they sent a fraud alert or "new sign-in" notice that never showed up, even in spam; a password-reset email for another account goes missing when you're sure you typed the right address; or the sent folder holds a message you don't remember writing. Any one alone could be a fluke. Together, or repeated, they're worth five minutes of checking.

What to do

  1. In Gmail, check Filters and Forwarding. Open Settings, then "See all settings." Under Filters and Blocked Addresses, look for any filter you didn't create — especially one that deletes, archives, or skips the inbox for certain senders or words. Under Forwarding and POP/IMAP, confirm no forwarding address is set unless you set it.
  2. In Outlook or Outlook.com, check Rules and Forwarding. Go to Settings, then Mail > Rules, and read through every rule for anything unfamiliar. Separately check Settings, then Mail > Forwarding, and confirm it's off unless you turned it on.
  3. Delete anything you don't recognize. A rule you didn't create has no reason to exist.
  4. Run a full security checkup (Gmail: myaccount.google.com/security-checkup. Outlook: account.microsoft.com/security). Change the password, and turn on two-step verification or a passkey if it isn't on already.
  5. Treat a strange report as a reason to check that same day — a contact mentioning an odd email "from you," or a bank saying it warned you about something you never saw — not a coincidence to shrug off.
  6. Do this for an older parent's account too. A few minutes checking their filters and forwarding settings can catch a compromise that would otherwise run silently for weeks.

How Family Sentinel helps

This is one of the specific things our engine watches for on a monitored account: as our site puts it, "we watch for the fingerprints of a hijacked account: secret auto-forwarding rules, and filters quietly deleting bank and security alerts before they're seen." A person on our team reviews meaningful findings before a family is contacted. We're read-only by design — we don't change an account's settings for you — so this checklist is still worth doing yourself, on your own account and on a parent's, even if you're already monitored.

Related reading

We watch for exactly this kind of silence.

A hidden filter or forwarding rule doesn't look like anything unusual from the outside — it just makes sure the warning never arrives. Family Sentinel reads every message in a monitored inbox for the fingerprints of a hijacked account and gets a warning to your family fast. Read-only by design, with a real Security Architect behind every serious flag. Your family can also set a personal verification phrase, so a scammer can never fake a warning from us.

Start your free month →

Want the next threat before it reaches you?

Scam Watch goes out regularly — the newest scams and how to spot them, in plain English. Free.

Written by the Family Sentinel security desk — a working Security Architect and the team who watch family inboxes around the clock. Sources: FBI Internet Crime Complaint Center (IC3), Public Service Announcement PSA200406, "Cyber Criminals Conduct Business Email Compromise through Exploitation of Cloud-Based Email Services" (2020); Microsoft Learn, "Alert classification for suspicious inbox manipulation rules" (Microsoft Defender XDR documentation); Google Workspace Help, "Identify and secure compromised accounts"; Google Gmail Help, "Create rules to filter your emails" and "Automatically forward Gmail messages to another account"; Microsoft Support, "Manage email messages by using rules in Outlook" and "Turn automatic forwarding on or off in Outlook." Have a suspicious message you'd like a verdict on? Forward it to security@familysentinel.org — no charge, no strings. (940) 281-6672.