How a scammer who gets into your email hides the warnings
When someone breaks into an email account, the first move usually isn't to steal anything. It's to go quiet — to set one small rule that makes sure the bank's fraud alert, the "did you mean to send this?" from a worried friend, and the provider's own security warning never reach the inbox at all.
Picture the account afterward: it looks completely normal. Mail still arrives. Nothing is obviously broken. That's the point — a scammer who has your password doesn't want you to notice, so rather than announcing themselves, they quietly set the mailbox to filter out exactly the messages that would tip you off, and let everything else through so nothing looks wrong at a glance.
The quiet rule that does the hiding
The FBI's Internet Crime Complaint Center (IC3) has warned about this tactic for years in the context of business email compromise, and the mechanics are the same whether the target is a company or a family member. As the FBI puts it, "often, the actors configure mailbox rules of a compromised account to delete key messages. They may also enable automatic forwarding to an outside email account." The Bureau's recommended defense is blunt: prohibit automatic forwarding to outside addresses.
Microsoft's security guidance describes the same pattern from inside an Outlook or Microsoft 365 account. Attackers "might set up email rules to hide incoming emails in the compromised user mailbox to obscure their malicious activities from the user." Those rules can delete messages, move them into a folder nobody looks at, mark them as already read, or forward them to an outside address — and some are set to catch only messages containing particular words, such as "suspicious email" or "do not reply." Once a rule like that is in place, it keeps running on its own. The scammer doesn't need to touch the account again.
Why it's easy to miss
This isn't a gap in judgment — it's a gap in visibility. Nothing about a working inbox rule announces itself: there's no pop-up and no warning banner, and a message that was filtered away simply never appears. It sits in a settings menu most people never open, doing its job silently. Google's own guidance for a compromised account tells users, as a recovery step, to check their Gmail filters and forwarding settings — because that is exactly where an attacker tends to leave a trace.
The signs that leak through
The rule only touches what's inside the account, so it can't erase what happens outside it. A few things tend to surface anyway: a friend or relative says "I got a strange email from you" or "did you mean to send that?" and you never saw it go out, or their reply either; a bank or the email provider later says they sent a fraud alert or "new sign-in" notice that never showed up, even in spam; a password-reset email for another account goes missing when you're sure you typed the right address; or the sent folder holds a message you don't remember writing. Any one alone could be a fluke. Together, or repeated, they're worth five minutes of checking.
What to do
- In Gmail, check Filters and Forwarding. Open Settings, then "See all settings." Under Filters and Blocked Addresses, look for any filter you didn't create — especially one that deletes, archives, or skips the inbox for certain senders or words. Under Forwarding and POP/IMAP, confirm no forwarding address is set unless you set it.
- In Outlook or Outlook.com, check Rules and Forwarding. Go to Settings, then Mail > Rules, and read through every rule for anything unfamiliar. Separately check Settings, then Mail > Forwarding, and confirm it's off unless you turned it on.
- Delete anything you don't recognize. A rule you didn't create has no reason to exist.
- Run a full security checkup (Gmail: myaccount.google.com/security-checkup. Outlook: account.microsoft.com/security). Change the password, and turn on two-step verification or a passkey if it isn't on already.
- Treat a strange report as a reason to check that same day — a contact mentioning an odd email "from you," or a bank saying it warned you about something you never saw — not a coincidence to shrug off.
- Do this for an older parent's account too. A few minutes checking their filters and forwarding settings can catch a compromise that would otherwise run silently for weeks.
How Family Sentinel helps
This is one of the specific things our engine watches for on a monitored account: as our site puts it, "we watch for the fingerprints of a hijacked account: secret auto-forwarding rules, and filters quietly deleting bank and security alerts before they're seen." A person on our team reviews meaningful findings before a family is contacted. We're read-only by design — we don't change an account's settings for you — so this checklist is still worth doing yourself, on your own account and on a parent's, even if you're already monitored.
Related reading
- If you clicked something — what to do now — the first-hour checklist, including how to check for hidden forwarding rules after entering a password somewhere you shouldn't have.
- Scam Library: Account Takeover — six real patterns built around the idea that whoever holds the inbox holds every password reset.
- Protecting an older parent from email and phone scams — the conversations to have and the settings to check, this week.
We watch for exactly this kind of silence.
A hidden filter or forwarding rule doesn't look like anything unusual from the outside — it just makes sure the warning never arrives. Family Sentinel reads every message in a monitored inbox for the fingerprints of a hijacked account and gets a warning to your family fast. Read-only by design, with a real Security Architect behind every serious flag. Your family can also set a personal verification phrase, so a scammer can never fake a warning from us.
Start your free month →Want the next threat before it reaches you?
Scam Watch goes out regularly — the newest scams and how to spot them, in plain English. Free.