There is no red screen, no encrypted file, no ransom demand. A compromised mailbox makes no noise at all. That is precisely what makes it so dangerous: the company keeps working normally while a stranger reads its correspondence.
This scenario has a name in the jargon: BEC, for “business email compromise”. In practice, it is the hacking of a business mailbox, followed by its patient exploitation. For an SME, it is today one of the costliest incidents, and one of the easiest to prevent.
What does an attacker actually do inside your mailbox?
The first surprise, for a manager who discovers the incident, is that the attacker has destroyed nothing. They have done something far worse: they have learned.
For days, sometimes weeks, they read. They work out who decides, who pays, who approves. They note your turns of phrase, your polite formulas, the names of your usual suppliers, the rhythm of your exchanges. They build a file on your company from your own correspondence.
Then they act, in three main ways.
Invoice diversion. This is the most profitable. The attacker waits for a genuine invoice to circulate, intercepts it, changes the bank details and sends it back from your mailbox, or from an address very close to yours. The customer pays in good faith. Nobody notices anything until the payment reminder, often weeks later.
Impersonation with your contacts. Writing from your real address, the attacker contacts your customers, your accountant, your bank. Technical checks are useless here: the message really does come from you. This technique also fuels CEO fraud, where an urgent transfer request appears to come from management.
Hidden forwarding rules. The attacker creates a rule in your mailbox that automatically forwards certain messages to an external address, then deletes them from the Sent folder. They keep receiving everything even after a password change. These rules are often given an innocuous name, a simple dot or a space as the title.
Unlike a typical fake e-mail, there is here no technical clue to spot: no approximate domain, no header error, no spelling mistake. Your customers receive an authentic message, sent from your server, within a real conversation thread. This is why verifying any IBAN change by phone is now essential, whatever the sender.
How does a mailbox actually get hacked?
Few entry points exist, and they are well known.
A password entered on a fake page. This is the main route. A message imitates Microsoft, your host or your bank, and leads you to a login page copied exactly. The subject is covered in detail in our article on phishing. The scale of the phenomenon is documented in Switzerland: in the second half of 2025, the National Cyber Security Centre received 6,299 phishing reports.
A reused password. You use the same password for your business mailbox and for a third-party site. That site gets hacked, your credentials leak, and bots replay them against thousands of services. No particular skill is required. Our recommendations are set out in the article on passwords.
The absence of two-factor authentication. This is not the cause of the intrusion, it is what makes it possible. Without a second factor, a stolen password grants immediate, full access. With it, it grants nothing.
The Swiss context confirms that this kind of fraud is far from marginal. In 2025, the National Cyber Security Centre recorded 64,733 voluntary cyber-incident reports, up from 62,954 the year before. In the second half of 2025 alone, fraud accounted for 52% of all reports received, or 15,090 reports.
The warning signs of a compromised mailbox
A compromise leaves traces. You just need to know where to look.
| Signal observed | What it means | Urgency |
|---|---|---|
| An inbox rule you did not create | Almost certain signal of an active compromise | Immediate |
| Messages missing from the Sent folder, even though your contacts received them | The attacker is erasing their tracks | Immediate |
| Logins from a country where you have no activity | Access from outside, often via an anonymising service | Immediate |
| A customer reports a strange e-mail apparently from you | Exploitation already under way with third parties | Immediate |
| Unsolicited two-factor authentication prompts | Someone has your password and is trying to get in | High |
| Messages marked as read that you did not open | Silent reading in progress | High |
| Massive non-delivery reports for messages you did not send | Your mailbox is being used to send spam | High |
| An automatic forwarding rule set up on your account | Systematic copying of your mail to a third party | Immediate |
The two things to check first are the inbox rules and the sign-in history. In both Microsoft 365 and Google Workspace, both are accessible in a few clicks from the account settings, and a quarterly check takes less than ten minutes. The other settings to put in place are gathered in our article on securing Microsoft 365.
What to do within the hour
Order matters. Many companies change the password and stop there, which leaves the attacker in place.
- Change the password of the affected account, from a device you are certain is clean.
- Revoke all active sessions. An open session survives a password change. This is the step most often forgotten.
- Enable two-factor authentication immediately, if this was not already done.
- Inspect rules, forwarding, and delegated access. Remove anything you did not create, after taking a screenshot for your records.
- Check connected applications on the account and remove any you do not recognise.
- Notify your contacts who were active during the period, in particular those with payments under discussion.
- Keep the evidence. Sign-in logs, screenshots of the rules, fraudulent messages. They will be useful for the analysis, for insurance, and for any potential complaint.
If a transfer has already been made, contact the bank without delay: a recall of funds is sometimes still possible within the very first hours. The full procedure is detailed in our article on the first hours after an incident.
Two-factor authentication, the decisive countermeasure
All the measures mentioned so far are useful. Only one truly changes the equation.
Two-factor authentication adds a proof of identity to the password: a temporary code generated by an app, a confirmation on your phone, or a physical security key. An attacker who holds your credentials is left in front of a door they cannot open from their computer.
It is the measure with the best ratio between the effort required and the risk avoided. It is included at no extra cost in Microsoft 365, Google Workspace and most Swiss hosting providers. Turning it on takes a few minutes per user.
Start with the accounts that would cause the most damage if compromised: management, accounting, IT administration, generic addresses such as invoicing or accounts. Prefer an authenticator app or a physical security key over SMS codes, which can be intercepted. Then extend it to all staff. A well-targeted partial rollout is worth infinitely more than a complete project postponed to next year.
Add two organisational habits. First: any change of bank details is verified by phone, on a known number, never the one given in the message. Second: beyond a certain amount, a transfer requires dual approval. Both rules cost nothing and neutralise most of the financial risk. The technical security of e-mail is covered in our dedicated article on e-mail security, and the step-by-step rollout in the one on two-factor authentication.
The legal consequences not to overlook
A business mailbox contains personal data: addresses, contact details, exchanges with customers, sometimes sensitive documents as attachments. Its compromise therefore constitutes a data security breach under Swiss law.
Notification to the Federal Data Protection and Information Commissioner is required when the breach is likely to result in a high risk for the people concerned. Two points matter here. Swiss law requires notification “as soon as possible” and does not set a 72-hour deadline: that timeframe belongs to the European regulation alone. And assessing the level of risk is your responsibility, which means documenting your reasoning, even if you conclude that no notification is necessary. The full framework is detailed in our article on your FADP obligations.
Finally, think about your backups. An attacker present in a mailbox sometimes has access to other services, and the ability to restore an earlier state remains your safety net. The principle is explained in the 3-2-1 backup rule.
To gauge your exposure in a few minutes, the cyber check-up devotes several questions to e-mail and authentication. The other attacks targeting Swiss SMEs are gathered in the Threats pillar.