You’ve been compromised. Your heart sinks as you realize an unauthorized user has been in your email account. Your first instinct, and the most common advice you’ll receive, is to immediately change your password. You do it, set up a new, complex passphrase, and breathe a sigh of relief. The attacker is locked out. You are safe now. Or are you?
This sense of security is often a dangerous illusion. While changing your password is a critical first step, it’s like changing the lock on your front door while the intruder is still hiding in the attic with a key to the back door. Sophisticated attackers know that a password is just one entry point. Once inside, they can create multiple, persistent backdoors that survive a password reset, allowing them to maintain access, spy on your communications, and continue their malicious activities undetected. This is not a simple hack; it is a full-scale account takeover, and securing it requires a much deeper level of scrutiny.
In this comprehensive guide, we will pull back the curtain on one of the most insidious methods attackers use to retain access: the abuse of email account delegation and other hidden permissions. We will explore how these features, designed for convenience and collaboration, are turned into powerful weapons against you. More importantly, we will provide you with a detailed, actionable checklist to audit your account, identify these hidden threats, and truly reclaim your digital space. Understanding these advanced threats is the first step toward building a resilient defense, a core principle of our approach to digital security.
Spis treści:
- Beyond the Password: The Persistence Problem
- The Hidden Backdoors: How Attackers Retain Access
- Your Comprehensive Security Checklist: Reclaiming Control
- The Nexus Group Solution: Expert Intervention

Beyond the Password: The Persistence Problem
In the world of cybersecurity, we often talk about “initial access.” This is the first breach, the moment an attacker successfully bypasses your defenses, usually through a phishing email, a stolen password from another data breach, or malware. But for professional cybercriminals, initial access is just the beginning. Their primary goal is to establish “persistence”—the ability to maintain long-term access to a compromised system or account, even if the initial vulnerability is fixed or credentials are changed. An email account, often the central hub of our digital lives, is a prime target for establishing this persistence.
Think of your email account as a digital headquarters. It contains everything: communication with banks, password reset links for other services, sensitive personal documents, and business correspondence. For an attacker, gaining persistent access is like bugging that headquarters. They can silently monitor all incoming and outgoing information, intercept critical data, and even use your account to launch further attacks on your contacts, all while you believe you’ve secured the perimeter. The simple password reset fails because it only addresses one authentication method. It doesn’t undo the configuration changes the attacker made while they were inside. They have already used their initial access to grant themselves new, independent forms of access that do not rely on your password at all.
This is a fundamental shift in how we must approach account security after a breach. It’s not a single event to be fixed with a single action. It is an infestation that requires a deep, methodical cleansing of your entire account environment. The attacker has planted seeds of access in various, often obscure, settings menus. Unless you know exactly where to look and what to look for, these backdoors will remain active indefinitely, silently working against you.
The Hidden Backdoors: How Attackers Retain Access
Once an attacker has initial access, they work quickly to embed themselves into your account’s infrastructure. They exploit features designed for convenience and productivity, twisting them into tools for espionage and control. Let’s break down their most common and effective techniques.
Mailbox Delegation: Handing Over the Keys
Mailbox delegation is a standard feature in platforms like Google Workspace and Microsoft 365. It’s designed to allow an executive to grant their assistant access to their email to manage correspondence, schedule meetings, and reply on their behalf. The delegate can open the primary user’s mailbox without needing their password; the access is based on a permission granted within the account settings.
This is a goldmine for an attacker. After gaining initial access, they can navigate to the account settings and add their own email address (or one they control) as a delegate with full permissions. These permissions can include:
- Reading all emails, including new and existing ones.
- Sending emails “as” you (the email appears to come directly from your address).
- Sending emails “on behalf of” you (the email shows it was sent by the delegate on your behalf).
- Deleting messages.
- Accessing your calendar and contacts.
When you reset your password, this delegation permission remains perfectly intact. The attacker is not logging in as you anymore; they are accessing your mailbox through their own account, using the permissions you “granted” them. You will receive no notification of their activity because, from the system’s perspective, this is authorized behavior. The attacker can continue to read every email you receive, including password reset confirmations for other services, bank statements, and sensitive business intelligence, all completely undetected.
OAuth and Connected Apps: The Trojan Horse
OAuth 2.0 is the technology that allows you to sign in to a third-party application or website using your Google, Microsoft, or Apple account. It’s incredibly convenient. When you see a “Log in with Google” button, that’s OAuth in action. You grant the app specific permissions (e.g., to view your contacts or read your emails) without ever giving it your password. The app receives a special “access token” that acts as a limited-use key.
Attackers abuse this system in two primary ways:
- Malicious Consent Phishing: They create a seemingly legitimate application, often disguised as a productivity tool, document scanner, or email enhancement. They then send a phishing email that tricks you into granting this app access to your account. The permission screen might look official, but the permissions you grant are overly broad, such as “Read, compose, send, and permanently delete all your email.”
- Post-Breach Authorization: After gaining initial access to your account, the attacker can authorize their own malicious application themselves. You would have no knowledge of this transaction.
Just like with delegation, the access token granted to the app is not tied to your password. When you reset your password, the token remains valid until it expires or is manually revoked. The attacker’s application can continue to access your data in the background, siphoning information silently. This is a particularly stealthy attack vector, as most users rarely review the list of applications connected to their accounts. A comprehensive review of these connections is a vital part of any effective cybersecurity audit.
Hidden Inbox Rules and Malicious Forwarding
Perhaps the oldest trick in the book, yet still incredibly effective, is the manipulation of inbox rules and forwarding settings. These are server-side rules that process your email before you even see it. An attacker can set up rules that are very difficult to spot.
A simple forwarding rule is easy: they create a rule to automatically forward a copy of every incoming email to an external address they control. A password reset will not affect this rule. However, more sophisticated attackers will use more subtle rules to avoid detection. For example, they might create a rule with these conditions:
“If the email’s subject or body contains the words ‘invoice’, ‘password’, ‘bank’, ‘reset’, or ‘confidential’, then forward it to [attacker’s email address], mark the email as read, and move it to the trash folder.”
With a rule like this, you would never even see the most critical emails. The attacker intercepts them, and they are immediately hidden from your view. You might only realize something is wrong when you fail to receive an expected password reset link or a notification from your bank. By then, the damage may already be done.
Hijacked Recovery Options
Your account’s recovery phone number and alternate email address are your lifelines. They are the designated methods for proving your identity if you ever get locked out. For an attacker with temporary access, compromising these recovery options is a top priority. They will either add their own phone number or email address to the list of recovery options or, if they can, replace yours entirely. When you discover the breach and reset your password, you might inadvertently trigger a notification to the attacker’s recovery address. This gives them a direct path to re-compromise your account by initiating their own “forgot password” request. It becomes a race to see who can seize control of the account first, and if the attacker has already embedded themselves via other means like delegation or OAuth, they have a significant advantage.
Your Comprehensive Security Checklist: Reclaiming Control
Now that you understand the mechanisms attackers use, it’s time to perform a thorough security audit. Simply changing your password is not enough. You must methodically check every potential backdoor. Follow this checklist step-by-step for your primary email provider (instructions are generally similar for Google and Microsoft).
Step-by-Step Guide to Auditing Your Email Account
Step 1: Audit Mailbox Delegates and Permissions
This is your first and most critical check. Look for any email addresses that you do not recognize or did not personally authorize.
- For Google Workspace/Gmail: Go to Settings > See all settings > Accounts and Import > Grant access to your account. Carefully review the list of users. If you see anyone you don’t recognize, immediately click “delete” next to their name.
- For Microsoft 365/Outlook: Go to Settings > View all Outlook settings > Mail > Sync email. Look for sections related to “Mailbox delegation” or “POP and IMAP” to ensure no unauthorized access is configured. In a corporate environment, an administrator may need to check this in the Exchange Admin Center.
Step 2: Scrutinize Connected Apps and OAuth Access
Review every single application that has permission to access your account data. Be ruthless. If you don’t recognize an app or no longer use it, revoke its access immediately.
- For Google Accounts: Go to your Google Account management page, then click on the “Security” tab. Find the section “Third-party apps with account access” and review the list. Click on any suspicious app and select “Remove Access.”
- For Microsoft Accounts: Go to your Microsoft Account management page and find the “Privacy” dashboard. Look for “Apps and services” to see a list of applications you’ve given permissions to. Revoke access for anything that is not absolutely essential and trusted.
The proliferation of third-party apps makes this a critical area of modern account security.
Step 3: Inspect All Inbox Rules and Forwarding
This requires a meticulous eye, as malicious rules can be designed to look innocuous.
- For Google Workspace/Gmail: Go to Settings > See all settings > Filters and Blocked Addresses. Review every single filter. Look for any actions that forward mail, delete it, or mark it as read. Also, check the “Forwarding and POP/IMAP” tab to ensure no unauthorized forwarding address has been set up.
- For Microsoft 365/Outlook: Go to Settings > View all Outlook settings > Mail > Rules. Examine each rule for suspicious actions. Also, check the “Forwarding” section to ensure it is either disabled or points to an address you own.
Step 4: Verify and Secure Recovery Information
Ensure that your account’s lifelines are still yours and have not been tampered with.
- Navigate to the security settings of your account (Google or Microsoft).
- Check the registered recovery phone number and recovery email address. Make sure they are correct and that you have sole access to them.
- While you are here, this is the perfect time to enable or strengthen your Multi-Factor Authentication (MFA). Use a strong method like an authenticator app (e.g., Google Authenticator, Microsoft Authenticator) or a physical security key, which provide far greater protection than SMS-based codes.
Step 5: Terminate All Active Sessions
Finally, after performing all the checks above and changing your password, you must force a logout on all devices and sessions. This ensures that any active session using an old password or stolen session cookie is terminated.
- For Google Accounts: In the “Security” settings, under “Your devices,” you can manage all active devices and choose to sign out of any or all of them. There is also an option in Gmail’s footer to “Sign out of all other web sessions.”
- For Microsoft Accounts: In the “Security” settings, under “Advanced security options,” you will find an option to “Sign me out everywhere.” This will force a sign-out on all devices within 24 hours.
The Nexus Group Solution: Expert Intervention
Following this checklist will significantly improve your security posture and help you reclaim a compromised account. However, sophisticated attackers can use even more obscure techniques, such as manipulating API settings or hiding malicious scripts within legitimate-looking services. For individuals and businesses dealing with significant financial or data loss, a DIY approach may not be enough. The stakes are too high, and the threat actors are too skilled.
This is where professional intervention becomes essential. At Nexus Group, our expertise is in digital forensics and asset recovery. We don’t just guide you through a checklist; we conduct a deep, forensic analysis of your digital environment to uncover every trace of an attacker’s presence. Our team understands the complex web of permissions, tokens, and configurations that criminals exploit. We can identify and neutralize threats that the average user would never find. Our comprehensive security services are designed to provide peace of mind and tangible results. At Nexus Group, we are so confident in our methods that we guarantee the recovery of your funds or your money back.
If you suspect your account has been compromised and that the attacker may have established persistent access, do not wait for the situation to escalate. Taking decisive, expert-led action is the key to minimizing damage and securing your digital life for the future.