Intended readership: CISOs, SOC managers, incident response teams, IT leaders, MSSPs
Email security tools are designed to catch bad messages: phishing links, spoofed domains, suspicious attachments. But the attacks doing the most damage now start before any message is sent. An employee credential gets harvested by an infostealer, circulates on a dark web marketplace, and eventually gets used by someone who is not your employee to log into their mailbox. From that point, every email the attacker sends passes SPF, DKIM, and DMARC without raising a flag — because the account is real. But the sender is not.
Compromise and business email compromise (BEC) are two different events separated by time. Compromise happens when credentials are stolen. BEC happens later, when someone uses those credentials to log in and operate as the employee. Between those two events, days or weeks pass. If you can see the compromise at the right moment, you can predict the BEC that would follow and prevent millions of euros being stolen at the root.
Most security leaders we surveyed understand this challenge, but almost none have controls in place for it. One capability can address the entire attack chain before it reaches your mailbox. Keep reading to find out what it is…
Between theft and exploitation
Every credential-based attack follows a recognizable sequence. The stages below are drawn from Group-IB’s investigations, including the W3LL phishing ecosystem, which ran for over seven years and equipped more than 500 cybercriminals with tools purpose-built for compromising Microsoft 365 accounts. In these cases, individual BEC losses reached hundreds of thousands of euros.
Stage 1: Infection. An employee’s device gets infected with an infostealer, often through a phishing email, a malicious download, or a compromised partner.
Stage 2: Exfiltration. Within hours or days, the infostealer harvests credentials, browser sessions, VPN configurations, and email access tokens. Everything gets sent to attacker infrastructure.
Stage 3: Circulation. The stolen credentials surface on underground forums, infostealer log marketplaces, or get sold directly to access brokers. At this point, credentials are visible in threat intelligence — but nobody has used them yet.
Stage 4: Exploitation. A threat actor purchases the credentials and logs into the employee’s mailbox, launching lateral phishing campaigns that spread across internal systems. This is where BEC begins.
Stage 5: Damage. Ransomware deployment, data exfiltration, or financial fraud.
Email security tools activate at Stage 4 or later — after the attacker has logged in and started acting. Group-IB operates at earlier stages, when credentials appear in threat intelligence but nobody has acted on them yet. Act before the login, and BEC never happens.
Group-IB’s Hi-Tech Crime Trends 2026 report shows identity and trust as the primary attack surfaces of the current threat landscape, with stolen tokens, credentials, and session cookies functioning as “portable supply chain access” that lets attackers blend in as trusted users. The scale of the underground market behind this is substantial: in 2025, Group-IB detected 2,227 publicly advertised corporate access sales on dark web forums, but the report notes that the most valuable types — domain admin accounts, VPN panels, SaaS logins — now trade exclusively in private channels and never reach open markets. For defenders, this means visibility into credential compromise is shrinking.
This underground infrastructure feeds real campaigns. In a recent case tracked by Group-IB, a stealer-as-a-service operation called Phantom Stealer delivered five distinct attack waves against European logistics, manufacturing, and technology organizations, each designed to harvest credentials for exactly this kind of downstream exploitation. Business Email Protection blocked every wave before a single email reached our customers.
Threat Landscape Service
Your employees' credentials may already be for sale on underground markets. Request a Threat Intelligence assessment to find out if your organization is exposed before anyone acts on it.
Where the intelligence comes from
Group-IB Threat Intelligence continuously monitors dark web forums, infostealer log marketplaces, breach databases, and private credential trading channels, with intelligence updated hourly. Business Email Protection checks the organization’s accounts against that intelligence, matching employee email addresses, AD and Azure AD credentials, and leaked passwords from stealer logs and breach dumps.
When a match is found, your SOC gets an immediate alert and can reset the password before anyone uses those credentials to log in. Beyond email credentials, Group-IB Threat Intelligence also tracks compromised accounts for remote access tools like TeamViewer, AnyDesk, LogMeIn, Chrome Remote Desktop, and Parsec, which threat actors frequently use as alternative entry points after credential theft.
It is the same proprietary intelligence pipeline that enabled Group-IB to unmask vicious adversaries, and its operational impact is measurable. In 2025, INTERPOL’s Operation Secure, supported by Group-IB intelligence, dismantled a cybercriminal network using Lumma, Risepro, and META Stealer infostealers that compromised data belonging to more than 216,000 potential victims, leading to 32 arrests and the seizure of 41 servers. Separately, Operation Serengeti 2.0 targeted BEC infrastructure specifically, resulting in 1,209 arrests across Africa, the dismantling of 11,432 malicious networks, and recovery of $97.4 million.
This is a fundamentally different approach from how other email security platforms work. Most derive their compromise signals from what happens inside the email environment: behavioral anomalies, sending anomalies, identity-graph changes. By the time those signals trigger, the attacker is already operating inside the mailbox. Group-IB’s signal comes from outside the email environment entirely, from the underground economy where credentials are traded, before any email-side indicator exists.
The First-Ever Magic Quadrant for Threat Intelligence
Group-IB has been named a Leader In the First-Ever Magic Quadrant for Threat Intelligence
Why internal email is where attackers thrive
Threat intelligence catches compromised credentials before anyone logs in. But what happens when someone does? Once an attacker gets into a mailbox, every defense designed for external threats becomes irrelevant.
Internal emails never cross your perimeter — they live on the server. Most email security tools simply never see them. The threat actor has already passed the MFA. Every email they send originates from a legitimate account. Reputation filters have no reason to flag the sender, because the sender has been communicating with colleagues for years. And if the attacker is using AI to match the victim’s writing style — which is increasingly common — content analysis has nothing to work with either.
Security leaders we surveyed see this firsthand. In conversations with enterprise CISOs and security architects, we noticed a consistent pattern: most organizations have minimal or no dedicated controls for internal email traffic.
“After an internal user has been properly authenticated with their MFA, email from them would be trusted. The email would not be subject to the legitimacy inspections like SPF and DMARC since it originates from a bona fide account.” — Field CISO, 10,000+ employee SaaS company
“This is a traditionally overlooked area due to the assumption that internal communications are intrinsically secure. Don’t count on users to sniff out that level of sophistication.” — CISO, mid-sized software company
“The phishing messages usually come from a trusted party, which prevents the typical red flags users usually use to identify malicious emails. They can also be sent to hundreds of inboxes at once, which makes it very difficult to quarantine and stop.” — Deputy CISO, large healthcare organization
When we asked these security leaders how confident they are in their ability to quickly detect a compromised internal account, the most common answer was a 3 on a 7-point scale. The majority cited AI-driven threat sophistication as their primary concern, and nearly half pointed to the inherent trust placed on internal communications as a core challenge. This is the fertile soil for BEC attackers, where many organizations have no dedicated defense.
How Business Email Protection predicts and prevents compromise
Business Email Protection connects to Microsoft 365 or Google Workspace via API and continuously checks the identities behind the mailboxes against Group-IB Threat Intelligence. It does not wait for a suspicious email to trigger an alert. It identifies compromise and predicts the BEC that would follow.
Predicting BEC from employee credentials. Business Email Protection pulls the organization’s employee directory from the cloud platform and continuously monitors every employee email address against Group-IB Threat Intelligence. When credentials surface in stealer logs, dark web markets, or breach data, Business Email Protection matches them within minutes. Your SOC gets notified immediately, and the affected mailbox gets a forced password reset. The attacker who would have logged in days or weeks later finds the credentials invalidated. At integration, Business Email Protection replays historical mail-log metadata against threat intelligence, so already-compromised identities surface on day one, not after the next incident.
Predicting supply chain attacks. Business Email Protection applies this same predictive approach to external identities: the partners, vendors, and contractors your organization corresponds with regularly. By modeling inter-company email relationships and checking every trusted-partner domain against threat intelligence, Business Email Protection identifies when a partner has been compromised and predicts which internal departments and employees are the most likely next targets. The compromised sender gets flagged. Historical messages get tagged retroactively. And departments predicted to be on the attack path receive warnings before any malicious email reaches them.
Internal email analysis. Group-IB’s prediction capabilities catch most compromised accounts before anyone logs in. But even if credentials slip through or a compromise is detected mid-session, Business Email Protection has a second layer: internal-to-internal email scanning. Unlike many email security tools that only inspect inbound traffic from external senders, Business Email Protection connects via API to analyze messages that stay entirely within the organization. If a compromised account sends a lateral phishing email to a colleague, every attachment and link gets detonated in a behavioral sandbox and stopped.
From detection to prediction
The email security industry has spent years building increasingly sophisticated engines that trigger after something bad happens. Sandboxes analyze attachments after delivery, AI flags anomalies after the attacker sends the first message, incident response teams investigate after the damage is done. All of that is detection. It is necessary, and yet it is not enough.
Predicting BEC before it happens changes the sequence entirely. Credentials appear in threat intelligence. Business Email Protection matches them to the organization’s directory. The security team resets the password, and the attacker never gets in. The BEC that would have followed — the lateral phishing, the invoice fraud, the supply chain compromise — never materializes.
Business Email Protection
Predict account compromise and stop BEC at the root with Business Email Protection.







