Analytics BIOC Informational

Outbound email includes an external BCC recipient observed for the first time

Internal sender BCC'd an external recipient whose address has not been observed in prior communications.

Module:
Email Security
Licensed by:
Email Security
Data source:
Microsoft 365 Emails
ATT&CK tactics: Execution (TA0002) Credential Access (TA0006)
ATT&CK techniques: User Execution (T1204) Brute Force: Password Cracking (T1110.002)
Detector tags: Exfiltration
Attacker's goals:

Use BCC to covertly exfiltrate data to an unusual external recipient without visibility to other recipients or monitoring systems.

Investigative actions:

Review headers and content for anomalies or potential exposure of sensitive data. Assess the email's context and attack techniques to determine the potential risk. Investigate if similar patterns have occurred recently across the organization.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Outbound email sent to an unknown external BCC recipient with no To or CC addresses Low (parent: Informational)