Gmail Forwarding Rule Hacker: Find BEC Filters and Forwards
How to find the Gmail forwarding rule or hidden filter a hacker left in a Workspace mailbox: the log events, the Gmail settings to export and what to delete.
TL;DR. After a mailbox takeover, attackers set up forwarding so they keep reading after you reset the password, and a filter that hides invoice and payment replies from the real user. The evidence is split across three places. The user accounts log has email_forwarding_out_of_domain with the destination. The Gmail log has messages auto-forwarded, archived or trashed. The Gmail settings hold the filter itself, which no audit log records. Export all three, drop them in the analyzer, then delete the filter after you have recorded it.
Forwarding and hiding rules are the backbone of business email compromise. The attacker doesn't need to stay signed in. The mailbox quietly sends them every thread about money, and hides the replies that would expose the fraud. MITRE ATT&CK tracks these as T1114.003 Email Forwarding Rule and T1564.008 Email Hiding Rules.
The three mechanisms
| Mechanism | What it does | Where the evidence is |
|---|---|---|
| Auto-forwarding (account setting) | Every incoming message is copied to an address | User accounts log email_forwarding_out_of_domain; Gmail settings autoForwarding and forwardingAddresses |
| Filter with forward action | Only matching messages (e.g. "invoice") are forwarded | Gmail settings filters (action.forward); Gmail log autoforward events |
| Hiding filter | Matching messages skip the inbox, get marked read, or go to trash or spam | Gmail settings filters (removeLabelIds: INBOX / UNREAD, addLabelIds: TRASH / SPAM); Gmail log archive and trash events |
Attackers often combine them. One filter on invoice OR payment OR "bank details" that removes INBOX and UNREAD and forwards outside does both jobs.
A detail that helps: Gmail requires a forwarding address to be verified before forwarding to it. The forwardingAddresses list shows each address with its verificationStatus. An accepted external address nobody recognises means the attacker controlled that mailbox long enough to confirm it.
Step 1: the user accounts log
In the Admin console (Reporting → Audit and investigation → User log events) or the Reports API (login / user_accounts), look for email_forwarding_out_of_domain. Google lists it under "Email forwarding settings changed" in the Login audit appendix. The event carries the destination address and the IP it was set from. That IP should match the attacker's sign-in. In the analyzer, this fires Automatic forwarding to an external address enabled (high).
Step 2: the Gmail log
The Gmail log (Reports API application gmail) records message events with a type: receive, send, auto-forward, archive, trash, and more. For a BEC:
- Auto-forwarded messages show which mail left and to whom. Usually supplier invoices and remittance advice.
- Archive and trash events right after delivery, on finance subjects, are the hiding filter at work.
- Sends to external recipients with subjects like "updated bank details" or "new payment instructions" are the fraud itself.
The analyzer flags auto-forwarded mail, three or more finance-subject messages archived or trashed within 24 hours, and outgoing bank-change mail to external recipients. The finance vocabulary covers English, French, German and Spanish. Remember that Reports API Gmail queries must use windows of at most 30 days.
Step 3: the Gmail settings (the filter itself)
No audit event describes a filter's criteria and actions. Read them from the mailbox:
- Gmail API:
users.settings.filters.list, plusforwardingAddresses.list,getAutoForwarding,delegates.listandsendAs.list. Save each response asgmail-settings/<mailbox>/<name>.json. - GAM:
gam user <email> show filters,show forwards,show forwardingaddressesfor a quick look. - No API? Open the user's Settings → Filters and blocked addresses and Forwarding and POP/IMAP with them and take dated screenshots.
In the analyzer, a filter that forwards outside the organization is high severity. A filter whose criteria contain finance words and whose actions remove INBOX/UNREAD or add TRASH/SPAM is flagged as hiding finance mail (high). External send-as aliases and delegates are flagged as medium: a delegate can read and send as the user, and an external send-as helps with impersonation.
There's one more clue in the OAuth token log. If a lure app holds gmail.settings.basic or full Gmail scope, you may see gmail.users.settings.filters.create among its API calls: the app created the filter, not a person in a browser. See suspicious OAuth apps.
Don't forget admin-level rules
User filters aren't the only way to copy mail. An attacker with admin access can create routing or content compliance rules that copy or BCC mail for many users. None of this appears in any mailbox's settings. Google Threat Intelligence documented exactly this in June 2026: a compliance rule that BCC'd matching messages to an attacker-controlled Gmail address. Check the Admin log for Gmail setting changes. See admin role abuse and SSO changes.
Clean-up, in order
- Record the filters, forwarding addresses and settings (export or screenshot). Your deletion removes the evidence.
- Contain the session and revoke the app tokens, so the attacker can't recreate the rules while you work.
- Delete the malicious filters and forwarding addresses, and disable auto-forwarding.
- Recover what the filter hid: search All Mail, Trash and Spam for the forwarded subjects and senders. Those threads tell you which suppliers and customers were targeted.
- Prevent: unless you have a business need, stop users from auto-forwarding outside the domain. Google documents the Automatic forwarding setting under Apps → Google Workspace → Gmail → End User Access.
- Warn the counterparties by phone, not email.
More on the full response: first-hour checklist. In a Microsoft 365 tenant, the equivalent artifacts are inbox rules and transport rules. See m365forensics.com for that side.
Related: email hiding rule, external auto-forwarding, and the fictional BEC walkthrough, where all three mechanisms appear.
FAQ
How do I find a Gmail forwarding rule set by a hacker?
Check the user accounts log for email_forwarding_out_of_domain (it names the destination), the Gmail log for auto-forwarded messages, and the mailbox's settings (filters, forwarding addresses, auto-forwarding) through the Gmail API or the user's Gmail settings. Filters are only visible in the settings.
Can an admin block external auto-forwarding in Gmail?
Yes. In the Admin console, go to Apps → Google Workspace → Gmail → End User Access → Automatic forwarding and untick the option that lets users automatically forward email to another address, for the whole organization or an organizational unit.