Skip to content

This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Workspace, Gmail and Google Drive are trademarks of Google LLC. Other names are trademarks of their respective owners.

Gmail Forwarding Rule Hacker: Find BEC Filters and Forwards

How to find the Gmail forwarding rule or hidden filter a hacker left in a Workspace mailbox: the log events, the Gmail settings to export and what to delete.

Published on 5 min read

TL;DR. After a mailbox takeover, attackers set up forwarding so they keep reading after you reset the password, and a filter that hides invoice and payment replies from the real user. The evidence is split across three places. The user accounts log has email_forwarding_out_of_domain with the destination. The Gmail log has messages auto-forwarded, archived or trashed. The Gmail settings hold the filter itself, which no audit log records. Export all three, drop them in the analyzer, then delete the filter after you have recorded it.

Forwarding and hiding rules are the backbone of business email compromise. The attacker doesn't need to stay signed in. The mailbox quietly sends them every thread about money, and hides the replies that would expose the fraud. MITRE ATT&CK tracks these as T1114.003 Email Forwarding Rule and T1564.008 Email Hiding Rules.

The three mechanisms

MechanismWhat it doesWhere the evidence is
Auto-forwarding (account setting)Every incoming message is copied to an addressUser accounts log email_forwarding_out_of_domain; Gmail settings autoForwarding and forwardingAddresses
Filter with forward actionOnly matching messages (e.g. "invoice") are forwardedGmail settings filters (action.forward); Gmail log autoforward events
Hiding filterMatching messages skip the inbox, get marked read, or go to trash or spamGmail settings filters (removeLabelIds: INBOX / UNREAD, addLabelIds: TRASH / SPAM); Gmail log archive and trash events

Attackers often combine them. One filter on invoice OR payment OR "bank details" that removes INBOX and UNREAD and forwards outside does both jobs.

A detail that helps: Gmail requires a forwarding address to be verified before forwarding to it. The forwardingAddresses list shows each address with its verificationStatus. An accepted external address nobody recognises means the attacker controlled that mailbox long enough to confirm it.

Step 1: the user accounts log

In the Admin console (Reporting → Audit and investigation → User log events) or the Reports API (login / user_accounts), look for email_forwarding_out_of_domain. Google lists it under "Email forwarding settings changed" in the Login audit appendix. The event carries the destination address and the IP it was set from. That IP should match the attacker's sign-in. In the analyzer, this fires Automatic forwarding to an external address enabled (high).

Step 2: the Gmail log

The Gmail log (Reports API application gmail) records message events with a type: receive, send, auto-forward, archive, trash, and more. For a BEC:

  • Auto-forwarded messages show which mail left and to whom. Usually supplier invoices and remittance advice.
  • Archive and trash events right after delivery, on finance subjects, are the hiding filter at work.
  • Sends to external recipients with subjects like "updated bank details" or "new payment instructions" are the fraud itself.

The analyzer flags auto-forwarded mail, three or more finance-subject messages archived or trashed within 24 hours, and outgoing bank-change mail to external recipients. The finance vocabulary covers English, French, German and Spanish. Remember that Reports API Gmail queries must use windows of at most 30 days.

Step 3: the Gmail settings (the filter itself)

No audit event describes a filter's criteria and actions. Read them from the mailbox:

  • Gmail API: users.settings.filters.list, plus forwardingAddresses.list, getAutoForwarding, delegates.list and sendAs.list. Save each response as gmail-settings/<mailbox>/<name>.json.
  • GAM: gam user <email> show filters, show forwards, show forwardingaddresses for a quick look.
  • No API? Open the user's Settings → Filters and blocked addresses and Forwarding and POP/IMAP with them and take dated screenshots.

In the analyzer, a filter that forwards outside the organization is high severity. A filter whose criteria contain finance words and whose actions remove INBOX/UNREAD or add TRASH/SPAM is flagged as hiding finance mail (high). External send-as aliases and delegates are flagged as medium: a delegate can read and send as the user, and an external send-as helps with impersonation.

There's one more clue in the OAuth token log. If a lure app holds gmail.settings.basic or full Gmail scope, you may see gmail.users.settings.filters.create among its API calls: the app created the filter, not a person in a browser. See suspicious OAuth apps.

Don't forget admin-level rules

User filters aren't the only way to copy mail. An attacker with admin access can create routing or content compliance rules that copy or BCC mail for many users. None of this appears in any mailbox's settings. Google Threat Intelligence documented exactly this in June 2026: a compliance rule that BCC'd matching messages to an attacker-controlled Gmail address. Check the Admin log for Gmail setting changes. See admin role abuse and SSO changes.

Clean-up, in order

  1. Record the filters, forwarding addresses and settings (export or screenshot). Your deletion removes the evidence.
  2. Contain the session and revoke the app tokens, so the attacker can't recreate the rules while you work.
  3. Delete the malicious filters and forwarding addresses, and disable auto-forwarding.
  4. Recover what the filter hid: search All Mail, Trash and Spam for the forwarded subjects and senders. Those threads tell you which suppliers and customers were targeted.
  5. Prevent: unless you have a business need, stop users from auto-forwarding outside the domain. Google documents the Automatic forwarding setting under Apps → Google Workspace → Gmail → End User Access.
  6. Warn the counterparties by phone, not email.

More on the full response: first-hour checklist. In a Microsoft 365 tenant, the equivalent artifacts are inbox rules and transport rules. See m365forensics.com for that side.

Related: email hiding rule, external auto-forwarding, and the fictional BEC walkthrough, where all three mechanisms appear.

FAQ

How do I find a Gmail forwarding rule set by a hacker?

Check the user accounts log for email_forwarding_out_of_domain (it names the destination), the Gmail log for auto-forwarded messages, and the mailbox's settings (filters, forwarding addresses, auto-forwarding) through the Gmail API or the user's Gmail settings. Filters are only visible in the settings.

Can an admin block external auto-forwarding in Gmail?

Yes. In the Admin console, go to Apps → Google Workspace → Gmail → End User Access → Automatic forwarding and untick the option that lets users automatically forward email to another address, for the whole organization or an organizational unit.

Related articles

A fictional business email compromise in Google Workspace, worked from the audit logs: AiTM sign-in, OAuth grant, hidden filter, fraud mail and Drive theft.
A first-hour checklist for a compromised Google Workspace account: preserve logs, cut sessions and OAuth tokens, remove forwarding and filters, stop payments.
How to tell if a Google Workspace account was compromised: which audit logs to pull, the event names that matter, how to correlate them and what to rule out.

This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Workspace, Gmail and Google Drive are trademarks of Google LLC. Other names are trademarks of their respective owners.