Trending Topics

The Mimecast Portal BEC risk: how attackers stay in the inbox after a password reset
The S-RM advisory on attackers abusing the Mimecast Personal Portal isn’t new – but it is newly relevant in a market still treating Microsoft 365 containment as the end of a business email compromise (BCE). The real lesson is sharper: if Mimecast access is tied too closely to Microsoft 365 identity, resetting an M365 password may not end the attacker’s access to email.
S-RM said attackers were using stolen Microsoft 365 credentials to access the Mimecast Personal Portal, then either send fraudulent invoices directly from Mimecast or mine archived email for business context. In one variant, attackers continued sending emails as the victim after the M365 account had been contained, with messages missing from Outlook Sent Items and bypassing Microsoft 365 Message Trace.
That persistence is what makes the issue worth revisiting. BEC is not slowing down. The FBI’s 2025 Internet Crime Report recorded $20.877 billion in reported cybercrime losses, with business email compromise the second-largest loss category at just over $3.046 billion.

S-RM’s own incident-response data adds the operational sting: in 2025, more than 25% of BEC cases it handled resulted in successful payment diversion, with one loss exceeding $4.5 million.
Mimecast hardening must be part of BEC containment
The danger is not that Mimecast is uniquely weak. It is that security teams may forget that email-security platforms are also access platforms. Mimecast’s portal can provide archive search, message tracking and the ability to send mail as the protected user. In the wrong hands, that is enough to continue a fraud campaign or build a more convincing one.
S-RM traced the risk to common configurations such as Microsoft Directory Synchronisation and SSO, where one phished credential can authenticate into both M365 and Mimecast. Even where Mimecast uses separate credentials, reused passwords and missing MFA can create the same exposure.
Mimecast’s own 2026 human-risk research explains why this matters beyond one advisory. It found that 96% of organisations expect email security challenges this year, 53% report increased phishing volume and 48% have seen a rise in BEC. Mimecast’s April analysis of the FBI data also framed BEC as a $3 billion problem that often carries no malware, malicious link or payload to block.
The response should be procedural as much as technical.
After any M365 compromise, teams should audit Mimecast logins, trace emails sent through the portal, review delegate access, terminate active Mimecast sessions and check for attacker-added MFA methods. S-RM also recommends resetting Mimecast credentials and session tokens, deleting unrecognised MFA devices, enforcing MFA for Mimecast, reviewing who actually needs archive access and regularly checking audit logs.
The takeaway for IT leaders is simple: BEC containment cannot stop at the mailbox. If attackers can still reach the Mimecast portal, they may still be in the conversation.
