Threat Actors Abuse Trusted Accounts and Internal Tools to Launch Convincing BEC Attacks

KnowBe4 Team | Oct 5, 2026

Attackers are continually finding new ways to refine business email compromise (BEC) attacks, according to Douglas McKee, Director of Vulnerability Intelligence at Rapid7.

When attackers compromise trusted tools and accounts, they can manipulate victims’ view of reality. One way attackers can achieve this is through what McKee calls “calendar warfare,” in which attackers use calendar meetings to trick users into falling for attacks.

“Meetings can be modified or deleted without generating the notification trail users expect to see. RSVP status can also be flipped,” McKee writes. “Maybe a key executive is changed from Accepted to Declined and leadership might reschedule, or move ahead without them, or read the whole thing as a deliberate opt-out. It works in the other direction too. An ‘Emergency Board Meeting’ lands on an executive's calendar with a believable organizer, a popup reminder, and a malicious Zoom link. When the reminder fires, the victim is not sizing up a suspicious email that arrived thirty seconds ago. They are joining a meeting that has been sitting in their calendar for two days.”

Likewise, when an attacker compromises a trusted account and uses it to send legitimate-looking communications, the victim themselves may not realize that someone else is using their account.

“Send an email as your CFO without ever touching their password, and you have the front half of a very convincing BEC,” McKee says. “Keep control of the mailbox afterward and you have the back half, too. Here, the attacker has a strategic choice. They can delete the sent message to hide their tracks, effectively wiping the trail of the fraud OR they can choose to leave the message in the Sent Items folder. By doing so, they ensure the CFO sees 'evidence' of the email they supposedly sent, creating a gaslighting scenario where the victim is left questioning their own actions.”

Rapid7 has the story: https://www.rapid7.com/blog/post/ve-business-email-compromise-rewriting-reality-zimbra-cve/

 

See KnowBe4 Cloud Email Security in Action

Request a personalized demo today to see how KnowBe4's Cloud Email Security products will enhance your email security.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, email and collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.