• Cyber Safety
  • Posts
  • Your Email Forwarding Rules Could Be Helping an Attacker”

Your Email Forwarding Rules Could Be Helping an Attacker”

In partnership with

Blu Dot surpasses 2,000% ROAS with self-serve CTV ads

Home furniture brand Blu Dot blew up on CTV with help from Roku Ads Manager. Here’s how:

After a test campaign reached 211,000 households and achieved 1,010% ROAS, the brand went all in to promote its annual sales event. It removed age and income constraints to expand reach and shifted budget to custom audiences and retargeting, where intent was strongest.

The results speak for themselves. As Blu Dot increased their investment by 10x, ROAS jumped to 2,308% and more page-view conversions surpassed 50,000.

“For CTV campaigns, Roku has been a top performer,” said Claire Folkestad, Paid Media Strategist, Blu Dot. “Comping to our other platforms, we have seen really strong ROAS… and highly efficient CPMs, lower than any other CTV partner we've worked with.”

Using Roku Ads Manager, the campaign moved from a pilot to a permanent performance engine for the brand.

Attackers Don’t Always Need to Stay Logged In

After compromising an inbox, an attacker can create forwarding or filtering rules that quietly send selected emails elsewhere — even after the initial intrusion is discovered.

The Most Valuable Messages Can Be Targeted

Rules can focus on invoices, password resets, financial conversations, contracts, or executive communications instead of forwarding everything and attracting attention.

Hidden Rules Enable Long-Term Surveillance

An attacker may monitor conversations for days or weeks, learning how employees communicate, who approves payments, and when valuable transactions occur.

Build a Holiday Creator Affiliate Program in 90 Days

Creators lock in holiday content calendars 90 days out, before brands figure out commissions. Waiting too long to launch an affiliate program means less runway to build demand and a missed shot at the best partnerships.

The 90-Day Holiday Sprint covers commissions, recruiting, and scaling a program at Day 30, 60, and 90.

This Can Lead Directly to Payment Fraud

Once attackers understand a financial workflow, they can impersonate vendors or executives and attempt to redirect legitimate payments to accounts they control.

Changing the Password May Not Be Enough

Responders should also review mailbox rules, forwarding addresses, active sessions, delegated access, connected applications, and authentication activity after an email compromise.

Monitor the Inbox Like a Security System

Alert on suspicious forwarding changes, restrict external forwarding where appropriate, enforce MFA, and investigate unusual mailbox configurations. Sometimes the attacker doesn’t need your password anymore — because your inbox is already sending them everything they need.

AI Insights. Real Growth. Higher GMV, Better Profits

The difference between growing stores and stagnant ones isn't more effort. It's better insights. StoreClaw analyzes your Shopify and Amazon data, surfaces your biggest growth opportunities, and helps you increase GMV while protecting profit. Start free with bonus tokens. No credit card required.