Plaintext communication (if not secured) allows interception.
Vulnerable to brute force and credential stuffing attacks.
Susceptible to DoS and command injection attacks.
Require IMAPS (port 993) with TLS encryption.
Implement rate-limiting to mitigate brute force attacks.
Use multi-factor authentication (MFA) for email accounts.
Repeated login failures or suspicious access patterns.
Unusual activity in IMAP server logs.
Compromised email accounts or unauthorised access.