Reply-chain hijacking borrows existing trust
One of the most effective phishing techniques is to reply to a conversation that was already happening.
An attacker with access to somebody's mailbox finds a genuine thread, with genuine history and genuine people, and adds a message to it. Everything above their reply is real. There is no cold approach to be suspicious of, no unfamiliar sender, and the context is one you recognise because you were part of it. Almost everything people are taught to look for is absent, which is what makes it work.
More on Email security
- DKIM protects signed content against later modificationChange one word, break the seal
- DMARC depends on alignmentBoth names, or neither
- Forwarding can break email authentication assumptionsIt was re-posted on the way
- A display name is not an email addressThey wrote that name themselves
- Secure email gateways see only traffic that reaches themIt only sees what comes past it
- Quarantine creates a second security decisionHeld is not decided
