Skip to main content
Conan O’Brien featured in series of 15+ AI security training modules
Blog
Phishing

Thread Hijacking Phishing: How Cyberattackers Exploit Trusted Email Conversations and How Organizations Can Stop Them

JULY 22, 202625 MIN READ
Adaptive TeamAdaptive Team
Thread Hijacking Phishing: How Cyberattackers Exploit Trusted Email Conversations and How Organizations Can Stop Them

Key takeaways

  • Thread hijacking phishing turns an organization's own trusted conversations into the delivery mechanism for fraud, which is what makes it so difficult to catch with the controls most security stacks already run.
  • Thread hijacking phishing inserts a malicious reply into a real, ongoing email conversation from a compromised but authenticated mailbox, so the recipient sees a trusted sender rather than an obvious cyberattack.
  • Because the message passes SPF, DKIM, and DMARC and originates from a legitimate account, thread hijacking phishing defeats the authentication and filtering controls most organizations depend on.
  • Thread hijacking phishing is a sub-technique of business email compromise (BEC) that steals existing trust rather than fabricating it, which drives higher per-incident losses than domain-based impersonation.
  • SOC teams detect thread hijacking phishing through behavioral signals: hidden mailbox rules, external forwarding, impossible-travel sign-ins, and sudden activity on dormant accounts.
  • Layered defense against thread hijacking phishing combines phishing-resistant MFA, mailbox anomaly detection, and out-of-band payment verification that no single technical control can replace.
  • Cybersecurity awareness training is the control that conditions the verification reflex, turning employees who recognize a hijacked thread into the last and most reliable line of defense.
  • A cybersecurity awareness training program built on realistic phishing simulations transforms abstract red flags into practiced recognition employees can recall under pressure.

Thread hijacking phishing inserts malicious replies into active, legitimate email conversations, weaponizing the trust between correspondents to bypass authentication protocols, evade content filters, and defraud organizations at scale. The same mechanisms that make these cyberattacks effective, authenticated sending domains, contextually relevant content, and the psychological weight of an existing business relationship, also create detection signals that security operations teams can monitor. What separates organizations that catch thread hijacking phishing early from those that discover it only after a wire transfer clears, is understanding how cyberattackers weaponize existing trust and build the controls that counteract it.

This guide covers:

  • How thread hijacking phishing progresses through the full cyberattack lifecycle, from initial credential compromise through reconnaissance, payload insertion, and lateral spread.
  • Why thread hijacking phishing slips past SPF, DKIM, DMARC, and content filters that were built to verify servers rather than human intent.
  • The SOC detection signals, incident response steps, and layered defenses that close the gaps traditional email security leaves open.
  • How cybersecurity awareness training conditions employees to verify sensitive requests before a hijacked thread turns into a fraudulent transfer.

Most organizations train employees to spot cold phishing while replies inside trusted threads slip past every filter. Adaptive Security builds the verification reflexes that stop thread hijacking phishing at the human layer.

Take a self-guided tour

What Is Thread Hijacking Phishing?

Thread hijacking inserts malicious messages into trusted conversations without cold phishing warning signs

Thread hijacking phishing is a sophisticated email cyberattack in which a cybercriminal compromises a legitimate email account, monitors active conversation threads, and inserts malicious messages, often payment redirects or credential-theft links, directly into ongoing correspondence between trusted parties. Because the message originates from a genuine account inside an established conversation, the recipient encounters none of the usual warning signs associated with a cold phishing email. This technique sits squarely within the business email compromise (BEC) family, which the FBI's Internet Crime Complaint Center tracks as one of the costliest categories of cyber-enabled fraud.

Definition and Core Concept

Thread hijacking phishing is defined by a single mechanic that separates it from every other phishing variant: the cyberattacker does not initiate contact. After gaining access to a real mailbox, typically through credential theft, a previous phishing success, or a session token compromise, the cyberattacker reads the victim's email silently for days or weeks, studying relationship dynamics, payment cadences, and conversational tone. Only when a high-value moment presents itself do they reply to an active thread as the genuine account holder.

This approach weaponizes existing trust. In a standard phishing cyberattack, the recipient must be convinced that an unfamiliar sender or spoofed address is legitimate. In thread hijacking phishing, that trust was already built over days, months, or years of real interaction, and the cyberattacker simply borrows it.

The email lands inside a thread the recipient has been actively participating in, from an address they recognize, often referencing specific details only a legitimate participant would know. The psychological friction that normally triggers suspicion never activates, which is precisely why generic phishing awareness leaves employees exposed to this technique.

The technical execution typically follows a three-phase sequence. First comes account compromise, where the cyberattacker gains persistent access to the mailbox and often establishes email rules that divert replies to hidden folders. Second comes reconnaissance, where the cyberattacker reads threads, identifies high-value targets, and maps the relationship web between senders and recipients.

Third comes insertion, where the cyberattacker replies within an existing thread, or in some variants forwards a real thread to a targeted employee with a fraudulent payment instruction, relying on accumulated trust to bypass scrutiny. This technique has existed for years, yet its prevalence has surged as account takeover (ATO) methods have become commoditized. Conversation hijacking has climbed sharply as a share of email-based cyberattacks, because thread hijacking phishing produces higher conversion rates than cold phishing when the trust problem is already solved.

According to the FBI's 2025 Internet Crime Report (released April 2026), cyber-enabled fraud accounted for almost 85% of all losses reported to IC3, totaling $17.7 billion, up from $13.7 billion in 2024. That concentration of loss around fraudulent, trust-based requests is exactly the pressure point thread hijacking phishing is built to exploit.

A cybercriminal reading months of email history can craft a payment redirect referencing the exact invoice a finance team expects. Adaptive Security trains employees to verify those requests before money moves.

Explore the platform

Thread Hijacking Phishing vs. Standard Phishing

The differences between thread hijacking phishing and standard phishing are structural rather than cosmetic. They diverge at the point of origin, the trust model, and the victim's cognitive response, and each divergence widens the detection gap that technical controls cannot close on their own.

Standard phishing emails arrive from outside the organization or from spoofed addresses, so they are interruption-based by nature. The recipient receives something unexpected, an invoice from an unknown vendor, a password-reset prompt, or a too-good-to-be-true offer, and must decide in seconds whether to engage. Cybersecurity awareness training teaches employees to spot these interruptions by checking the sender address, hovering over links, and questioning urgency, which gives even a moderately trained recipient a fighting chance.

Thread hijacking phishing dismantles that defense because the email is a continuation rather than an interruption. It appears inside a thread the recipient already opened, replied to, and filed as safe, and the sender address is the actual account of a colleague, vendor, or client. The message references real context such as a project name, an invoice number, or a meeting date, so the recipient's internal security checklist returns clean answers every time.

The psychological mechanism is fundamentally different. Standard phishing exploits urgency and fear, pressuring the recipient to act before a fabricated deadline passes. Thread hijacking phishing exploits rapport and routine, because the existing conversation already provides the justification and the cyberattacker never needs to manufacture a crisis.

When a finance team member receives a reply in an ongoing vendor payment thread with updated wiring instructions, resistance is exceptionally low and nothing about the interaction feels out of place. Detection is also harder at the infrastructure level, because standard phishing often leaves artifacts that email security gateways can catch, such as spoofed headers, domain reputation failures, and known-malicious URLs.

Thread hijacking phishing emails originate from legitimate, trusted accounts inside the organization or its partner ecosystem, so the headers are clean and any URLs may be benign document-sharing links leading to a second-stage payload. Traditional secure email gateways and even AI-driven filters struggle to distinguish a malicious thread reply from a legitimate one when both originate from the same authenticated account.

Key Terminology in Thread Hijacking Phishing

The vocabulary around thread hijacking phishing is overlapping and inconsistent, and it is worth clarifying because security teams and vendors use several terms that describe variations of the same core technique. Each term carries a slightly different emphasis, and understanding all four helps security leaders recognize that they describe different facets of the same persistent, expensive cyber threat.

  • Conversation hijacking is the broadest term and is functionally interchangeable with thread hijacking phishing. It describes any cyberattack in which a cybercriminal inserts messages into an existing email exchange between two or more parties after compromising one participant's account, emphasizing the theft of the specific conversational history that increases credibility.
  • Reply-chain attack refers to the same technique but focuses on the delivery mechanism, where the cyberattacker replies within an existing email chain rather than composing a new message. Reply-chain emails inherit the subject line, thread ID, and message history of the original conversation, making them indistinguishable from legitimate responses in both the recipient's inbox and most security filters.
  • Multi-persona phishing describes a more complex variant in which the cyberattacker compromises multiple accounts within the same organization or partner network and orchestrates a conversation involving several personas. One compromised account sends a request, another confirms it, and a third provides supporting documentation, all from real mailboxes the recipients trust, which mimics internal approval workflows and social proof.
  • Business email compromise (BEC) is the umbrella category under which thread hijacking phishing, conversation hijacking, and reply-chain attacks all sit. The FBI defines BEC as a sophisticated scam targeting businesses and individuals who perform legitimate transfer-of-funds requests, frequently carried out by compromising business or personal email accounts.

These terms are not mutually exclusive, and a single cyberattack can be accurately described as thread hijacking phishing, a reply-chain attack, and a BEC incident simultaneously. The terminology often reflects which aspect the speaker is emphasizing: the method of access, the delivery vector, the target psychology, or the criminal category. Each describes the same exploitation of the human trust layer that no email gateway can fully protect.

Understanding what thread hijacking phishing is matters only insofar as it drives organizations to act, because cybersecurity awareness training that focuses exclusively on spotting cold phishing emails leaves employees defenseless against the cyberattack they are least likely to question. The most effective countermeasure is exposing employees to realistic thread hijacking scenarios in a controlled environment, so they learn to verify payment requests and sensitive data transfers through a secondary channel even when the request appears inside a familiar conversation from a trusted colleague.

Employees drilled only on suspicious sender addresses cannot defend against a real vendor replying in a real thread. Adaptive Security exposes teams to thread hijacking scenarios that build the right instinct.

Take a self-guided tour

How Thread Hijacking Phishing Works: The Complete Attack Lifecycle

Thread hijacking phishing begins when a cyberattacker gains access to a legitimate email account, reads real conversations to identify valuable threads, inserts a malicious reply that inherits the trust of the existing exchange, and then covers every trace using automated mailbox rules. Each stage exploits a specific weakness in how organizations trust their own email infrastructure. The entire cyberattack often completes before the genuine account holder notices anything is wrong, which is why every stage below matters to detection.

Stage 1: Initial Account Compromise

Every thread hijacking phishing attack starts with a breached mailbox, and cyberattackers gain access through credential theft, session hijacking, or infostealer malware. Each vector feeds the same objective: persistent, authenticated access to a mailbox full of trusted conversations.

Credential theft remains the most common entry point because employees reuse passwords across personal and corporate accounts. When a third-party service suffers a data breach, those credentials are tested against Microsoft 365 and Google Workspace logins at scale, and cyberattackers also harvest credentials through phishing campaigns that direct targets to fake login portals indistinguishable from the real thing.

Session hijacking takes a more sophisticated route. Through adversary-in-the-middle (AiTM) toolkits, cyberattackers intercept authentication tokens after a user completes multi-factor authentication, so the cyberattacker never sees the password. The session token grants the same access as the legitimate user and remains valid until revoked, which renders MFA alone insufficient as a defense.

Infostealer malware, often delivered through cracked software, malicious browser extensions, or compromised advertising networks, silently exfiltrates saved credentials, session cookies, and autofill entries from the victim's browser. Within minutes, the cyberattacker has a full credential inventory for the target and often for multiple users on the same device. Once inside a mailbox, the cyberattacker has access to years of email history, contact lists, and file attachments, and that repository becomes the raw material for the next stage.

Stage 2: Reconnaissance and Thread Selection

With a compromised inbox open, the cyberattacker reads. They hunt for threads with specific characteristics: active payment negotiations, outstanding invoices, pending wire transfers, merger discussions, or exchanges between finance staff and external vendors. Threads involving senior executives carry the highest value because recipients are conditioned to comply with requests from authority figures.

The cyberattacker absorbs the organization's rhythms over days or weeks, learning how the company formats invoices, the tone executives use, which vendors have recurring billing relationships, and when payments typically process. According to Verizon's 2026 Data Breach Investigations Report, stolen credentials were involved in 13% of all breaches, which is the same foothold that makes this patient reconnaissance possible.

Thread selection comes down to trust currency. A 40-message thread between a controller and a CFO carries exponentially more credibility than a cold email, so the cyberattacker inserts themselves into a conversation the recipient already trusts at a moment when action is expected. That psychological advantage is the core mechanism that makes thread hijacking phishing so dangerous and so difficult for generic phishing tests to address.

A password-sprayed procurement inbox looks worthless until a cyberattacker reads its active vendor threads. Adaptive Security uses realistic phishing simulations to build habits that stop credential compromise at the source.

Explore the platform

Stage 3: Malicious Payload Insertion

Once the right thread is identified, the cyberattacker crafts the insertion so the reply appears as a normal continuation with the same subject line, formatting, and sender identity the recipient has trusted throughout the exchange. The payload varies by objective, and each variant is tuned to the specific thread it sits inside.

For financial fraud, the cyberattacker attaches a fake invoice with altered payment instructions using the same vendor and formatting but a different bank account. For credential harvesting, the reply contains a link to a SharePoint or DocuSign phishing portal, and in espionage cases the cyberattacker requests that sensitive documents be forwarded under the cover of an existing discussion.

Payment instruction changes are the most lucrative variant. The cyberattacker waits until a genuine invoice thread reaches the approval stage, then replies with updated banking details, and because the message comes from a trusted sender inside a trusted thread, the recipient rarely questions it. According to the FBI's 2025 Internet Crime Report (released April 2026), business email compromise (BEC) accounted for $3.046 billion in losses across 24,768 incidents, averaging $123,000 per case.

Malicious links embedded in thread replies bypass most link-scanning tools because they arrive from an internal, authenticated account. The same email sent cold would trigger security warnings, but sent as a reply in an established thread, it sails through.

Stage 4: Covering Tracks

Once the malicious reply is sent, the cyberattacker moves immediately to operational security, and the objective is to prevent the genuine account holder from seeing any evidence of the intrusion. The primary method is the creation of mailbox rules that quietly reroute the conversation away from the victim's view.

Cyberattackers configure rules, often named with a single period to appear inconspicuous, that automatically route incoming replies containing specific keywords to rarely accessed folders such as Archive or RSS Feeds. The rule marks messages as read and stops processing further rules, ensuring the target never sees a response. Security journalist Brian Krebs documented this exact pattern in 2024, noting that these attacks exploit the trust embedded in existing conversations to bypass both human skepticism and technical controls.

Cyberattackers also delete sent items from the compromised mailbox and purge the recoverable items folder when possible. Some configure forwarding rules that silently copy all inbound mail to an external address, extending the window of visibility even after credentials are reset, and timing is deliberate because attacks are often launched during holidays or weekends to maximize the gap between intrusion and detection.

Stage 5: Lateral Propagation

A single compromised mailbox is never the endgame. Once a cyberattacker controls a trusted internal account, they propagate across the organization and outward to supply chain partners using the trust relationships embedded in every email thread. This is where one hijacked inbox becomes an organization-wide incident.

Internally, the cyberattacker scans for threads involving IT, HR, and other privileged departments, then uses the hijacked identity to send internal messages requesting credential resets, VPN access, or MFA re-enrollment, all appearing to come from a colleague the recipient knows personally. One compromised finance account can yield several compromised IT accounts within a week.

External propagation follows the same logic. The cyberattacker finds threads with clients, vendors, law firms, and auditors, then replies with malicious payloads, and because the message arrives from a trusted business partner inside an established conversation, the recipient organization's defenses are as blind to it as the original victim's were. One thread hijack in a mid-market manufacturer can cascade into compromises across an entire supply chain.

This is why thread hijacking phishing defies perimeter-based detection logic. Every email the cyberattacker sends is technically legitimate, sent from an authenticated account, inside a trusted thread, to a known contact, so the cyber threat is not in the infrastructure but in the human trust that infrastructure was built to carry. Phishing simulations that replicate real thread hijacking scenarios close the detection gap that technology alone cannot address.

One hijacked finance mailbox can seed credential-reset requests that compromise IT accounts across the company within days. Adaptive Security conditions every department to challenge internal requests that break from normal process.

Book a demo

How Cyberattackers Gain Initial Access for Thread Hijacking Phishing

Thread hijacking begins with mailbox compromise and has become the leading BEC technique at scale

Thread hijacking phishing does not start in the inbox. It starts weeks or months earlier, when a cyberattacker compromises a legitimate mailbox through one of several distinct and increasingly sophisticated entry vectors. Thread hijacking and fabricated threads have grown into the leading business email compromise (BEC) technique across the industry, and that volume is impossible without scalable, repeatable methods of gaining initial mailbox access that bypass the defenses most organizations consider sufficient.

Credential Phishing via Proxy-Based Kits

Adversary-in-the-middle (AiTM) phishing kits represent the most dangerous evolution in credential theft because they defeat the one control organizations have spent years deploying: multi-factor authentication. Traditional phishing captures a username and password, but AiTM kits sit between the victim and the real login page, proxying the entire authentication flow in real time and capturing not only credentials but also the session token issued upon successful MFA completion.

A January 2026 case documented by ANY.RUN researchers, examined in detail later in this guide, shows the pattern in full: a compromised contractor mailbox, a phishing link placed inside an active C-suite thread, and no domain mismatch, urgency language, or formatting anomaly to give it away.

The phishing link routed through proxy infrastructure that captured the target's credentials and session token, granting the cyberattacker immediate authenticated access indistinguishable from the legitimate user's activity. The speed of these attacks leaves almost no window for human intervention, because proxy-based kits complete token capture in under a minute from the moment a victim clicks the link, which means the compromise is finished before most security teams receive an alert.

Session Cookie Theft and OAuth Token Abuse

Stolen session cookies let cyberattackers authenticate as the victim without ever needing the password. Once a user authenticates to a cloud email platform, the browser stores a session cookie that represents that authenticated state. If a cyberattacker acquires that cookie through an AiTM proxy, malware, or any other extraction method, they can import it into their own browser and resume the session from anywhere with no MFA prompt.

This is the mechanism that makes thread hijacking phishing operationally possible at scale. A cyberattacker with a valid session token can read months of email history, study communication patterns, identify ongoing deals and invoice threads, and insert a fraudulent message that reads as a natural continuation of the conversation. According to the IBM X-Force Threat Intelligence Index 2025, valid compromised credentials were the initial access vector in 30% of all intrusions in 2024, which reflects how thoroughly identity-based attacks have supplanted traditional exploit-based intrusions.

OAuth consent grants create an even more persistent backdoor. When a user approves a malicious OAuth application during a phishing flow, that application receives delegated access to the mailbox through Microsoft Graph API or the equivalent Google API. That access survives password resets, MFA changes, and session expiration, because it operates at the application-permission level rather than the user-session level.

Microsoft documented campaigns where a single threat actor created approximately 17,000 multitenant OAuth applications across different tenants, using delegated mailbox access to read email and propagate phishing internally without detection. For thread hijacking phishing specifically, OAuth grants give cyberattackers the ability to monitor inboxes continuously and insert themselves into conversations at the moment of maximum impact, such as when a payment instruction is about to be confirmed.

An OAuth grant approved during a single phishing flow can survive every password reset a security team performs. Adaptive Security teaches employees to recognize the consent prompts that hand cyberattackers permanent mailbox access.

Take a self-guided tour

Infostealer Malware: The Credential Pipeline at Scale

Infostealer malware operates as the industrial-scale supply chain for credential theft. These lightweight programs harvest saved browser passwords, autofill records, session cookies, and cryptocurrency wallets from infected endpoints, package the data into a log, and sell it on dark-web marketplaces where initial access brokers buy the raw material for thread hijacking phishing operations.

The economics explain why the technique has become a volume business. Commercial stealers now sell on a subscription basis at low monthly prices, putting industrial-grade credential theft within reach of operators with minimal technical skill, and a broker who buys a log containing valid Microsoft 365 credentials acquires everything needed to begin reconnaissance with no phishing infrastructure required. According to Verizon's 2026 Data Breach Investigations Report, 96% of ransomware victims were small and medium-sized businesses, which present the unpatched devices and compromised credentials that infostealer logs put up for sale.

The personal-device blind spot makes this cyber threat especially difficult to contain. A large share of devices infected in infostealer campaigns are personal rather than corporate-managed, creating a breach pathway that sits entirely outside enterprise endpoint controls. An employee who saves a work password in their personal browser, or who checks work email on an unmanaged home laptop, creates a credential bridge that no corporate security stack can see.

Credential Stuffing and Password Spraying

Lower-sophistication techniques have not disappeared; they have become the volume layer that feeds more targeted operations. Credential stuffing automates login attempts using username-password pairs harvested from unrelated breaches, exploiting the reality that a majority of people reuse passwords across accounts, while password spraying tests a small set of common passwords across many accounts to stay beneath account-lockout thresholds.

These techniques succeed specifically against accounts without MFA or with predictable password hygiene, and they succeed at a rate that makes the economics work for cyberattackers operating at scale. A single successful credential-stuffing login against a Microsoft 365 account that lacks MFA gives the cyberattacker access to the inbox, the sent-items folder, the contact list, and the calendar.

A password-sprayed account belonging to a mid-level procurement manager may not look like a valuable target, but that inbox contains active threads with finance, legal, and external vendors, each of which becomes a hijacking opportunity once the cyberattacker reads the conversation history. Once a valid session token, an OAuth grant, or a compromised internal account is obtained, the cyberattacker's activity becomes largely indistinguishable from legitimate user behavior.

Every thread hijacking phishing operation depends on an earlier compromise that gave the cyberattacker not just access, but the ability to blend into ongoing business conversations so smoothly that neither the recipient nor any security tool raises an alarm. The question is not whether a cyberattacker can get inside, but how long they have already been there before anyone notices.

Reused passwords and unmanaged personal devices hand cyberattackers the credentials that make thread hijacking possible. Adaptive Security builds the password and device habits that close those entry points workforce-wide.

Explore the platform

Why Thread Hijacking Phishing Evades Traditional Email Security Defenses

Thread hijacking phishing evades defenses because it operates entirely inside authenticated, pre-existing relationships. The message arrives from a legitimate, compromised mailbox that passes every email authentication protocol an organization has deployed, and across the industry, hijacked and fabricated conversation threads have surpassed traditional cold-email BEC as the leading technique in the category. The infrastructure was built to verify servers rather than human intent, and that gap is exactly what this technique exploits at every layer of the defense stack.

The Trust Problem: Why SPF, DKIM, and DMARC Pass

Email authentication protocols, Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting, and Conformance (DMARC), were designed to answer one question: did this email really come from the server it claims to have come from? They were never designed to answer the far harder question of whether the sender should be trusted with what they are asking for.

When a cyberattacker compromises a legitimate mailbox and replies inside an active thread, every authentication check returns clean. SPF verifies that the sending IP is authorized by the domain, DKIM confirms the message was not tampered with in transit, and DMARC evaluates both and returns a pass when properly enforced. From the perspective of the authentication stack, the email is indistinguishable from genuine business communication because structurally it is; the sending infrastructure is authentic and only the sender's intent has been corrupted.

This authentication blind spot is particularly dangerous because it creates a false sense of security among security leaders. Organizations that have invested heavily in DMARC enforcement, moving from a monitoring policy to full rejection, often believe they have closed the door on impersonation-based phishing.

Thread hijacking phishing walks straight through that door because it does not impersonate the domain; it operates from the domain. MITRE ATT&CK maps this pattern under T1566 (Phishing), which explicitly identifies thread hijacking as a technique where adversaries insert targets into existing email threads containing malicious files or links.

Content-Based Filter Blind Spots

Traditional email content filters operate on pattern matching: known-bad URLs, suspicious attachment types, linguistic markers of urgency or fraud, and mismatches between display names and sender addresses. Thread hijacking phishing defeats every one of these signals because the cyberattacker is writing from inside the conversation rather than launching something new.

The reply references real names, real project titles, real invoice numbers, and the natural cadence of an ongoing business discussion. The ANY.RUN contractor case noted earlier is instructive here: there was no misspelled domain, no generic greeting, and no flagged attachment, just a link that looked like the next document in an approval workflow everyone was already expecting to review.

Content filters that score messages based on anomaly detection find nothing anomalous because the cyberattacker has access to every prior message in the thread and can match its tone, formatting, and vocabulary precisely. The absence of malware signatures compounds the problem, because many of these attacks deliver links to adversary-in-the-middle (AiTM) phishing pages rather than malicious attachments. The initial email contains zero executable code, zero suspicious macros, and zero attachment-based indicators, so the malicious infrastructure sits behind a URL that is invisible at the moment of delivery.

The Context Gap in Legacy Email Security

Secure email gateways (SEGs) and native protections in Microsoft 365 and Google Workspace evaluate messages individually. Each email is scored on its own metadata, sender reputation, header integrity, body content, and URL reputation, without meaningful reference to the conversation it belongs to. This atomized evaluation model is exactly the wrong approach for detecting thread hijacking phishing, where the risk signal exists not inside any single message but in the relationship between messages.

A reply from a known vendor after two weeks of silence containing a new link to a document-signing platform is not suspicious in isolation. It is suspicious only when contextualized against the thread's prior rhythm, the sender's historical communication patterns, and the sudden introduction of a new external URL where none had appeared before.

Legacy SEGs lack conversation-level state. They cannot detect that a sender has never previously included links in threads with a given recipient, that the tone of a reply shifts subtly from the thread's established pattern, or that a reply arrives at an unusual hour for that specific sender. These are the behavioral signals that distinguish a legitimate continuation from a hostile insertion, and they are invisible to per-message inspection engines.

Email defenses built to inspect messages one at a time will systematically miss attacks that derive their power from the conversation they sit inside.

Multi-Persona Phishing and Advanced Evasion

The most sophisticated thread hijacking phishing campaigns escalate beyond a single malicious reply. Cyberattackers now orchestrate multi-persona scenarios where multiple compromised or spoofed participants reinforce the illusion of legitimacy, making the attack virtually indistinguishable from normal multi-party business communication at the human-review level. One compromised account replies with a request, and a second compromised account, perhaps at a different organization involved in the same project, confirms or amplifies it.

The target sees colleagues and partners apparently aligned, which reduces the likelihood that any single participant will question the thread's integrity. MITRE ATT&CK T1598 (Phishing for Information) covers the credential-harvesting variant of these attacks, noting that adversaries frequently use compromised accounts to manipulate email metadata and headers, removing evidence of the intrusion while harvesting credentials or sensitive data from thread participants.

The multi-persona approach is particularly effective against finance and procurement teams, where multi-party approval chains are standard operating procedure. When a payment request arrives inside a thread where the vendor, the project manager, and the executive sponsor all appear to have weighed in, the instinct to verify through a second channel is overridden by the chorus of apparent consensus already on display.

According to the World Economic Forum's 2026 Global Cybersecurity Outlook, among respondents from the most cyber-resilient organizations, 52% indicate that board members receive regular cybersecurity updates and 48% report that board members are actively engaged with the cybersecurity function, reflecting how far trust-based threats have risen up the executive agenda at the best-prepared companies. This tactic exploits a fundamental asymmetry, because cyberattackers can study every message in the thread, including attachments, tone, and decision-making patterns, before inserting their contribution.

The recipient experiences the thread as a continuous, unbroken narrative, and the result is a social engineering cyberattack that inherits the full authority structure of an existing business relationship. Defending against it requires moving beyond per-message inspection toward behavioral analysis that reads conversations the way a human security analyst would, and equipping employees with the skills to recognize when a trusted thread asks them for something worth verifying.

Authentication confirms the mailbox is real while a cyberattacker sits inside it redirecting a payment. Adaptive Security pairs AI email security with training so both tooling and workforce catch what authentication cannot.

Explore the platform

Thread Hijacking Phishing vs. Business Email Compromise: Overlap and Key Differences

Thread hijacking phishing and business email compromise (BEC) are often conflated in security discussions, but the relationship is hierarchical rather than synonymous. BEC is the umbrella category encompassing any cyberattack that compromises or impersonates business email to conduct fraud, while thread hijacking phishing is one specific, highly effective technique within that category. Where most BEC variants fabricate trust from scratch, thread hijacking steals trust that already exists by inserting itself into a genuine, ongoing conversation.

Defining BEC and Its Relationship to Thread Hijacking Phishing

Business email compromise (BEC) is the broad category of attacks in which criminals manipulate or impersonate business email to conduct unauthorized transfers of funds or extract sensitive data. It is a family of tactics that includes domain spoofing, lookalike domain registration, executive impersonation from external addresses, vendor email compromise, and thread hijacking phishing. According to Verizon's 2026 Data Breach Investigations Report, 62% of confirmed incidents involve a human element, which is precisely the layer every BEC variant is engineered to exploit.

Thread hijacking phishing is the specific BEC sub-technique in which a cyberattacker gains access to a legitimate email account and then replies within an existing email conversation the recipient already recognizes and trusts. Because the cyberattacker operates from inside a real account within a real thread, the message carries none of the red flags that alert recipients to other BEC variants. There is no misspelled domain to catch and no unfamiliar sender address to question, and the controls that catch domain spoofing, DMARC, DKIM, and SPF, are completely blind to a cyberattacker who is inside a legitimate mailbox replying to a real conversation.

Where Thread Hijacking and BEC Overlap

Thread hijacking exploits business trust rather than technical vulnerabilities, bypassing infrastructure defenses

Thread hijacking phishing and other BEC variants converge around a shared exploitation of human trust rather than technical vulnerabilities. None of these attacks rely on malware, and they do not exploit software vulnerabilities, crack encryption, or bypass firewalls. Instead, they weaponize existing business relationships, the very trust that makes organizations function at speed.

Both thread hijacking phishing and other BEC techniques target financial transactions and sensitive data as their primary payload. Whether the cyberattacker spoofs a CEO's address from an external domain or replies within a hijacked thread to redirect a vendor payment, the objective is the same: convince the recipient to move money or disclose information before suspicion can form. BEC scams have been reported across all 50 U.S. states and well over 100 countries, which underscores how uniformly effective trust-based social engineering remains across cultures and industries.

Another critical overlap is that both bypass traditional email security gateways. Secure email gateways look for malicious links, attachments, and domain reputation signals, and a well-crafted BEC email contains none of those signals. The email body is plain text, the request is plausible, and in the case of thread hijacking phishing, the sender is literally the person the recipient has been emailing all week.

Where Thread Hijacking and BEC Diverge

The divergence becomes clearest when examining what each technique requires to succeed. Standard BEC techniques do not require account compromise, because domain spoofing, lookalike domain registration, executive impersonation from a free webmail account, and vendor email compromise all manufacture the appearance of legitimacy externally.

Thread hijacking phishing, by contrast, requires access to a genuine, pre-existing email conversation inside a legitimate account. The cyberattacker must first compromise credentials through phishing, credential stuffing, or session token theft before the hijack can begin, so the technical barrier to entry is higher but the payoff is proportionally greater. Once inside a real thread, the cyberattacker inherits the full context of the relationship and can craft a request so contextually accurate that even trained employees struggle to identify it as fraudulent.

Domain spoofing and lookalike domains can be detected by authentication protocols and attentive recipients, but thread hijacking phishing leaves no such fingerprints. The sender address is correct, the email signature matches, and the conversation history is real, so the only anomaly is the ask itself, and by the time that registers, the transfer is often already complete.

Financial Impact of Thread Hijacking Phishing

Thread hijacking phishing attacks tend to produce higher per-incident losses than other BEC variants because the trust embedded in an existing conversation dramatically increases victim compliance. A finance employee receiving a wire request from an external "CEO" address must overcome multiple signals of suspicion before complying, while that same employee receiving a reply within an ongoing vendor negotiation thread encounters no such friction.

The built-in context, prior messages, agreed-upon payment terms, and the natural cadence of the exchange short-circuits the verification instincts that might catch other BEC attempts. Security practitioners consistently report that account-compromise-based attacks, including thread hijacking phishing, produce larger individual losses than domain-based impersonation, because compromising an account and replying within a real thread takes more effort and is therefore reserved for higher-value targets.

The comparison table below summarizes how thread hijacking phishing and other BEC variants differ across the dimensions that matter most for detection and loss prevention.

Dimension Thread Hijacking Phishing Other BEC Variants
Account compromise required Yes; the cyberattacker must access a legitimate mailbox No; the cyberattacker fabricates identity externally
Authentication protocol detection Ineffective, since the sender uses a real, authenticated account Partially effective, since DMARC, DKIM, and SPF can catch spoofing
Trust mechanism Hijacked, exploiting existing conversation history and relationships Fabricated, relying on the recipient accepting a manufactured identity
Detection difficulty for recipients Extremely high, with no visible anomalies in sender, thread, or signature Moderate, since an unfamiliar sender address or domain discrepancy may raise flags
Typical per-incident loss Higher, since context-rich targeting justifies investment in account compromise Lower to moderate, with broader targeting and lower success rates per attempt
Primary defense Multi-channel verification, phishing-resistant MFA, and training on anomalous requests Email authentication protocols, domain monitoring, and training on sender verification

The gap between these two approaches points to a larger truth about modern email-based cyber threats: defenses built to catch external forgery cannot stop a cyberattacker who has already walked through the front door. Organizations that rely exclusively on authentication protocols leave their most sensitive transactions exposed to the one attack vector those protocols were never designed to detect.

A malicious reply from a trusted mailbox needs no forged domain to succeed, so protocol checks never fire. Adaptive Security closes that gap with training built specifically for account-compromise attacks like thread hijacking.

Book a demo

How to Defend Against Thread Hijacking Phishing Attacks

Defending against thread hijacking phishing demands a layered security architecture that goes well beyond the generic anti-phishing advice most organizations rely on. Email authentication with SPF, DKIM, and DMARC is the necessary foundation, but these protocols provide zero protection against a malicious reply sent from a genuinely compromised, authenticated mailbox. Effective defense layers mailbox-level anomaly detection, phishing-resistant multi-factor authentication (MFA), and out-of-band payment verification on top of that foundation, so the attack fails even when a technical control does.

1. Deploy Email Authentication Protocols, and Understand Their Limits

SPF, DKIM, and DMARC form the backbone of email authentication, and every organization should have them properly configured. SPF specifies which IP addresses are authorized to send mail from a domain, DKIM cryptographically signs outgoing messages so receiving servers can verify the message was not altered in transit, and DMARC ties them together by telling receiving servers what to do when a message fails authentication.

Configured correctly, these three protocols prevent cyberattackers from spoofing a domain and sending phishing emails that appear to come from the organization, and they stop unauthorized senders from using a lookalike domain. Any domain without DMARC set to at least quarantine is leaving the front door wide open.

None of these protocols matter when the cyberattacker is replying from a mailbox they have already compromised. As established earlier, all three checks pass because the mailbox itself is genuine and only the person behind the keyboard is illegitimate. Authentication is the necessary floor rather than the defense, which is why the layers that follow carry the actual weight against thread hijacking phishing.

2. Implement Mailbox-Level Monitoring and Anomaly Detection

Since thread hijacking phishing attacks originate from compromised but authenticated mailboxes, the signals security teams need to detect are behavioral rather than protocol-level. Security teams must monitor for the specific anomalies that indicate a cyberattacker has taken control of an account and begun exploiting its existing conversation history.

The most critical signal is the silent creation of inbox rules. Cyberattackers routinely establish rules that delete replies from the real account owner, forward specific messages to an external address, or archive messages containing keywords like "fraud," "verify," or "banking" before the legitimate user can see them. These rules are often set within minutes of initial compromise and are the earliest indicator that a mailbox has been weaponized.

Other signals demand equal attention: forwarding rules pointing to external domains that suddenly appear on accounts that have never forwarded mail before, anomalous spikes in reply volume to dormant threads, and replies sent at unusual hours relative to the account owner's normal behavior. Dormant accounts that suddenly become active, especially those belonging to departed employees or contractors whose mailboxes should have been deactivated, are another red flag.

The scale of the problem justifies the monitoring investment. According to the FBI Internet Crime Complaint Center's 2025 Internet Crime Report, internet crime drove $20.877 billion in reported losses, a 26% jump over the prior year, and business email compromise (BEC) remains a persistent share of that total. When nearly three in ten BEC attacks now ride on hijacked trust and measured losses reach into the billions, mailbox-level anomaly detection stops being optional.

3. Deploy Phishing-Resistant MFA and Conditional Access Policies

MFA is necessary, but it is not sufficient against a threat actor who has done their homework. Thread hijacking phishing begins with credential compromise, and adversary-in-the-middle (AiTM) proxy kits are purpose-built to strip MFA out of the equation.

When an employee clicks a link inside a hijacked thread and is proxied through an AiTM server, the token capture described earlier plays out in seconds. The victim sees a legitimate-looking sign-in page, completes their push notification or one-time code, and walks away thinking nothing happened, while the cyberattacker now holds a valid, authenticated session.

The Canadian Centre for Cyber Security's 2025 guidance on AiTM defense underscores that phishing-resistant MFA, specifically FIDO2 and WebAuthn hardware security keys, is the only authentication method that prevents session token theft by cryptographically binding the authentication to the legitimate domain. Unlike push notifications, SMS codes, or authenticator app one-time passwords, a FIDO2 key will not complete the authentication handshake with a fraudulent proxy server, because the domain mismatch breaks the ceremony and the cyberattacker gets nothing.

Conditional access policies add a second critical layer. Requiring compliant, managed devices for access to email and collaboration tools, enforcing geographic and IP-based restrictions, and binding session tokens to the specific device that completed authentication all reduce the window of damage even when credentials are stolen. Session token binding, which ensures that a token issued to one device cannot be replayed from another, is particularly effective against AiTM attacks that export tokens for use on cyberattacker-controlled infrastructure.

Push-notification MFA still hands a cyberattacker the session token the moment an employee approves a proxied login. Adaptive Security trains teams to recognize AiTM sign-in traps before they complete the handshake.

Take a self-guided tour

4. Build Out-of-Band Vendor and Payment Verification Workflows

Every layer described above can fail. A compromised vendor mailbox will pass authentication checks, and an employee who clicks a well-crafted link in a seven-forward-deep approval thread may still hand over their session token despite MFA. When the technical controls run out, process controls are what stop the wire transfer.

The single most effective defense against thread hijacking phishing monetization is an out-of-band verification workflow for payment changes. Any request to update banking details, redirect an invoice payment, or change wire instructions, regardless of how legitimate the email thread looks or how urgent it sounds, must be verified through a second, independent channel. The verifying phone number must come from a system of record the cyberattacker cannot alter, such as the vendor master file, the ERP contact record, or a credentialed external database maintained outside the email environment.

Multi-person approval chains add another friction point that cyberattackers cannot easily overcome. A single compromised finance team member who approves a fraudulent invoice is a six-figure incident, but two approvers, each operating from an independently verified contact and neither communicating verification details through the hijacked thread, force the cyberattacker to compromise multiple accounts across different channels simultaneously.

Verified contact databases deserve specific investment. When every phone number a finance team uses to verify payment changes lives in the same email inbox the cyberattacker already controls, verification is theater. Finance, procurement, and accounts payable teams need a separate, maintained contact repository, ideally integrated into the ERP or procurement platform and updated through a controlled process rather than through inbound email requests.

This closes the loop, because even when a thread is hijacked and credentials are stolen, the payment never moves without a human-to-human voice confirmation against a number the cyberattacker cannot redirect.

Thread hijacking phishing succeeds because it inherits the credibility of existing conversations and long-standing vendor relationships. Defeating it requires introducing structured friction exactly where the cyberattacker depends on speed and silence, and simulating these scenarios so employees recognize the pattern before a real attack lands turns a procedural safeguard into an instinctive one.

A verification phone number stored in the same inbox a cyberattacker controls turns payment confirmation into theater. Adaptive Security drills the out-of-band verification habit until employees reach for an independent channel automatically.

Book a demo

Real-World Thread Hijacking Phishing Examples and Case Studies

Thread hijacking phishing is not a theoretical attack pattern. Documented incidents reveal an operational playbook that combines patience, precision, and deep exploitation of trusted business relationships, and the cases below show how the technique plays out from initial contractor compromise to multi-persona invoice fraud. Understanding these real sequences helps security teams and employees recognize the pattern before a hijacked thread lands in their own inbox.

The Compromised Contractor C-Suite Attack

In January 2026, ANY.RUN researchers uncovered a supply chain phishing campaign in which cyberattackers compromised a sales manager's mailbox at one of the target company's trusted contractors and waited, monitoring ongoing discussions until they identified a thread involving multiple executives. The conversation was about finalizing a document approval, a routine, high-trust workflow where an extra link or attachment would not raise suspicion.

By the time the malicious reply landed in the executives' inboxes, the email had passed through seven forwards, each layering additional legitimacy onto the thread. The cyberattackers did not need to fabricate urgency or impersonate anyone cold, because the thread already contained the names, the rapport, and the business context. The only fabricated element was the phishing link, which led through a multi-stage redirection chain, including anti-bot gates, to an adversary-in-the-middle credential harvesting page designed to capture Microsoft authentication tokens, including those protected by multifactor authentication.

Thread hijacking phishing exploits a psychological vulnerability that no security filter can patch: recipients see their name attached to an ongoing discussion and instinctively engage, often before skepticism has time to activate. That instinct is exactly what cybersecurity awareness training is designed to interrupt.

Multi-Persona Invoice Fraud Scenarios

Not all thread hijacking phishing attacks insert a single malicious link. A more sophisticated variant involves compromising multiple accounts across the same supply chain to construct fraudulent invoice threads where every participant appears legitimate to everyone else. Security researchers have cataloged recurring multi-persona scenarios that follow predictable but devastating patterns.

In the vendor impersonation scenario, cyberattackers compromise a supplier's mailbox and reply within a real invoice discussion, substituting altered banking details for an upcoming payment. The request arrives from the vendor's actual email address, inside the vendor's actual email thread, referencing the vendor's actual invoice number. In the executive impersonation variant, a compromised executive account sends a follow-up message to the finance team, applying pressure to process the updated payment before quarter close.

The legal and accounting scenarios are equally precise. A compromised law firm account inserts a fraudulent contract amendment into a live negotiation, or a compromised accounting firm requests sensitive financial documents under the cover of routine audit preparation. Each of these scenarios succeeds because the cyberattacker is writing from inside the trust boundary that every verification protocol assumes is secure.

The Speed of Modern Thread Hijacking Phishing

Velocity defines the operational tempo of thread hijacking phishing as much as stealth does. Cyberattackers can exfiltrate real email threads from a compromised mailbox, generate spoofed replies, and deliver malicious payloads to the original correspondents within hours of initial infection. The reply spoofs the infected user's name, lands in the original contact's inbox, and appears to be a natural continuation of an earlier conversation, with the thread itself supplying the sender identity, the subject line, the business context, and the relationship history.

According to the CrowdStrike 2026 Global Threat Report, the average adversary breakout time, the window between initial access and lateral movement, dropped to 29 minutes, with the fastest measured at just 27 seconds. Security operations center teams calibrated for dwell times measured in days may not be prepared for an attack pattern where the full kill chain completes in a single afternoon.

This velocity collapses the window for detection, investigation, and response. It also makes clear why phishing simulations that train employees to pause and verify, even on messages that look fully authentic, must run continuously rather than once a year. When a hijacked thread lands in an inbox, the employee is the last control between the cyberattacker and a credential harvest that bypasses multifactor authentication entirely.

When the kill chain completes in under an hour, an untrained employee is the last control before a drained account. Adaptive Security runs continuous phishing simulations that keep that reflex sharp year-round.

Explore the platform

How SOC Teams Detect Thread Hijacking Phishing Activity

Thread hijacking inserts payment redirects into real vendor conversations from compromised accounts

Thread hijacking phishing is the most surgical variant of business email compromise (BEC). Rather than sending a fake invoice from a lookalike domain, a cyberattacker inserts themselves into a real conversation between a vendor and a finance executive, replies from the vendor's actual compromised account, and redirects the payment before anyone notices the thread was poisoned. According to the FBI Internet Crime Complaint Center's 2025 Internet Crime Report, phishing and spoofing generated 191,561 complaints, the highest number of reports in any category, which reflects the sheer volume of compromise attempts SOC teams must triage.

Detecting thread hijacking phishing before it causes financial loss requires monitoring a specific set of signals across the email platform's audit logs. SOC analysts should prioritize four detection surfaces: anomalous mailbox rules, unauthorized forwarding configurations, abnormal reply patterns with geolocation mismatches, and activity from dormant accounts. Each signal surfaces a different stage of the cyberattacker's operational lifecycle, and catching any one of them early can interrupt the kill chain before the fraudulent wire transfer clears.

What Mailbox Rule Anomalies Signal a Thread Hijacking Phishing Attempt?

Inbox rules are the cyberattacker's quietest persistence mechanism. After compromising a mailbox, the adversary creates rules that silently redirect or hide replies from legitimate thread participants, often within minutes of initial access. The most reliable indicator is a newly created rule with a name beginning with a period, which hides the rule from the Outlook user interface entirely and suppresses the victim's awareness that anything is wrong.

The rule's target folder is equally diagnostic. Legitimate users rarely route incoming mail to system folders like RSS Feeds, Conversation History, or Junk Email, so when a New-InboxRule or Set-InboxRule operation moves messages matching a specific subject line or sender into one of these folders, the intent is almost certainly malicious.

According to Microsoft's audit log documentation, the New-InboxRule operation is recorded every time a mailbox rule is created via Outlook on the web, and Set-InboxRule captures every modification, so both should be monitored in real time. SOC teams should configure alerting on any rule that combines a hidden name, an obscure destination folder, and a keyword filter matching terms like "invoice," "wire," or "payment."

How Do Forwarding Rules Enable Thread Hijacking Phishing?

External email forwarding is the thread hijacker's primary exfiltration channel. Cyberattackers configure forwarding so every reply in the compromised thread silently lands in a cyberattacker-controlled inbox, enabling real-time interception and response, and three distinct mechanisms require monitoring.

In Microsoft 365 environments, the critical audit operations are New-InboxRule with ForwardTo or RedirectTo parameters pointing to external domains, Set-Mailbox with a populated ForwardingSmtpAddress, and New-TransportRule when the cyberattacker has elevated to administrative privileges. The UpdateInboxRules operation, triggered when rules are modified via the Outlook desktop client, collapses forwarding details into a RuleActions field that must be parsed for external SMTP addresses.

For Google Workspace environments, SOC teams should monitor the Gmail audit log for events where forwarding_enabled is set to true or where forwarding addresses are added to user accounts, both visible through the Admin console's user log events. Any forwarding rule targeting a domain outside the organization's registered domains should generate an immediate high-severity alert.

What Reply Patterns Reveal a Hijacked Email Thread?

Thread hijacking phishing produces reply activity that diverges from the legitimate user's established behavioral baseline. A finance director who always sends emails from Chicago suddenly replying at 2:00 a.m. from an IP address in another country is not a productivity anomaly; it is a compromise indicator.

Analysts should correlate Microsoft Entra ID sign-in logs with Exchange mailbox audit events to detect impossible-travel scenarios, such as a sign-in from an unfamiliar country followed within seconds by email send activity. The MailItemsAccessed operation, which records when mail protocols sync items in a folder, can reveal a cyberattacker browsing the inbox for active threads before inserting themselves into the conversation. Pairing geolocation data from identity logs with email send timestamps provides the strongest behavioral signal that a reply is not coming from the legitimate account owner.

Why Are Dormant Accounts the Preferred Entry Point?

Dormant accounts are the thread hijacker's preferred entry point. An account belonging to a former employee, a long-term leave case, or a rarely used shared mailbox can sit compromised for weeks without anyone noticing unusual activity, which gives the cyberattacker unlimited time to study conversation patterns, identify high-value threads, and insert fraudulent replies with surgical precision.

SOC teams should define a dormant threshold, typically 30, 60, or 90 days of inactivity, and generate alerts for any sign-in, mail read, or rule creation event on an account that has crossed it. The CISA Enhanced Visibility and Hardening Guidance, issued for communications infrastructure defenders but explicitly applicable to broader enterprise environments, recommends validating all accounts and disabling inactive ones to reduce the attack surface. Even a single FolderBind or MailItemsAccessed event on a 90-day-dormant mailbox warrants immediate investigation, and where disabling dormant accounts outright is not operationally feasible, real-time alerting on the first sign of life from a sleeping mailbox is non-negotiable.

Detection signals tell a SOC a mailbox is compromised, yet every employee on the hijacked thread must still recognize the attack. Adaptive Security equips the workforce to act on those same signals.

Take a self-guided tour

Incident Response: What to Do When a Thread Is Hijacked

A thread hijacking phishing compromise demands a response playbook that goes beyond generic phishing incident response, because the cyberattacker is already inside a legitimate mailbox and may have operated undetected for days or weeks. The four-phase framework below covers immediate containment to lock the cyberattacker out, investigation to map the full blast radius, stakeholder notification to preserve trust with external parties, and complete eradication to ensure no persistence mechanisms remain. Every step assumes the cyberattacker may still be active, so speed matters more than perfection.

1. Immediate Containment: Lock the Cyberattacker Out in Minutes

The moment a thread hijacking phishing incident is confirmed, the first actions must sever the cyberattacker's access entirely. Security teams should force a password reset on the compromised account immediately to terminate the active session, then revoke all session tokens and OAuth grants through the identity provider's admin console. In Microsoft 365 this means selecting "Revoke sessions" on the user's account, and in Google Workspace it means using the sign-out function followed by revoking application-specific passwords and third-party OAuth tokens from the connected apps panel.

The next step is to disable the compromised account, because temporary disablement is safer than deletion when the mailbox must be preserved for forensic investigation. Security teams should simultaneously inspect and remove all inbox rules, since cyberattackers routinely create hidden forwarding rules that redirect replies to an archive folder or external address and continue harvesting sensitive thread content even after losing direct access. Cyberattackers have been observed creating mailbox rules with deliberately nondescript names that move emails containing specific keywords to archive folders and mark them as read, effectively blinding the legitimate user to follow-up replies.

Finally, security teams should check for persistence mechanisms the cyberattacker may have planted, such as additional MFA methods registered under the compromised account, newly created app passwords, or supplementary email addresses added to the recovery profile. Cyberattackers who have held access for an extended period often establish multiple paths back in, and every one must be removed before the account is re-enabled.

2. Investigation and Scope Assessment: Map What the Cyberattacker Touched

Thread hijacking phishing is not contained at the mailbox boundary, because a cyberattacker with weeks of access may have moved laterally into SharePoint document libraries, Teams channels, or OneDrive files. The investigation should begin by pulling mailbox audit logs to identify every thread the cyberattacker read, every reply they sent, and the full list of external contacts who received malicious messages. Investigators should then cross-reference these with Entra ID sign-in logs or Google Workspace audit logs to determine the IP addresses, geolocations, and device types used during the compromise window.

Message trace logs are equally critical. A detailed message trace across the compromise period identifies outbound emails sent from the compromised account to external recipients inside hijacked threads, and each recipient represents a potential secondary compromise, whether a vendor, client, or partner who received a malicious attachment or a fraudulent payment instruction from what appeared to be a trusted contact.

The investigation should not be limited to email. Security teams should audit SharePoint access logs and Teams activity for the compromised account, because cyberattackers who compromise a mailbox often discover linked services accessible with the same credentials. If the account had access to sensitive document repositories or participated in deal-room conversations, those assets must be scoped into the incident immediately.

3. Notification and Stakeholder Communication: Move Fast Without Undermining Trust

Internal notification must happen within the first hour, informing the IT security lead, the affected user's manager, legal counsel, and the executive team if the compromised account belonged to a senior leader. Compliance obligations may require notifying the data protection officer or regulatory authorities depending on the nature of the data exposed in hijacked threads. Where a hijacked thread exposed personal data, the incident may also trigger statutory breach notification duties, so legal counsel should assess reporting obligations early rather than after containment concludes.

External notification is the more delicate challenge. Every external party who received a malicious reply from the compromised account must be contacted, but the message must preserve their confidence in future email communications with the organization.

The right approach is a side-channel verification method that operates outside the compromised email platform entirely, whether a phone call, a message through a separate collaboration tool, or direct contact from the relationship manager. The key principle is never to rely on the same compromised channel to deliver the warning about that channel's compromise.

When communicating externally, the organization should state clearly that a specific email thread was compromised, confirm which messages were unauthorized, and provide a point of contact for questions. Vague language that creates unnecessary alarm should be avoided, because the goal is transparency paired with demonstrable control: the organization caught the intrusion, contained it, and is informing affected parties directly.

4. Eradication and Recovery: Remove Every Trace of the Cyberattacker

Thread hijacking eradication requires removing nested rules and revoking all sessions and MFA tokens

The eradication checklist begins by confirming all mailbox rules have been fully removed, and the account should be rechecked even if this step was performed during containment, because cyberattackers sometimes nest hidden rules or create secondary rules triggered by the deletion of the primary rule. Security teams should revoke every session token a second time after the password reset and require a full MFA re-enrollment rather than simply re-enabling the previous configuration, since a cyberattacker who registered their own MFA method during the compromise window would otherwise retain a path back in.

The critical and often overlooked step is searching for and removing malicious emails from all recipient inboxes. In Microsoft 365, Exchange Online message trace combined with the Search-Mailbox or New-ComplianceSearch cmdlets with a purge action can locate and delete the cyberattacker's replies across every internal and external recipient mailbox within the tenant. In Google Workspace, Google Vault can search for and hold messages while the security team evaluates which must be purged.

This step prevents a recipient from acting on a fraudulent request days or weeks after the incident is closed.

Finally, side-channel verification should become a standing protocol for any sensitive request delivered through email, regardless of how legitimate the thread appears. The organizational lesson from a thread hijacking phishing incident is that trust in the channel itself must be verified through an independent path every time a high-value action is requested, and building that verification reflex across the organization is where realistic multi-channel phishing simulation turns an incident response lesson into durable behavioral change.

One fraudulent reply left in a recipient inbox can trigger a wire transfer weeks after an incident closes. Adaptive Security builds the verification reflex that stops recipients from acting on hijacked requests.

Book a demo

How Thread Hijacking Phishing Is Evolving: AI, Collaboration Platforms, and Future Trends

Thread hijacking phishing is becoming harder to detect and accessible to a broader range of cyberattackers because three trends are converging: large language models that generate replies indistinguishable from legitimate correspondence, the migration of business conversation to collaboration tools with weaker security postures than email, and an expanding universe of SaaS-connected identities that multiplies the number of hijackable threads. As reported in a peer-reviewed 2026 USENIX Security study by Czybik and colleagues involving 7,700 participants, LLM-based spear phishing almost triples the click rate compared to generic phishing strategies, regardless of whether the generic emails are written by humans. The historical tell of awkward language no longer exists, and the trust mechanism this technique exploits grows stronger while the attack surface widens.

How Is AI-Generated Content Changing Thread Hijacking Phishing Campaigns?

The single biggest factor altering the thread hijacking phishing landscape is the large language model. Once a cyberattacker compromises an inbox, they feed the existing thread history into an LLM and instruct it to generate a reply that mirrors the legitimate account holder's cadence, vocabulary, punctuation habits, and formatting signatures.

This eliminates what was historically the most reliable detection signal: writing that feels slightly off. Employees conditioned to flag poor grammar now face replies indistinguishable from legitimate correspondence, and the generated replies chain naturally to the thread's subject matter, referencing specific invoice numbers, project names, and meeting dates pulled directly from the compromised inbox. That realism is something standard cybersecurity awareness training built around spelling errors never prepared employees to question.

According to Sumsub's 2025–2026 Identity Fraud Report, sophisticated fraud, meaning coordinated attacks that combine several advanced techniques in a single verification attempt, rose 180% globally, while deepfake attempts climbed 94% in the United Kingdom and 96% in France. That trajectory signals how quickly AI-assisted deception is scaling across every channel employees use.

The operational impact is that thread hijacking phishing campaigns once requiring a patient, skilled operator now scale through automation. One compromised account feeds an LLM pipeline that generates dozens of contextually tailored replies across multiple hijacked threads simultaneously, a throughput impossible with manual social engineering.

How Is Thread Hijacking Phishing Moving Beyond Email?

Thread hijacking phishing began in email, but email is no longer where most business conversation happens. The technique is migrating aggressively to collaboration platforms where security detection trails the mature defenses built around email over two decades.

Microsoft Teams has become a primary target. Cyberattackers use compromised Entra ID credentials to access Teams environments, then insert themselves into active chats by impersonating IT support, finance personnel, or external partners, often initiating voice or video calls to build credibility before delivering a malicious link. According to the Cloud Security Alliance's State of SaaS Security Report 2025, 63% of organizations report external data oversharing and 86% rank SaaS security as a high organizational priority, yet detection coverage across collaboration platforms remains fragmented and inconsistent.

Slack presents a parallel vector, where cyberattackers exploit stolen session tokens to join workspaces and drop messages into existing threads, distributing links to credential-harvesting portals disguised as shared documents. Because Slack threads register as internal and safe, the click-through rate on these links punishes organizations that treat collaboration-platform security as an afterthought. SharePoint and OneDrive file-sharing links embedded in hijacked threads complete the pattern, because the link originates from a trusted internal source, lands inside a real conversation, and leads to a phishing page, bypassing skepticism on three fronts simultaneously.

Why Is the Thread Hijacking Phishing Attack Surface Expanding?

The number of accounts a cyberattacker can compromise, and therefore the number of trusted threads available to hijack, is multiplying. The average organization now operates hundreds of SaaS applications, each representing an identity perimeter that demands defense.

Remote and hybrid work policies mean employees authenticate from personal devices and home networks outside corporate security stacks, and BYOD programs introduce endpoints that security teams cannot fully monitor. Contractor and external collaborator accounts, often provisioned with loose access controls and forgotten after engagements end, create persistent, unmonitored entry points, and when any one of these accounts is compromised, the cyberattacker inherits every trusted thread that account participates in.

The expanding number of hijackable accounts across SaaS tools, remote devices, and contractor logins makes thread hijacking phishing a growing rather than shrinking threat vector. Every new SaaS tool adopted, every external partner login granted, and every personal device connecting to corporate systems expands the pool of hijackable conversations. The organizations best positioned to defend against this evolution are those running phishing simulations that replicate the multi-channel reality of modern thread hijacking phishing, with scenario-based drills across the collaboration platforms employees use every day rather than email tests alone.

As business conversation migrates to Teams and Slack, cyberattackers follow it into channels where detection barely exists. Adaptive Security runs multi-channel phishing simulations that prepare employees for hijacked threads wherever they appear.

Explore the platform

How Cybersecurity Awareness Training Reduces Thread Hijacking Phishing Risk

Thread hijacking phishing succeeds because it weaponizes trust that already exists between real contacts inside authenticated email threads. According to the National Cybersecurity Alliance's 2025–2026 Oh Behave! The Annual Cybersecurity Attitudes and Behaviors Report, 52% of employed participants reported they have not received any training on the security or privacy risks of AI tools, and this technique is engineered specifically to evade the technical controls organizations rely on most. No email security gateway flags a message from a legitimate account replying to a real conversation thread, which is precisely why cybersecurity awareness training that teaches employees to pause, inspect, and verify is the countermeasure that closes the gap.

Why Technical Controls Alone Cannot Stop Thread Hijacking Phishing

Thread hijacking phishing exploits human trust rather than technical vulnerabilities. When a cyberattacker gains access to a compromised email account and replies to an existing conversation, the message arrives through fully authenticated channels: SPF, DKIM, and DMARC validate the sending domain, the sender is a real contact the recipient has corresponded with before, and the thread history is genuine. Multi-factor authentication on the recipient's account does nothing to stop a message that was sent legitimately from a compromised counterparty.

Secure email gateways face the same blind spot. These tools scan for malicious links, attachments, and sender reputation signals, and a hijacked thread contains none of those markers. The email body references real projects, uses the correct names, and mirrors the tone of previous messages, because the cyberattacker has been reading the thread history for days or weeks before inserting themselves.

Cybersecurity awareness training fills the gap that authentication protocols and filtering technologies were never designed to address: the human decision to act on a request that looks right but is not.

Training Employees to Recognize Hijacked Thread Red Flags

Effective cybersecurity awareness training teaches employees to spot the behavioral signals that distinguish a hijacked thread from a genuine continuation of a conversation, and these indicators are trainable and repeatable. A payment instruction that changes bank details at the last minute, without prior discussion, is the most common tell, and subtle shifts in writing style, shorter sentences than usual, or an uncharacteristic lack of pleasantries can all signal that someone else is typing from the compromised account.

Urgency that bypasses normal approval workflows is another red flag, because legitimate business partners rarely demand same-day wire transfers while insisting that standard verification steps be skipped. Replies arriving at unusual times, outside business hours in the sender's time zone, warrant additional scrutiny, and file-sharing links that point to unfamiliar domains instead of the expected SharePoint, Google Drive, or Dropbox portal should trigger immediate suspicion. A cybersecurity awareness training program that simulates these exact scenarios in a controlled environment transforms abstract warning signs into practiced recognition patterns employees can recall under pressure.

Building Verification Workflows Through Behavioral Conditioning

The most effective cybersecurity awareness training programs do not simply inform employees about thread hijacking phishing; they condition a verification reflex. When a payment change request or sensitive data transfer arrives through any channel, the trained response is to confirm it through a second, out-of-band method before acting, whether that means calling a known number, walking to a colleague's desk, or using a separate approved messaging platform to verify the instruction independently.

Repeated phishing simulations and reinforcement turn this verification step from an optional courtesy into an automatic behavioral reflex. Employees who have practiced stopping a simulated hijacked payment request several times will pause automatically when a real one arrives, regardless of how convincing the hijacked message appears. That reflexive pause is what stops a thread hijacking phishing attack cold, and technical controls cannot create it; only cybersecurity awareness training can.

A perfectly written hijacked reply gives an employee no grammatical tell, only a request that breaks routine. Adaptive Security conditions the verification reflex that stops those requests however convincing they look.

Take a self-guided tour

See How Adaptive Security Prepares Teams to Stop Thread Hijacking Phishing

Adaptive Security detects thread hijacking through intent analysis and behavioral signals without mail server changes

Stopping thread hijacking phishing requires closing the gap that SPF, DKIM, and DMARC leave open: a malicious reply sent from a genuinely trusted mailbox. Adaptive Security closes that gap by pairing AI-powered Cloud Email Security with cybersecurity awareness training in one platform, so behavioral signals, intent analysis, and LLM reasoning catch the hijacked replies native filters miss, and every detected attack becomes a targeted lesson for the employee it reached. Because the detection layer integrates through API without MX record changes, organizations add advanced email protection without ripping out the email provider they already run.

The result is a workforce that recognizes a hijacked thread before acting on it and a detection layer that removes the cyber threat before it spreads. Adaptive Security drills the out-of-band verification reflex through realistic phishing simulations that replicate real thread hijacking and multi-persona scenarios, feeding every result into individual risk scores that show security leaders exactly where compromise is most likely. AI Governance extends that visibility to the shadow AI accounts and unmanaged browser sessions that hand cyberattackers the credentials thread hijacking phishing depends on in the first place, while Compliance Training keeps regulated teams aligned with the policies that govern payment and data-handling workflows.

Rather than treating email security, cybersecurity awareness training, and human risk scoring as separate purchases, Adaptive Security unifies them so a cyber threat that reaches one inbox becomes intelligence that protects the whole organization. That is how a single hijacked thread turns from a six-figure incident into a detected, remediated, and taught moment across the workforce.

Trusted conversations are exactly what no email filter was built to question, which is why thread hijacking phishing walks past them. Adaptive Security unites AI email detection with behavioral training to catch it.

Book a demo

Frequently Asked Questions About Thread Hijacking Phishing

Can Multi-Factor Authentication Alone Prevent Thread Hijacking Phishing Attacks?

No, multi-factor authentication alone cannot prevent thread hijacking phishing attacks. Adversary-in-the-middle (AiTM) proxy phishing kits capture credentials and active session tokens simultaneously, letting cyberattackers authenticate without triggering an MFA prompt. Once inside the mailbox, they bypass MFA entirely and begin the reconnaissance that precedes thread hijacking. Phishing-resistant MFA methods like FIDO2 hardware tokens close this gap by binding authentication to the legitimate domain, but they cannot stop a cyberattacker who gained access through infostealer malware, credential stuffing, or OAuth token abuse. MFA is a necessary layer, but defending against thread hijacking phishing also requires mailbox monitoring, forwarding-rule detection, and employee training on out-of-band verification workflows.

What Share of BEC Attacks Involve Thread Hijacking or Fake Threads?

Thread hijacking and fabricated threads have become the leading business email compromise (BEC) technique across the industry, surpassing traditional email-based approaches such as domain spoofing and executive impersonation from external addresses. The growth reflects the effectiveness of thread hijacking phishing: cyberattackers exploit the built-in trust of an existing email conversation, which dramatically increases victim compliance compared to cold-contact phishing. As proxy-based phishing kits and infostealer malware make initial account compromise easier, security researchers expect this technique's share of BEC attacks to keep rising, which is why detection and training must both target the conversation layer rather than the message alone.

How Fast Can a Thread Hijacking Phishing Attack Execute From Compromise to Delivery?

A thread hijacking phishing attack can move from initial compromise to malicious email delivery in a matter of hours, and in documented cases the credential-and-token capture stage completes in under a minute once a victim clicks. In the January 2026 case analyzed by ANY.RUN, proxy infrastructure captured a target's Microsoft credentials and session token almost immediately after the click, granting authenticated access before any alert fired. Automation compresses the timeline further, because once a cyberattacker accesses a mailbox, they can programmatically scan for high-value threads involving financial discussions or executive communications, then craft and send contextually relevant replies before the account holder detects the compromise. This velocity is why mailbox monitoring and anomaly detection must operate in real time rather than through manual review cycles.

What Are the Earliest Warning Signs That an Email Thread Has Been Hijacked?

The earliest warning signs of a hijacked email thread include unexpected changes to payment instructions or bank account details, subtle shifts in the sender's tone or writing style, and urgent requests that bypass established approval workflows. Additional red flags include replies that arrive at unusual hours inconsistent with the sender's normal communication patterns, file-sharing links that redirect to unfamiliar domains rather than expected portals like SharePoint or Google Drive, and requests to re-enter credentials to view a supposedly shared document. Any email within an existing thread that creates pressure, deviates from standard procedures, or introduces a new payment destination warrants out-of-band verification through a known phone number before any action is taken.

Do SPF, DKIM, and DMARC Stop Thread Hijacking Phishing Attacks?

No, SPF, DKIM, and DMARC do not stop thread hijacking phishing attacks. These email authentication protocols verify that the sending server is authorized to send mail on behalf of the domain, confirming the messenger rather than the message. In a thread hijacking phishing scenario, the cyberattacker sends the malicious reply from a genuinely compromised, authenticated mailbox belonging to a legitimate contact, so because the mailbox is real and properly configured, all three protocols pass. The authentication framework has no mechanism to detect that a cyberattacker rather than the account owner now controls the mailbox. Closing this gap requires training employees to verify any unexpected payment or sensitive data request through a separate, out-of-band channel before acting.

Fraud hides inside a trusted conversation where filters and authentication cannot see it. Adaptive Security unites AI email detection with behavioral training to catch thread hijacking phishing at the tooling and human layers.

Take a self-guided tour

Adaptive Team

Adaptive Team

As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.

Get started with Adaptive Security

Get started

Human security for the AI era.