Thread hijacking (conversation hijacking) is an attack where a criminal inserts themselves into a genuine, ongoing email thread, usually via a compromised account, and replies with malicious content that inherits the thread''s established trust and context.
Key facts
- It typically follows account takeover: the attacker replies from or spoofs a real participant inside a real conversation.
- Because the thread, history and participants are genuine, recipients rarely suspect the injected reply.
- It is a favored delivery method for BEC payment fraud and malware, precisely because the surrounding context does the persuasion.
How it works
An attacker compromises a mailbox, reads recent threads to understand who is discussing what, and picks a moment to reply, sometimes with new bank details, sometimes with a malicious link or attachment reframed as the deliverable everyone was waiting for. The quoted history sells it: the recipient sees their own earlier messages, the familiar participants, the expected topic. The reply looks like the next step in a conversation they trust.
Why it beats suspicion and filters
Traditional filters look for known-bad content and unusual senders; a hijacked reply comes from a real sender inside a real thread with passing authentication. There is nothing "wrong" at the surface layer. Only the behavior is wrong: an out-of-pattern change of bank details, an unusual link inside a thread that has never contained links, a document from a colleague who never shares that file type. This is the ground where business email compromise and vendor email compromise both thrive.
How to defend
Verify payment and link or attachment changes even within known threads, out of band and through a channel you control. Deploy phishing-resistant MFA to prevent the account takeover that makes hijacking possible in the first place. And add behavioral detection that recognizes out-of-pattern replies inside otherwise normal threads, the deviation is the signal.
How Sentaro helps
Sentaro''s Behavioral Defense models each organization''s real conversation graph and flags replies that break a thread''s established pattern: new payment instructions inside a routine relationship, first-ever attachments, tone shifts mid-thread. It also flags the account-takeover behavior that precedes hijacking, so the attack can be interrupted at both ends.