← Glossary

Thread Hijacking

Thread hijacking injects malicious replies into real, ongoing email conversations, borrowing their trust and context to defeat normal suspicion.

Updated

Thread hijacking (conversation hijacking) is an attack where a criminal inserts themselves into a genuine, ongoing email thread, usually via a compromised account, and replies with malicious content that inherits the thread''s established trust and context.

Key facts

  • It typically follows account takeover: the attacker replies from or spoofs a real participant inside a real conversation.
  • Because the thread, history and participants are genuine, recipients rarely suspect the injected reply.
  • It is a favored delivery method for BEC payment fraud and malware, precisely because the surrounding context does the persuasion.

How it works

An attacker compromises a mailbox, reads recent threads to understand who is discussing what, and picks a moment to reply, sometimes with new bank details, sometimes with a malicious link or attachment reframed as the deliverable everyone was waiting for. The quoted history sells it: the recipient sees their own earlier messages, the familiar participants, the expected topic. The reply looks like the next step in a conversation they trust.

Why it beats suspicion and filters

Traditional filters look for known-bad content and unusual senders; a hijacked reply comes from a real sender inside a real thread with passing authentication. There is nothing "wrong" at the surface layer. Only the behavior is wrong: an out-of-pattern change of bank details, an unusual link inside a thread that has never contained links, a document from a colleague who never shares that file type. This is the ground where business email compromise and vendor email compromise both thrive.

How to defend

Verify payment and link or attachment changes even within known threads, out of band and through a channel you control. Deploy phishing-resistant MFA to prevent the account takeover that makes hijacking possible in the first place. And add behavioral detection that recognizes out-of-pattern replies inside otherwise normal threads, the deviation is the signal.

How Sentaro helps

Sentaro''s Behavioral Defense models each organization''s real conversation graph and flags replies that break a thread''s established pattern: new payment instructions inside a routine relationship, first-ever attachments, tone shifts mid-thread. It also flags the account-takeover behavior that precedes hijacking, so the attack can be interrupted at both ends.

Questions we get asked.

What is thread hijacking in simple terms?

An attacker joins a real ongoing email conversation, usually because they have compromised one participant''s mailbox, and sends a reply that abuses the thread''s built-up trust to redirect payment, steal data or deliver malware.

How do attackers get into a real email thread?

Most often by account takeover (phishing, credential theft or AiTM), less often by careful spoofing where authentication and lookalike domains hide the substitution.

Why is thread hijacking so effective?

It inherits trust: the participants, history and topic are genuine, so the malicious reply reads as the next step in a conversation the recipient already believes in.

How do we detect thread hijacking?

Verify in-thread payment or link or attachment changes out of band, and use behavioral detection that flags replies breaking a thread''s established pattern rather than relying only on sender or content signals.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.