Skip to content

Thread Hijacking

Thread hijacking inserts a malicious request into an existing conversation or reuses genuine conversation history to make a new interaction appear legitimate. The attacker borrows the established context, participants, subject matter, and timing of the thread.

Compromised mailboxes are a common source of access, although stolen email history, exposed documents, forwarded messages, or copied conversation content can provide similar context. Genuine details may therefore remain intact while the direction of the conversation changes.

Conversation history can be treated as evidence that a new request belongs to the established workflow. A small change in payment details, destination, attachment, account, or requested action may receive less scrutiny because the surrounding thread is familiar.

Thread hijacking commonly appears in supplier, customer, project, legal, recruitment, finance, or other ongoing business conversations. A familiar thread may introduce changed payment instructions, a new document location, an urgent approval, or movement to another account or channel.

The subject line, previous replies, known participants, and business context may remain genuine while a single operational detail changes inside them: a payment instruction, a document location, an approver, or the account the reply should go to. The familiar surroundings carry that single change past scrutiny.

Thread hijacking indicators commonly appear when a familiar conversation changes direction. Authentic history and genuine participants can remain present while the new request departs from the established workflow.

IndicatorWhat to look for
Sudden request shiftA routine thread introduces payment changes, access requests, document release, credential prompts, new attachments, or urgent approvals.
Changed communication pathThe sender seeks movement to a new email address, personal account, phone number, messaging application, file-sharing service, or external portal.
Sender detail mismatchThe sender address, reply-to address, display name, signature, domain, or linked destination differs from the expected contact.
Unexpected link or attachmentA previously routine conversation introduces an unanticipated file, shared document, login page, invoice, form, or download.
Real context, risky actionGenuine conversation history is paired with an action that could expose money, access, credentials, records, or sensitive information.
Tone or timing changeWording, urgency, greeting, formatting, timing, or decision style differs from earlier messages in the thread.
Process bypassThe existing thread is used to justify skipping approval, supplier, finance, legal, procurement, HR, or access processes.
Verification resistanceCallback, independent confirmation, or established verification is discouraged, or confirmation is redirected to contact details supplied in the message.
Mailbox compromise indicatorsUnexpected forwarding rules, unusual replies, anomalous sign-in activity, changed mailbox behaviour, or messages sent from a genuine account at unusual times are present.
Third-party confusionParticipants in the conversation are unaware of the request, disagree about instructions, or cannot confirm the new direction through known contact details.