Conversation-Hijacking Attacks Make It Almost Impossible to Avoid Becoming a Victim

Stu Sjouwerman | Jan 23, 2020

Closeup side profile portrait upset sad skeptical unhappy serious woman talking texting on phone displeased with conversation isolated city background. Negative human emotion face expression feelingAttackers target organizations to insert themselves into group email conversations as a way of ensuring the likelihood that one or more recipients are happy to unwittingly infect themselves.

So, you’re on a group email thread that’s been going back and forth with each recipient participating with commentary. At some point, one of the recipients naturally and contextually offers up a link or an attachment that will assist with the conversation’s topic. Would you click it?

Cybercriminals using this new technique are betting you will.

According to new research from security vendor Barracuda, attackers are taking a page from domain impersonation and deepfake voice attacks, and are now realizing the value of leveraging a compromised credential by simply looking through their email, finding a current email thread with several people on it, and inserting malware with a contextually-accurate reason. Remember, according to Microsoft, attackers spend about 146 days on your network before being detected; that’s enough time to find an opportunity to infect users.

It’s conniving and so evil you have to at least appreciate its brilliance.

It’s also a great indicator that users need to be taught to never trust any email – no matter who sends it. Users that participate in Security Awareness Training realize that even emails which appear to be from a trusted source still need to undergo some level of scrutiny. And in the case of conversation-hijacking attacks, the scrutiny is definitely necessary.

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.