Blog/Phishing

Reply-Chain Phishing Inside Real Conversations

Attackers who compromise a mailbox reply inside real email threads, adding a malicious link or payment request. How thread hijacking works and how to spot a reply that does not fit.

CyberWatch AI1 October 2026 · 2 min read
An overhead view of a person typing on a laptop at a wooden desk

Reply-chain phishing is one of the hardest types to spot. The message arrives inside a real conversation you have been having, with real history below it, from someone you know. The attacker has either broken into that person's mailbox or copied the thread, and now adds a malicious link, attachment or payment instruction.

How it works

  1. An attacker compromises a mailbox, often a supplier's or colleague's.
  2. They read ongoing conversations and pick one with a natural next step.
  3. They reply in the thread: "Here are the updated files", "Please use our new account for this payment".
  4. They may set rules to hide replies from the real owner. See hidden forwarding rules.

Warning signs

  • A reply that does not quite fit: a different tone, generic wording, or unexpected urgency.
  • New links or attachments nobody asked for.
  • Changed bank details or a new payment request. See vendor email compromise.
  • A sender address that differs slightly from earlier messages in the thread.
  • Old threads suddenly revived after months.

A familiar thread is not proof. Verify any payment change or unexpected file by phone, using a number you already had.

What to do

  • Do not click or pay; contact the sender another way.
  • Report it to your IT team or email provider.
  • Tell the sender their mailbox may be compromised.

Got an odd reply in a real thread? Paste it into CyberWatch AI Scan for a free check.

For more, see how to recognise phishing in our complete guide.

Frequently asked questions

How can an attacker reply in a real thread?

By compromising the mailbox of someone in the conversation, or by copying the thread and sending from a lookalike address.

What gives it away?

A reply that changes tone, adds an unexpected link, attachment or bank change, or comes from a subtly different address.

What should I do if I suspect it?

Contact the sender through another channel, report it, and let them know their account may be compromised.

Sources

  1. Suspicious email actions, UK National Cyber Security Centre
  2. Small business guide: cyber security, UK National Cyber Security Centre
  3. Cybersecurity for Small Business, US Federal Trade Commission
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.