Family Sentinel
Scam Watch · September 28, 2026 · 5 min read

The scammer who replies inside your own email thread

You have been emailing your landscaping vendor or payroll processor for weeks about a real invoice. Then a reply arrives — same address, same thread, same amount — asking you to send payment to a "new" account. Every technical check passes, because the message really did come from that account.

This is called conversation hijacking, or thread hijacking: business email compromise where nobody is being spoofed. The attacker is inside a mailbox belonging to a vendor, contractor, or colleague your organization already trusts, waiting in real conversations for the moment a payment or password comes up.

Why this one is different from the usual phishing email

Most phishing training says to check the sender's address, watch for a lookalike domain, and be wary of a first-time contact. Thread hijacking defeats all three at once, because the account really is the vendor's and the conversation really did happen. Attackers "insert themselves into existing email threads, so their actions appear to be normal business communications," Proofpoint notes — and because the message travels through the vendor's own, legitimately authenticated mail server, it passes SPF, DKIM, and DMARC like every other email from that account.

The scale behind this is real money. Business email compromise accounted for more than $3 billion in reported losses in 2025 across nearly 25,000 complaints, according to the FBI's Internet Crime Complaint Center (IC3) — an average loss well over $120,000 per incident. Barracuda Networks reports conversation hijacking specifically has risen 70 percent since 2022, despite taking more effort per victim than a generic phishing blast.

What generative AI is changing

The genuinely new part is speed and fluency. Proofpoint notes "generative AI makes it fast and easy for attackers to create convincing messages that match tone, language, and context" — which matters once an attacker is already inside a real thread and only has to keep a conversation going, not invent one from nothing. Microsoft has separately documented a 2026 campaign of over a million emails impersonating executives that carried structural fingerprints — templated formatting and other tells — consistent with AI-drafted text. Neither finding proves every hijacked thread now gets an AI-written reply; together they show real account access and AI tools able to produce a fast, in-character response are both documented and increasingly paired. Treat any mid-thread request to change how or where money moves as suspicious on its own, however well it reads.

The one rule that defeats this attack: never verify a payment or account change using contact information from the request itself — not the phone number in the signature, not a "reply to confirm" link. Call the person back on a number you already had. The FBI's guidance on business email compromise is explicit: use "previously known numbers, not the numbers provided in the e-mail request," and route any vendor payment change through a second person's sign-off before it takes effect.

What to do — this week

  1. Before any payment detail changes, call back on a number you already had. Look it up in your own records or a prior invoice — never a number, link, or "updated" address supplied in the thread asking for the change.
  2. Require two-person approval for any change to where money goes. One person should never receive a change request and also approve the updated payment alone — the specific control the FBI names for vendor payment redirection.
  3. Check the actual sending address and reply-to field, not just the display name and thread history. A hijacked account usually looks identical at a glance — the giveaway, if there is one, is a reply-to address that quietly differs from the visible sender, or a domain one character off from the one you have used for months.
  4. Slow down anything marked urgent, confidential, or "don't call, just reply." A legitimate vendor or colleague will always accept a callback. A request that discourages one is telling you something.
  5. Notice behavior that does not match the person, even in a real thread. Odd hours, a sudden shift in tone, or a request that skips the normal process are worth a second look.
  6. If a payment already went out, treat it as an emergency, not an embarrassment. Call your bank immediately about a recall or hold, notify the vendor through a number you already had, and file a report at ic3.gov. Speed matters most once money has moved.

Related reading

A hijacked account still leaves a pattern behind — that is what we watch for.

You cannot eyeball your way to certainty on a message from a genuine account inside a genuine thread. Family Sentinel's detection engine learns how the vendors and colleagues you regularly correspond with normally send, without keeping message content, and adds scrutiny when a known account starts behaving unlike itself. Read-only by design, with a real Security Architect behind every serious flag.

Book a free 20-minute checkup →

Want the next threat before it reaches you?

Scam Watch goes out regularly — the newest scams and how to spot them, in plain English. Free.

Written by the Family Sentinel security desk — a working Security Architect and the team who watch organizational inboxes for a living. Sources: FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report (business email compromise losses and complaint counts); FBI IC3 Public Service Announcement, "Business E-mail Compromise / E-mail Account Compromise" (verification and out-of-band guidance); Proofpoint, "How to Prevent Business Email Compromise (BEC) Attacks"; Microsoft Security Blog, "Protecting organizations from AI-assisted executive impersonation and invoice fraud" (September 2026); Barracuda Networks conversation-hijacking research. Have a suspicious vendor or invoice email you would like a second opinion on? Forward it to security@familysentinel.org or call (940) 281-6672 — no charge, no strings.