High riskEmail

Email Thread Hijacking Scam

This scam happens when attackers who have compromised a contact's mailbox reply within a real, existing email thread, using the genuine history to make a malicious link or attachment look trustworthy because it continues a conversation you recognise.

Quick verdict

Risk level
High risk
Scam type
Reply-chain phishing scam
Main red flag
A reply in a familiar thread that suddenly adds an unexpected link or attachment.
What to do first
Do not open the link or attachment. Verify with the sender through a separate, known channel before acting.

How this scam works

This scam happens when attackers who have compromised a contact's mailbox reply within a real, existing email thread, using the genuine history to make a malicious link or attachment look trustworthy because it continues a conversation you recognise.

Email scams, or phishing, remain one of the most common ways criminals steal logins, payment details, and money. A convincing message imitates a brand or contact and steers you toward a fake login page, a malicious attachment, or a fraudulent payment.

In short, the giveaway is usually simple: A reply in a familiar thread that suddenly adds an unexpected link or attachment. Do not open the link or attachment. Verify with the sender through a separate, known channel before acting.

Scammers rotate tactics constantly, the same operation may also run the Malware Attachment Scam and the Fake Invoice Email Scam. See the full Email Scams guides hub, or test a suspicious message with the scam checker.

How to spot this scam

  • An unexpected link or attachment appearing in a thread that was previously normal
  • A reply that feels slightly off in tone, timing or wording compared with the real contact
  • A request to log in to view a file, or to enable content in an attachment
  • A sender address that looks almost right but has small differences on close inspection
  • Pressure to open or act quickly within an otherwise familiar conversation

What the message looks like

Example pattern, not a real report
Example pattern: 'Re: Project update, Thanks for the notes. Please see the revised document attached and let me know your thoughts: [unfamiliar link]'

This is a fictional, anonymised example used to illustrate the pattern. It is not a verified real message, and any names are used only to show how the scam typically reads.

What gives it away: A reply in a familiar thread that suddenly adds an unexpected link or attachment.

The scale of it

Most reported
phishing was the most common type of cybercrime complaint reported to the FBI in 2023
$12.5B
total reported internet-crime losses in the US in 2023

How to protect yourself

  • Do not open the link or attachment without verifying it first
  • Confirm with the contact through a separate, known channel such as a phone call
  • Check the sender's full email address carefully for subtle changes
  • Report the message to your IT or security team and avoid forwarding it

Already responded? Do this now

  • Do not enter any credentials or enable content if prompted
  • Disconnect the device from the network if you ran an attachment, and run a security scan
  • Change passwords for any account you may have exposed, from a trusted device
  • Report it to your IT or security team so they can check for further compromise

Mistakes to avoid

  • Do not assume a reply is safe just because the thread is real
  • Do not enter your login on a page reached through the email
  • Do not enable macros or 'protected content' in an unexpected attachment

Related scams to know

Common questions

How can the scammer reply inside a real conversation?
They usually gain access to a contact's mailbox, then reply within an existing thread. Because the history is genuine, the message looks trustworthy, which is what makes this pattern effective.
If the email comes from someone I know, is it safe?
Not always. A trusted contact's account can be compromised, so an unexpected link or attachment in a familiar thread is still worth verifying through a separate channel first.
How do I verify without tipping off the attacker?
Reach the person through a different, known channel such as a phone call or a fresh message, rather than replying in the same thread, which the attacker may be monitoring.
I opened the attachment. What should I do?
Disconnect from the network, run a security scan, change exposed passwords from a trusted device, and tell your IT or security team so they can check for any further compromise.

Last reviewed June 2026 · Written & reviewed by the

Disclaimer: This page provides educational information only to help you recognise common scam patterns. It is not legal, financial, cybersecurity, or law enforcement advice, and it does not confirm whether any specific message, company, or person is genuine or fraudulent. When in doubt, contact the official organisation directly and report concerns to your local authorities.