Email Conversation Takeover: How to Detect Thread Hijacking After Account Compromise
ID: e4900d14-e81d-57a5-8756-2c0b610fab82
STIX ID: report--e4900d14-e81d-57a5-8756-2c0b610fab82
Feed Name: Security Boulevard
Email conversation takeover is a post-compromise attack in which an adversary controlling a legitimate mailbox hijacks an existing thread to insert fraudulent replies that pass SPF/DKIM/DMARC and exploit recipient trust; this guide explains the attack mechanics, why gateway/native filters miss it, the account/thread/content signals that reveal a hijack, detection methods for Microsoft 365 and Google Workspace, and recommended rapid containment and organization-wide remediation to prevent business email compromise losses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
