Walls & Ceilings logo
search
cart
facebook twitter linkedin youtube youtube Spotify Podcasts Apple Podcasts Spotify Podcasts Apple Podcasts
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Walls & Ceilings logo
  • NEWS
  • TOPICS
    • Drywall
    • Stucco/EIFS
    • Ceilings
    • Steel Framing
    • Fireproofing
    • Interior Plaster
    • Building Envelope
    • Insulation
    • Technology
    • Interior
    • Exterior
    • Women In Construction
  • COLUMNS
    • Up Front
    • All Things Gypsum
    • Art & Craft of Plastering
    • Stucco Stop
    • Steel Deal
    • Industry Voices
  • PRODUCTS
    • Buzz Guide
  • EVENTS
    • Industry Events
    • Webinars
    • BUILD Expo
  • MEDIA
    • Videos
    • Podcasts
    • Photo Galleries
    • BUILD26 Videos
    • Take our Quiz!
    • Infographics
  • EXCLUSIVE
    • Newsletters
    • Top 50 Contractors
    • Contractor of the Year
    • State of the Industry
    • W&C Store
    • Market Research
    • CEUs
    • Sponsor Insights
    • Custom Content & Marketing Services
  • DIRECTORY
  • EMAGAZINE
    • eMagazine
    • Advertise
    • Archive Issues
  • SIGN UP!
Building EnvelopeExteriorStucco/EIFS

Watch Out for Reply-Chain Phishing Attacks

NOT PROTECTING YOUR INFORMATION CAN LEAVE THE DOOR OPEN FOR HACKERS.

By Tony Cesar
WC1022-FEAT-Rubicon-p1FT-Phishing-GettyImages-1335959802.jpg
October 19, 2022

Phishing. It seems you can’t read an article on cybersecurity without it coming up. That’s because phishing is still the number one delivery vehicle for cyberattacks.

A cybercriminal may want to steal employee login credentials. Or wish to launch a ransomware attack for a payout. Or possibly plant spyware to steal sensitive info. Sending a phishing email can do them all.

Phishing not only continues to work, but it’s also increasing in volume due to the move to remote teams. Many employees are now working from home. They don't have the same network protections they had when working at the office.

Why has phishing continued to work so well after all these years? Aren’t people finally learning what phishing looks like?

It's true that people are generally more aware of phishing emails and how to spot them than a decade ago. But it's also true that these emails are becoming harder to spot as scammers evolve their tactics.

One of the newest tactics is particularly hard to detect. It is the reply-chain phishing attack.


What is a reply-chain phishing attack?

Just about everyone is familiar with reply chains in email. An email is copied to one or more people, one replies, and that reply sits at the bottom of the new message. Then another person chimes in on the conversation, replying to the same email.

Soon, you have a chain of email replies on a particular topic. It lists each reply one under the other so everyone can follow the conversation.

You don’t expect a phishing email tucked inside that ongoing email conversation. Most people are expecting phishing to come in as a new message, not a message included in an ongoing reply chain.

The reply-chain phishing attack is particularly insidious because it does exactly that. It inserts a convincing phishing email in the ongoing thread of an email reply chain.


How does a hacker gain access to the reply chain?

How does a hacker gain access to the reply chain conversation? By hacking the email account of one of those people copied on the email chain.

The hacker can email from an email address that the other recipients recognize and trust. They also gain the benefit of reading down through the chain of replies. This enables them to craft a response that looks like it fits.

For example, they may see that everyone has been weighing in on a new product idea for a product called Superbug. So, they send a reply that says, “I’ve drafted up some thoughts on the new Superbug product. Here’s a link to see them.”

The link will go to a malicious phishing site. The site might infect a visitor’s system with malware or present a form to steal more login credentials.

The reply won’t seem like a phishing email at all. It will be convincing because:

  • It comes from an email address of a colleague. This address has already been participating in the email conversation.
  • It may sound natural and reference items in the discussion.
  • It may use personalization. The email can call others by the names the hacker has seen in the reply chain.


Business email compromise is increasing

Business email compromise is so common that it now has its own acronym. Weak and unsecured passwords lead to email breaches. So do data breaches that reveal databases full of user logins. Both are contributors to how common BEC is becoming.

In 2021, 77% of organizations saw business email compromise attacks. This is up from 65% the year before.

Credential theft has become the main cause of data breaches globally. So, there is a pretty good chance of a compromise of one of your company’s email accounts at some point.

The reply-chain phishing attack is one of the ways that hackers turn that BEC into money. They either use it to plant ransomware or other malware, or to steal sensitive data to sell on the Dark Web.


Tips for addressing reply-chain phishing

Here are some ways that you can lessen the risk of reply-chain phishing in your organization:

  • Use a business password manager. This reduces the risk that employees will reuse passwords across many apps. It also keeps them from using weak passwords since they won’t need to remember them anymore.
  • Put multi-factor controls on email accounts. Present a system challenge (question or required code). Using this for email logins from a strange IP address can stop account compromise.
  • Teach employees to be aware. Awareness is a big part of catching anything that might be slightly “off” in an email reply. Many attackers do make mistakes.


How strong are your email account protections?

Do you have enough protection in place on your business email accounts to prevent a breach? Let us know if you’d like some help! We have email security solutions that can keep you better protected.

KEYWORDS: building envelope design CI (continuous insulation)

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Wc1022 feat rubicon p3 author tony cesar

With over 10 years of experience working in a variety of areas in technology, Tony Cesar has seen it all. He has a passion for technology and a strong focus on the cybersecurity side. With threats at an all-time high and not getting any easier, it is his job to make sure everyone he works with is aware of the threats out there and how to protect themselves. He is the president and CEO of Rubicon.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Abercrombie & Fitch

    EIFS in 2026: How Specialty Finishes Are Redefining Exterior Wall Systems

    As building codes, owner expectations, and design demands...
    Stucco/EIFS
    By: Regi Mendoza
  • proper air and vapor control

    From Energy Efficiency to Moisture Management: Why Air and Vapor Control Matter

    How proper air and vapor control within building...
    Building Envelope
    By: Benjamin Meyer AIA, LEED AP
  • Linear Metal Ceiling Beam Baffles

    Top 25 Ceiling Contractors of 2026

    Suspended ceilings demand precision, code compliance and...
    Ceilings
    By: John Wyatt and Tanja Kern
You must login or register in order to post a comment.

Report Abusive Comment

Manage My Account
  • eMagazine Subscription
  • Newsletters
  • Online Registration
  • Manage My Preferences
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Walls & Ceilings audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Walls & Ceilings or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • medical professionals moving a patient on a stretcher through the halls of a medical building
    Sponsored byNational Gypsum Company

    What Does High Performance Mean When It Comes To Gypsum Boards?

Popular Stories

Linear Metal Ceiling Beam Baffles

Top 25 Ceiling Contractors of 2026

Wichita Biomedical Campus

Wichita Drywall Worker Dies After Scaffolding Fall

QXO Just Changed the Game-Here's What Contractors Are Asking

QXO Just Changed the Game-Here's What Contractors Are Asking

Less compound

Joint Compound Market to Reach $9.7B by 2033

Events

June 24, 2026

The Bright Side & Benefits of Designing with Integrated Lighting

Credits 1 AIA LU/HSW; 0.1 ICC CEU

This course will explore the pivotal role architects and lighting design play in creating safer, more sustainable spaces. Learn how to avoid common lighting mistakes and make informed decisions that create the best visual environment for occupants. 

January 1, 2030

Webinar Sponsorship Information

For webinar sponsorship information, visit www.bnpevents.com/webinars or email webinars@bnpmedia.com.

See our full library of webinars

View All Submit An Event

Products

2026 National Painting Cost Estimator

2026 National Painting Cost Estimator

See More Products

Related Articles

  • All in Agreement
    Who's Looking Out For You?

    See More
  • Cadence McShane Construction logo

    Cadence McShane Hosts Topping Out Ceremony for Anthology of Highland Park in Dallas

    See More
  • Hurricane Getty Images

    Watch for Scams After Hurricane Idalia

    See More

Related Products

See More Products
  • bim 3e.jpg

    BIM Handbook: A Guide to Building Information Modeling for Owners, Designers, Engineers, Contractors, and Facility Managers, 3rd Edition

  • 1118458605.jpg

    Sustainable Facades: Design Methods for High-Performance Building Envelopes

  • 978-0-7643-3022-3.jpg

    Award-winning Green Roof Designs: Green Roofs for Healthy Cities

See More Products

Related Directories

  • International Institute for Lath & Plaster

×

Connect with the industry’s leading resource for unparalleled insights and education.

Join thousands of industry professionals today. Shouldn’t you know what they know?

JOIN NOW
  • RESOURCES
    • Advertise
    • Contact Us
    • Directories
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletters
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • Instagram
    • YouTube
    • X
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing