G
15

Just realized most people ignore the 'reply all' risk in work emails

I was on a call with my brother last week, he does IT for a school district in Ohio. He told me about a teacher who accidentally forwarded a staff email chain to the whole district listserv, and it had a sketchy link attached. No one clicked it, but it got me thinking, we all focus on phishing scams and password managers, but the simple act of replying all can expose internal email addresses and open doors for social engineering. I used to hit reply all without a second thought until he said, 'every address you blast is a target for a spammer.' Now I check the recipient list every single time, and I've started telling my coworkers to do the same. Has anyone else had a close call with a reply all slip-up that could have been worse?
1 comments

Log in to join the discussion

Log In
1 Comment
king.jordan
The real danger with reply all is how it turns your coworkers into phishing bait without them knowing it. That teacher's email with the sketchy link, even if nobody clicked it, just told every spammer on that list which addresses actually work and which inboxes get checked. Once that info is out there, those people get targeted way harder with stuff that looks like it comes from inside the district. Someone on that list probably forwarded the email to a personal account or replied all again to say "hey this is spam," which just feeds the cycle. The trick is to treat every email address as a piece of your building's key system, not something to hand out freely.
2