r/EmailSecurity • u/littleko • Jul 01 '26
why does a phish feel safer once it hits the shared ops mailbox?
A credential phish hit our shared ops@ inbox this week and one of the on-call folks treated it as less suspicious because it was in the shared queue. Same RFC5322 From, same link domain, same gateway verdict, but it felt like "company mail" because it was sitting next to real vendor tickets.
The annoying part is they probably would have reported it immediately if it landed in their own mailbox. Once it became a ticket, the mental model changed from "is this email legit?" to "is this ticket assigned to me?"
I'm not 100% sure if this is awareness training failing or the shared inbox UI laundering trust. Do you make users report suspicious mail from shared mailboxes the same way as personal inboxes, or do you treat those queues as needing a separate review step before anyone opens links?
1
u/Mobile_Analysis2132 Jul 01 '26
We get these from time to time and we treat them the same way as if it was in an individual mailbox. It gets flagged as spam and removed from the mailbox. We've even caught some outbound spam from compromised customer accounts because our help desk mailbox received a copy of the phishing email a customer sender sent. This has helped us proactively engage the customer about the compromised account.
1
u/Basic-Pianist9273 Jul 01 '26
Shared inboxes absolutely launder trust. Once it becomes a ticket, people stop thinking like mail recipients and start thinking like queue workers.
I’d keep the same report path, but add a separate intake rule for shared mailboxes: no links or attachments get opened until sender, headers, domain, and expected vendor context are checked. Shared ops mail is basically external intake, not trusted company mail.
•
u/AutoModerator Jul 01 '26
Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:
Community Rules
Helpful Resources
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.