![]()
For years, cyber security awareness has taught us to be suspicious of unexpected emails.
- Look for unfamiliar senders.
- Watch for poor spelling and grammar.
- Question links from unknown sources.
- But what if the next cyber threat doesn’t come from a stranger at all?
- What if it comes from someone you’ve been emailing for weeks?
Trust Has Become the New Attack Surface
One of the most significant shifts in cyber security isn’t happening in firewalls, antivirus platforms or email filters. It’s happening in human behaviour.
A growing technique known as Zombie Phishing highlights this shift perfectly. Rather than sending phishing emails from fake accounts, attackers compromise legitimate mailboxes and insert themselves into existing conversations. They reply to genuine email threads, often using real context, real relationships and real business activity to make a malicious message appear completely legitimate.
The Security Rules We’ve Relied On Are Changing
Historically, cyber criminals had to persuade people to trust them. Now, they’re increasingly inheriting trust that already exists. When an email arrives from a colleague, supplier, hotel owner, technology partner or finance contact you’ve worked with before, most people naturally lower their guard. It’s exactly what modern attackers are counting on. The result is that many traditional warning signs no longer apply. The sender is genuine, the conversation is genuine, the history is genuine, but the request isn’t.
Why This Matters for Hospitality
Hospitality businesses operate through relationships. Hotels work closely with owners, brands, suppliers, technology partners, management companies and finance teams. A huge amount of day-to-day activity relies on trusted communication between those groups.
When those relationships are disrupted, the impact can extend beyond IT. It can affect operations, finances, guest experience and business continuity. That’s why attacks that exploit trusted communications can be particularly effective. They don’t necessarily target technology first. They target the people using it.
The Bigger Trend
Zombie Phishing is unlikely to be the last attack of its kind. In many ways, it reflects a broader shift we’re seeing across cyber security. Attackers are placing less emphasis on breaking through technical barriers and more emphasis on exploiting trusted identities and established relationships. The answer isn’t to trust nobody, business simply doesn’t work that way. But organisations may need to start asking different questions.
Instead of: “Can our people identify a suspicious email?”
The question is increasingly becoming: “Can we identify when a trusted account is behaving suspiciously?”
That’s a fundamentally different challenge. It requires a combination of:
- Strong identity protection
- Multi-factor authentication
- Security awareness training
- Detection and monitoring
- Clear verification processes for sensitive requests
Most importantly, it requires recognising that trust itself has become part of the cyber security conversation.
Final Thought
Cyber security awareness has traditionally focused on strangers. But many of today’s attacks are designed to look familiar.
Zombie Phishing is not interesting because it’s a new phishing technique. It’s interesting because it highlights a much bigger shift. For organisations that rely on strong relationships to operate, understanding that distinction may become one of the most important cyber security conversations of the next few years.
