One Empty Field: The Email Security Bypass Letting Attackers Impersonate Your Executives episode artwork

EPISODE · Sep 9, 2026 · 29 MIN

One Empty Field: The Email Security Bypass Letting Attackers Impersonate Your Executives

from ShadowTalk: Powered by ReliaQuest · host ReliaQuest

Organizations rely on Microsoft 365's RejectDirectSend control to block internal email spoofing—but a structural gap lets attackers walk right past it. With nothing more than a basic Python script and an empty envelope sender, threat actors are impersonating executives, IT support, and finance teams to launch Business Email Compromise, payment fraud, and follow-on account takeover.Join hosts Alexandra Moore and John Dilgen as they discuss:How an empty email header field bypasses RejectDirectSend and lands phishing in executive inboxesHow help desk impersonation combined with spoofed internal email creates a dangerous new pretextWhich controls—IP-restricted connectors, automated containment, and out-of-band verification—actually close the gap Two questions your organization should be asking right now:If someone attempted a Direct Send from an unauthorized IP into your tenant tomorrow, would it be rejected?When was the last time you tested whether your employees follow out-of-band verification procedures under pressure?Resources: https://linktr.ee/ReliaQuestShadowTalkJohn Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.

Episode metadata supplied by the publisher feed · Published Sep 9, 2026

Embed this episode

Organizations rely on Microsoft 365's RejectDirectSend control to block internal email spoofing—but a structural gap lets attackers walk right past it. With nothing more than a basic Python script and an empty envelope sender, threat actors are impersonating executives, IT support, and finance teams to launch Business Email Compromise, payment fraud, and follow-on account takeover. Join hosts Alexandra Moore and John Dilgen as they discuss: How an empty email header field bypasses RejectDirec...

Distinct summary based on available episode metadata or transcript content.

Ready to play

One Empty Field: The Email Security Bypass Letting Attackers Impersonate Your Executives

0:00 29:54

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of ShadowTalk: Powered by ReliaQuest?

This episode is 29 minutes long.

When was this ShadowTalk: Powered by ReliaQuest episode published?

This episode was published on September 9, 2026.

Can I download this ShadowTalk: Powered by ReliaQuest episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!