Security

February 10, 2026

Lateral phishing: crawling through the air ducts

If you haven’t already read our post on what phishing is, we suggest reading that one first.

Lateral phishing is a technique where an attacker compromises multiple accounts within a domain. It’s a growing issue, especially within higher education. So, identifying a lateral phishing attack is important to staying safe and keeping your peers and colleagues safe, too.

Have you watched a spy movie, where the sly spy breaks into a building, then moves from place-to-place within the building by crawling through the air ducts to bypass the security? That’s essentially what lateral phishing is. The attacker breaks into the email environment by phishing one user, then uses that account to move around the email environment.

Here’s how the attack works.

The attacker might send a phishing email to you. It looks totally normal; maybe it appears to be from a professor, friend, or company that you know. For example, it might be a request to fill out a survey. Or, it could be a shared file. You click on the link, but behind the scenes, the attacker has just stolen your email address and password.

Now, the attacker doesn’t care about you anymore. Instead, they’ll use your account to attack other people. This is the “lateral” part.

The attacker will log into your email account and write a new email that looks like it came from you, and they’ll send email messages to other people within the domain (other Denison email addresses).

Put yourself in the next person’s shoes: if you got an email from person-denison@gmail.com, you might assume that the message is illegitimate, but if it came from person@denison.edu, it looks a lot more legit.

The recipient(s) of the malicious emails sent from your account might click on the links, since they trust you, causing their accounts to become compromised. The attacker keeps moving sideways, using the people they’ve tricked to trick more people.

Citations

A. Pearson et al. Phishing Campaigns Targeting Higher Education Institutions. Google Cloud/Mandiant Threat Intelligence. February 24, 2025. [Online.] Available: https://cloud.google.com/blog/topics/threat-intelligence/phishing-targeting-higher-education/.

E. Morrow. “Scamming higher ed: An analysis of phishing content and trends.” Computers in Human Behavior, vol. 158, p. 108274. April 25, 2024. [Online.] Available: https://doi.org/10.1016/j.chb.2024.108274.


Denison aims to promote the use of inclusive language. While we value the use of inclusive language, terms that are outside of Denison's direct influence are sometimes required for the sake of maintaining user understanding. As other join Denison in embracing the use of inclusive language, Denison will continue to update the documentation to reflect those changes.

Denison Service Desk

Contact the Service Desk by email, phone, or on the Self-Service Portal. You can also find them in Fellows Hall.