Out-of-Office Replies Are a Gift to Attackers in August

Every August, thousands of mailboxes start answering attackers' questions automatically. A detailed out-of-office reply tells anyone who emails it exactly who is away, until when, who is covering, and how to reach them - free reconnaissance, delivered on demand, at precisely the time of year when security teams are running their thinnest shifts. Vacation season does not just create absent employees; it creates a self-service intelligence feed about them.
The risk is not hypothetical. Insurers, red teams, and incident responders all converge on the same picture: summer absences plus informal deputy arrangements plus reduced monitoring equal prime conditions for business email compromise (BEC) and fraud.
What a Single Auto-Reply Gives Away
Consider the classic well-meaning OOO: name, job title, exact absence dates, mobile number for emergencies, the deputy's name and direct line, and sometimes the supervisor to escalate to. Red-team analysis by DirectDefense shows that this single message leaks enough to seed a targeted attack: identity, role, phone numbers, reporting line, and a guaranteed window during which the real person cannot contradict anyone impersonating them.
From the attacker's perspective, that reply converts one probing email into a complete playbook. They now know they can spoof the absent manager without risk of a hallway conversation exposing them, they know which deputy to pressure, and they know the deadline: everything must happen before the return date on the auto-reply.
The Read-Receipt Trick: Recon Without a Reply
Auto-replies are not even required. Security firm Hoxhunt has documented a summer pattern in which attackers pair OOO harvesting with read-receipt phishing: probing messages are sent with the Disposition-Notification-to header set, so mail clients quietly report back when and whether a message was opened. Combined with harvested vacation dates, alternate contacts, and reporting lines from auto-replies, attackers can map who is at their desk, who is away, and who answers for whom - then impersonate the absent colleague with convincing timing and context.
An attacker does not need to breach anything to learn your org chart in August. Your mail infrastructure will explain it politely, one auto-reply at a time.
Attackers Time Their Strikes for Empty Desks
The reconnaissance would matter less if defenses were constant - but they are not. The Semperis Ransomware Holiday Risk Report, surveying organizations across the US, UK, Germany, France, and six other markets, found that 52 percent of organizations were hit by ransomware on holidays or weekends. The same study found most organizations shrink their security operations at exactly those times: 78 percent of organizations reduce SOC staffing by 50 percent or more on holidays and weekends, and 6 percent leave the SOC entirely unstaffed.
Claims data points the same direction. Cyber insurer Stoik reports that July and August rank among the most loss-intensive months, and that 69 percent of all claims reported between June and August 2025 traced back to email-related incidents (phishing, fraud and business email compromise combined) - with vacation absences and improvised deputy arrangements explicitly cited as enablers. When the person who normally approves payments is on a beach and the stand-in is working from a hasty handover note, an urgent-sounding invoice gets far less scrutiny than it would in October.
Writing an OOO That Says Less
The good news: this is one of the cheapest risks to reduce. Nobody needs to abandon auto-replies - they need templates that respect a simple rule: external senders get service continuity, not personnel intelligence.
- Split internal and external replies. Every major mail platform supports different messages for colleagues and outsiders. Keep detail internal.
- External template: 'Thank you for your message. It will be handled with some delay. For urgent matters, please contact our team at [shared functional mailbox or main number].' No names, no dates, no personal mobiles.
- Drop the exact dates externally. 'Currently unavailable' serves correspondents just as well and denies attackers their deadline.
- Route to functions, not individuals. A shared mailbox monitored by the team beats naming a single deputy whom an attacker can immediately target.
- Disable automatic read receipts to external addresses at the mail-server level, closing the Disposition-Notification-to channel quietly mapping your office occupancy.
Deputy Rituals and an August-Themed Simulation
Template hygiene handles the leak; process handles the exploitation. Before each vacation wave, make two rituals standard:
- A real handover, not a hallway sentence. Deputies should receive a short written brief: which approvals they may give, which they may not, and the hard rule that payment details, payroll changes, and gift card purchases are never approved on email authority alone.
- A verification pact. Agree that any unusual request appearing to come from the absent colleague - especially anything urgent, confidential, or financial - is verified through a second channel: a phone call to a known number, or a message in the corporate chat tool. Attackers rely on deputies being too polite or too junior to double-check.
Then test it. An OOO-themed phishing simulation in late summer - an urgent request seemingly from a vacationing manager, or a supplier invoice timed to a known absence - shows precisely whether the verification pact holds when the pressure feels real. Running such seasonal scenarios through a platform like empowsec turns the abstract advice into a measurable, teachable moment for the exact people who will face the real thing, and feeds the results into each user's risk profile so follow-up training lands where it is needed.
Key Takeaways
- A detailed OOO reply leaks identity, title, phone numbers, supervisor, deputy, and absence duration - enough to seed BEC impersonation of the absent employee or their stand-in.
- Attackers pair auto-reply harvesting with read-receipt (Disposition-Notification-to) tricks to map who is away and who is covering, without triggering any alarm.
- Timing is deliberate: 52 percent of organizations have been hit by ransomware on holidays or weekends, while 78 percent reduce SOC staffing by 50 percent or more at those times and 6 percent leave the SOC entirely unstaffed; insurer data traces 69 percent of summer claims to email-related incidents (phishing, fraud and BEC combined).
- Fix the leak cheaply: minimal external OOO templates - no dates, no personal deputies, functional mailboxes instead - and separate internal from external replies.
- Fix the exploitation with written handovers, a two-channel verification pact for unusual requests, and an August-themed phishing simulation that rehearses the scenario before attackers stage it.


