How Out-of-Office Replies Can Put Workers at Risk

Chain of command and other personal or company information in these greetings can be useful to people performing social-engineering attacks. Simply write that you'll be "unavailable"

Ah, the innocuous out-of-office notification message. Who in the corporate world hasn't used it at one time or another?

Sure, the out-of-office function built into Microsoft Outlook and similar email software is great for letting colleagues, customers, vendors and even friends and acquaintances know that you're lying on a beach in Hawaii, sipping a Mai-Tai or two — and that you won't be able to respond.

Since you can't, or don't want to, respond while you're on vacation or away for some other reason, you include a way for people to contact you in an emergency.


On supporting science journalism

If you're enjoying this article, consider supporting our award-winning journalism by subscribing. By purchasing a subscription you are helping to ensure the future of impactful stories about the discoveries and ideas shaping our world today.


You also include the name and contact information of your boss or co-worker. You'll probably also tell people how long you'll be away and when you'll be back in the office.

No big deal, right?

Wrong. You never know who's going to see that information, according to security experts.

Giving away too much
"In many enterprises today, guarding against data breaches and targeted attacks is one of the top concerns of IT administrators," Trend Micro researcher Roland Dela Paz said last fall in a blog post.

"One of the things that administrators guard against is reconnaissance and targeting of any potential high-value personnel who may fall victim to a targeted attack," Dela Paz noted. "A less obvious source of information leakage, however, is the humble out-of-office notification."

Security expert Andy O'Donnell, network security guide at About.com, has seen a lot of "crazy stuff" in out-of-office replies.

"It's amazing what people put in them and reveal about themselves," O'Donnell said. "My rule of thumb is, 'If you wouldn't tell a room full of strangers the information, you shouldn't put it in your out-office-reply.'

"One of the things people put in is their chain of command — who their supervisor is."

O'Donnell said that sort of information could be very useful to people performing social-engineering attacks on companies.

"They could [use that information] and contact a department of that company claiming to be the supervisor of that person and they could get that person's Social Security number if people aren't thinking on their feet," O'Donnell said.

[7 Easy Ways to Get Your Identity Stolen]

Please rob me
"There's a lot of revealing information there," O'Donnell added. "If someone is going on a trip, you obviously know that they're not going to be at their house."

A lot of burglars are trolling on Facebook looking for just that kind of information, but leaving it in an out-of-office reply just makes it easy for them, he said.

"A lot of times, people will tell you exactly where they're going to be — if it's a conference, for example — and that could be potentially dangerous," O'Donnell said.

"If someone wants to track you down at that conference, they'll know exactly where you're going to be, what your name is, your cellphone number — just a lot of information that doesn't need to be out there and could be going to anybody, potentially."

One of the problems is that companies aren't really aware of the security risks of out-of-office replies.

"I have a newsletter that I send out to subscribers for About.com, and when my newsletter goes out, it will prompt an out-office-reply for a lot of people," O'Donnell said. "There's so much information that people put in those, all their contact information, what their supervisor's name is, who to contact for invoicing or things like that.

"They put a lot of their business in those replies when they don't know who's going to get them. It could be a complete stranger on the Internet, or a spammer or a scammer. Anybody could send you an email, and that auto-reply is going to do its job and send a reply back to them."

How to hold back
O'Donnell has some tips for users and IT administrators to create safer out-of-office notification messages:

— Set up your mail client to send different out-of-office notifications to people outside your organization than to people inside your company.

— Have a security policy in place for rules of behavior. Have a user agreement so users are aware of what the company's policies are in terms of information security and protecting information.

"Companies should include what information can be divulged in out-of-office notifications in this policy document," O'Donnell said. "For example, 'You will not list your chain of command in an out-of-office reply.'"

— Don't reveal too much information. Be intentionally vague. If you have to leave an auto-reply, don't say you'll be in Hawaii; say you'll be unavailable. Instead of giving strangers your cellphone or home phone number, tell them you'll be checking your email.

— Leave all of your personal information out of your signature block.

"If you wouldn't give this information to a complete stranger, don't include it in your out-of-office notification," O'Donnell said.

Copyright 2013 TechNewsDaily, a TechMediaNetwork company. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

It’s Time to Stand Up for Science

If you enjoyed this article, I’d like to ask for your support. Scientific American has served as an advocate for science and industry for 180 years, and right now may be the most critical moment in that two-century history.

I’ve been a Scientific American subscriber since I was 12 years old, and it helped shape the way I look at the world. SciAm always educates and delights me, and inspires a sense of awe for our vast, beautiful universe. I hope it does that for you, too.

If you subscribe to Scientific American, you help ensure that our coverage is centered on meaningful research and discovery; that we have the resources to report on the decisions that threaten labs across the U.S.; and that we support both budding and working scientists at a time when the value of science itself too often goes unrecognized.

In return, you get essential news, captivating podcasts, brilliant infographics, can't-miss newsletters, must-watch videos, challenging games, and the science world's best writing and reporting. You can even gift someone a subscription.

There has never been a more important time for us to stand up and show why science matters. I hope you’ll support us in that mission.

Thank you,

David M. Ewalt, Editor in Chief, Scientific American

Subscribe