
read receipts
The Scam With No Payload: Why 'Hi, are you free?' Is the Whole Trick
The email your filter can't catch is the one that says almost nothing at all.
The most dangerous email your boss never sent contains no link, no attachment, and no misspelled bank warning. It contains four words: "Hi, are you free?"
That's the con. The whole thing. And it works because it's built to slip past every defense you have — including your own instincts.
Here's the mechanics. A traditional phishing email carries a weapon: a malicious link, a poisoned PDF, a fake login page. Your spam filter, your email gateway, and increasingly your AI screening layer are all trained to sniff those out. They check the sender against SPF, DKIM, and DMARC records. They scan attachments. They flag urgency plus a payment request. A message that says "Hi, are you free?" trips none of that, because there's nothing to trip. It reads like a Tuesday.
The payload isn't in the email. The payload is your reply.
Once you write back — "Sure, what's up?" — you've done two things the attacker needed. You've confirmed the account is live and monitored, and you've opened a thread where you are now the one supplying the trust. The next message is where it lands. It's almost always small, plausible, and time-boxed: I'm stuck in a meeting, can you grab some gift cards for a client, I'll reimburse you, just send me the codes on the back. Sometimes it's a wire to a "new vendor." The gift-card version is popular precisely because gift cards are the closest thing to untraceable cash a normal employee can buy at a CVS.
This is business email compromise, and it is not a fringe problem. The FBI's Internet Crime Complaint Center logged $2.9 billion in reported BEC losses in 2023 alone — a category built almost entirely on plain-text messages that no filter flagged. The FTC, separately, has tracked gift cards as one of the top payment methods scammers demand, with hundreds of millions lost that way year after year. These aren't people falling for cartoon Nigerian-prince emails. They're competent employees answering what looks like a normal ping from a name they recognize.
And the name is the second half of the trick. Look at the actual sending address, not the display name. Attackers register lookalike domains — swap an rn for an m, add a hyphen, use a free Gmail with your CEO's name typed into the "from" field. Display names are free to fake; the domain behind the @ is not. That's your tell. If "Dave Morgan, CEO" is writing from [email protected], Dave has not gotten a new email address. Dave does not exist.
The reason the boring opener beats the flashy one is psychological, not technical. A cold demand for money triggers suspicion. A warm, low-stakes question builds a relationship first, so that by the time money enters the chat, you've already decided this person is who they say they are. The scam borrows your own consistency against you.
So the defense isn't spotting a bad link, because there won't be one. It's a rule about the ask, not the message: any request for gift cards, wire transfers, or a payment routed through a channel other than your normal process gets verified out-of-band. Call the person. Not the number in the email signature — the one in your phone. Walk to their desk.
The scammer is counting on you being polite enough to reply and busy enough not to check. Prove them wrong on the second part, and the first part stops mattering.
Sources
- FBI IC3 — 2023 Internet Crime Report, BEC losses
- FTC Consumer Advice — Gift card scam data and payment-method trends
- CISA — Social engineering and phishing guidance